I. Introduction 1. Purpose of CI Protection I. Introduction National life and socioeconomic activities fully depend on diverse social infrastructures, and information systems are being broadly utilized to enable infrastructures to properly fulfill their functions. Under such circumstances, there is a need for the public and private sectors to make all-out efforts to intensively protect critical infrastructure services (CISs), such as information and communication services, electric power supply services and financial services, whose suspension or deterioration is highly likely to have tremendous impact. The private sector should not completely count on the government, nor should the government leave everything to the private sector. Close public-private collaboration is indispensable. Therefore, the government established the Cybersecurity Policy for Critical Infrastructures Protection (the “Cybersecurity Policy”), a shared policy between the government, which bears responsibility for promoting independent measures by CI operators relating to CI cybersecurity and implementing other necessary measures, and CI operators, which independently carry out relevant protective measures, as a basic framework for CI protection, and has promoted this initiative to date. Threats surrounding CI are becoming increasingly advanced and sophisticated year by year. On the other hand, due to differences in how systems are used in each CI field, the threats faced by each organization are becoming increasingly distinctive. In view of this situation, the government has based this Cybersecurity Policy for Critical Infrastructure Protection (“this Cybersecurity Policy”) on the Fourth Edition of the “Cybersecurity Policy for Critical Infrastructure Protection” (the “Fourth Policy”), which serves as a reference for critical infrastructure protection, while also actively updating the policy to further enhance critical infrastructure protection based on public-private collaboration. This will enable critical infrastructure fields as a whole to flexibly respond to trends in future threats and changes in the environment surrounding systems and assets. 1. Purpose of CI Protection 1 Based on the concept of mission assurance, the purpose of CI protection (CIP) is to maintain safe and continuous provision of CISs. Taking the view that natural disasters, mismanagement, cyberattacks, and changes in the environment surrounding CI constitute risks that make the continuous provision of CISs uncertain, the aim is to ensure resilience and prevent serious impact on national life and socioeconomic activities, from the dual aspects of limiting risk to acceptable levels, and in terms of preparing for CISs outages, taking appropriate action in the event of outages, and ensuring rapid restoration of services. 1 In the Cybersecurity Strategy (Cabinet Decision of September 28, 2021), the concept of mission assurance is described as follows: “Refers to the condition in which any organization represented by companies, CI operators (excl. related entities), and government bodies understand the operations or services that they should carry out as their missions, and ensure necessary capabilities and resources to reliably execute such missions. This means that senior executives or managers of each organization should identify operations or services that represent their missions and take all responsibility for secure and sustainable provision, rather than making cybersecurity initiatives themselves the goal.” 1

Select target paragraph3