4.3 Response based on Informed Risk When everything is connected with networks, there are inseparable benefits and risks which should be considered objectively. Thus, security measures and implementation methodologies should be identified in advance, considering the likelihood of unforeseen risk occurring. Considering the possibility that potential risks and the degree of risk acceptance may differ for each use case and that they may change over time, security measures and implementation methodologies should be adopted flexibly in terms of mission assurance. From this perspective, risk assessment should be conducted regularly and as appropriate. It is required to establish a mechanism to determine and isolate a systemic risk, i.e., a risk in specific IoT system spreads to other IoT systems. 4.4 Proper Application of Performance Requirements and Specification Requirements The environment surrounding IT is changing rapidly. Therefore, the requirements should be composed of two elements; one is performance-based requirements that are universal and essential. The other element relates to specification requirements that provide effective means and particular methods available at the time. Specification requirements should be constructed through identification of targeted IoT systems and creation so that they can choose the most appropriate means in a flexible way. 4.5 Step-by-Step and Continuous Approach Considering continuous changes of IoT systems’ function due to the ever-evolving environment, e.g., technological innovation, fundamental requirements should first be identified and then these requirements should be continually advanced on a step-by-step basis. 4.6 Collaboration and Role Sharing Role sharing among stakeholders of IoT systems such as industry, government and academia should be clarified. Additionally, a mechanism for ensuring security by information sharing, coordination and cooperation among all stakeholders should be determined. All stakeholders should know their responsibility demarcation. 4.7 Consideration of Other Operational Rules Regarding items relating to IoT systems operations, such as IoT systems coordination, data utilization, and protection of personal information, social rules that span beyond 4

Select target paragraph3