Index
I. Purposes and Positioning .................................................................................................................. 1
1. The Importance of Information Security Measures for Critical Infrastructure (CI) ............................ 1
2. What Are “Safety Principles?”...................................................................................................... 2
3. Positioning of the Guideline ......................................................................................................... 2
4. Expectations Toward the Continual Improvements and Dissemination of Safety Principles based on
This Guideline ................................................................................................................................ 5
II. Items That Should Ideally Be Prescribed in the Safety Principles........................................................ 6
1. Purpose of Formulating the Safety Principles................................................................................. 6
2. Applicable Scope ........................................................................................................................ 6
3. Roles of Stakeholders .................................................................................................................. 6
4. Measures .................................................................................................................................... 6
4.1. The “Plan” Perspective ............................................................................................................ 7
4.1.1. Perspective of the Organization’s Situation ........................................................................... 7
(1) Understanding the External and Internal Environments ............................................................ 7
(2) Understanding the Requirements of Stakeholders .................................................................... 7
4.1.2. The “Leadership” Perspective .............................................................................................. 7
(1) Commitment of the Management ........................................................................................... 7
(2) Formulation of Information security Policies .......................................................................... 8
(3) Assignment of Responsibilities and Authority for the Roles in the Organization ........................ 9
4.1.3. The “Plan” Perspective.......................................................................................................11
(1) Information Security Risk Assessment...................................................................................11
(2) Decision on Information Security Risk Treatment ................................................................. 12
(3) Formulation of Individual Policies for Security Management Measures .................................. 19
(4) Formulation of Plans for Addressing Information Security Risks ............................................ 19
4.1.4. The “Support” Perspective ................................................................................................ 19
(1) Securing Resources ............................................................................................................. 19
(2) Human Resource Development and Awareness-Raising ......................................................... 20
(3) Communication .................................................................................................................. 20
4.2. The “Do” Perspective ............................................................................................................ 21
4.2.1. The Operational Perspective .............................................................................................. 21
(1) Introduction and Operation of Information Security Measures ................................................ 21
(2) Addressing CISs Outages .................................................................................................... 22
(3) Conducting Exercises and Training ...................................................................................... 23
4.3. The “Check” Perspective ....................................................................................................... 24
4.3.1. The Evaluation Perspective ............................................................................................... 24
(1) Monitoring and Auditing ..................................................................................................... 24
(2) Review by the Management................................................................................................. 24
4.4. The “Act” Perspective ........................................................................................................... 25
4.4.1. The Improvement Perspective ............................................................................................ 25
(1) Corrective Measures and Continual Improvements ................................................................ 25
Annex 1: Scope of CI Operators and Critical Information System Examples.......................................... 26
Annex 2: Explanation of CI Services and CI Service Outage Examples ................................................. 27
Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and
Countermeasures that Are Associated with Incident Readiness ............................................................. 33
Annex 4: References for Concrete Examples of Measures .................................................................... 46
Definitions / Glossaries ..................................................................................................................... 50
References........................................................................................................................................ 52