V.
5.3
Promotion of security by design ·································································· 34
5.4
Promotion of international cooperation ·························································· 34
5.5
Strengthening cybercrime countermeasures ····················································· 35
5.6
Ensuring security in cooperation with the Digital Agency ···································· 35
5.7
Promotion of public relations activities ·························································· 35
Activities Taken by Stakeholders ········································································· 37
1.
Cabinet Secretariat ························································································· 37
2.
Responsible Ministries for CIP ·········································································· 40
3.
Cybersecurity Related Ministries ········································································ 41
4.
Crisis Management Ministries and Disaster Prevention Related Ministries ······················· 42
5.
CI Operators ································································································ 42
6.
CEPTOARs and CEPTOAR Secretariat ································································ 45
7.
CEPTOAR Council ························································································ 45
8.
Cybersecurity Related Agencies ········································································· 46
9.
Cyberspace-related Operators ··········································································· 47
VI. Assessment and Verification ··············································································· 48
1.
Assessment of This Cybersecurity Policy ······························································ 48
1.1
Assessment ··························································································· 48
1.2
Supplementary studies ············································································· 48
2.
Verification of This Cybersecurity Policy ······························································ 49
2.1
Verification ·························································································· 49
2.2
Verification of measures taken by CI operators ················································ 49
2.3
Verification of policies by government organizations ········································· 49
VII. Revision of This Cybersecurity Policy ··································································· 50
ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM
NISC
51
1.
Information Related to System Failures ································································ 51
2.
Information Sharing to NISC from CI Operators ····················································· 52
2.1
Cases requiring information sharing to NISC ··················································· 52
2.2
Framework for information sharing to NISC ··················································· 52
2.3
Handling of information shared to NISC ························································ 53
3.
Information Sharing from NISC ········································································· 54
3.1
Cases requiring information sharing from NISC ··············································· 54
3.2
Framework for information sharing from NISC ················································ 54
3.3
Cooperation for information sharing from NISC ··············································· 55
ANNEX 1 SCOPE OF CI OPERATORS AND CRITICAL INFORMATION SYSTEM
EXAMPLES ········································································································· 56
ANNEX 2 EXPLANATION OF CI SERVICES AND SERVICE MAINTENANCE LEVELS ··· 57
ANNEX 3. CATEGORIES OF EVENTS AND CAUSES FOR INFORMATION SHARING TO NISC
62
ii