I. Introduction 2. Envisaged Future 2. Envisaged Future The future images expected to be realized through the initiatives based on this Cybersecurity Policy are set out hereunder. (Clarification of responsibilities) ○ The purpose of CIP, the responsibilities of each stakeholder, and the items to be implemented are clarified and disseminated to all stakeholders as a common understanding. (Organizational governance) ○ Organizational governance functions fully in order to clarify responsibilities and authorities within organizational units, allocate resources appropriately, and accurately implement PDCA cycles so as to ensure that in response to environmental changes the purpose of CIP can be achieved at all times by all organizational units. (Ensuring optimal protection measures within the organization of each CI operator) ○ Based on the characteristics of the organization and the CISs provided, top management clarifies risks and make all persons within the organization aware of them. ○ Requirements relating to the continuous provision of CISs are clear, with standards and manuals formulated and maintained accordingly, with the status of compliance by related persons being readily assessable. (Comprehensive measures in response to threats) ○ In order to respond precisely to changes to CI-related threats, measures are promoted for a comprehensive response capable of anticipating future changes in the environment, including the supply chain, etc. (Communication) ○ Daily communications is conducted within each organization and among stakeholders in order to enhance measures to prevent CISs outages. In addition, in the event that CISs outages occur, thorough communication will ensure a calm response, and continued improvements will be made, leveraging experiences and applying them to future measures. (Coexistence and co-prosperity with society) ○ Independent and proactive measures by all stakeholders contribute to nurturing a cybersecurityfocused culture and also support sustainable development of society. ○ In addition to CISs being continually provided, stakeholders work together to ensure that CIP measures are well publicized nationally and provide the public with a sense of security. (Regular assessment and revision) ○ In addition to the measures of all stakeholders being regularly assessed, the policy will be revised 2

Select target paragraph3