II. Items that Should Ideally be Prescribed in the Safety Principles II. Items That Should Ideally Be Prescribed in the Safety Principles 1. Purpose of Formulating the Safety Principles Based on the concept of mission assurance, the safety principles set out the need to implement the PDCA cycle for information security measures in reference to the contents of the safety principles, in order to eliminate, as far as possible, the occurrence of CISs outages in CI that have an impact on the safe and continuous provision of CISs, as well as to ensure their swift recovery in the occurrence of such an event. 2. Applicable Scope Based on the examples of applicable CI provided in “Annex 1: Applicable CI Operators and Examples of Critical Information Systems,” as well as the CISs (including procedures), examples of CISs outages, and service maintenance levels provided in “Annex 2: Explanation of CISs and Examples of CISs Outages,” the applicable scope for the items to be prescribed in the safety principles shall be listed. 3. Roles of Stakeholders With regard to the stakeholders of the CI sectors within the scope of the safety principles (*refer to the Definitions and Glossary), provide a comprehensive and specific list, and clearly define the roles of each stakeholder in relation to the respective information security measures. In particular, with regard to the role of CI operators, the efforts of the management should also be included, taking reference from the section “Responsibility of Top Management” in the 4th Cybersecurity Policy and other materials. 4. Measures In light of the fact that CI operators have the social responsibility of realizing the safe and continuous provision of CISs, review the adoption or rejection of the measure items listed in items 4.1 to 4.4, in accordance with the PDCA cycle for information security measures. The PDCA cycle for information security measures typically follows the flow of: Plan, which involves identifying the measures based on the results of analysis; Do, which involves moving to the implementation phase, and after a certain period of time; Check, which involves evaluating the need to review the measures, and; Act, which involves putting in place improvements. However, in actual operations, depending on the results of the monitoring and detection carried out in the “Do” phase, it is necessary to be aware of the possible need to respond actively, such as by reviewing the contents of the measures urgently. In addition, list the references that set out concrete examples of each measure in Annex 4: References for Concrete Examples of Measure Items. This provides a source of reference during 6

Select target paragraph3