V. 5.3 Promotion of security by design ·································································· 34 5.4 Promotion of international cooperation ·························································· 34 5.5 Strengthening cybercrime countermeasures ····················································· 35 5.6 Ensuring security in cooperation with the Digital Agency ···································· 35 5.7 Promotion of public relations activities ·························································· 35 Activities Taken by Stakeholders ········································································· 37 1. Cabinet Secretariat ························································································· 37 2. Responsible Ministries for CIP ·········································································· 40 3. Cybersecurity Related Ministries ········································································ 41 4. Crisis Management Ministries and Disaster Prevention Related Ministries ······················· 42 5. CI Operators ································································································ 42 6. CEPTOARs and CEPTOAR Secretariat ································································ 45 7. CEPTOAR Council ························································································ 45 8. Cybersecurity Related Agencies ········································································· 46 9. Cyberspace-related Operators ··········································································· 47 VI. Assessment and Verification ··············································································· 48 1. Assessment of This Cybersecurity Policy ······························································ 48 1.1 Assessment ··························································································· 48 1.2 Supplementary studies ············································································· 48 2. Verification of This Cybersecurity Policy ······························································ 49 2.1 Verification ·························································································· 49 2.2 Verification of measures taken by CI operators ················································ 49 2.3 Verification of policies by government organizations ········································· 49 VII. Revision of This Cybersecurity Policy ··································································· 50 ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC 51 1. Information Related to System Failures ································································ 51 2. Information Sharing to NISC from CI Operators ····················································· 52 2.1 Cases requiring information sharing to NISC ··················································· 52 2.2 Framework for information sharing to NISC ··················································· 52 2.3 Handling of information shared to NISC ························································ 53 3. Information Sharing from NISC ········································································· 54 3.1 Cases requiring information sharing from NISC ··············································· 54 3.2 Framework for information sharing from NISC ················································ 54 3.3 Cooperation for information sharing from NISC ··············································· 55 ANNEX 1 SCOPE OF CI OPERATORS AND CRITICAL INFORMATION SYSTEM EXAMPLES ········································································································· 56 ANNEX 2 EXPLANATION OF CI SERVICES AND SERVICE MAINTENANCE LEVELS ··· 57 ANNEX 3. CATEGORIES OF EVENTS AND CAUSES FOR INFORMATION SHARING TO NISC 62 ii

Select target paragraph3