c)
The governments and/or regulators should consider appropriate support based
on the situation in its own country and industry.
2-7-3 Government support for cross-industry exercises in the private sector
a)
It is preferable to conduct cross-industry exercises among the highly
interdependent industries after careful interdependency analysis. “Highly
interdependent” means if production or services in a certain company or
industry stop, it affects other companies or industries such as a supply chain or
the settlement system in financial industries.
b)
As many industries may participate in the cross-industry exercises,
participants have to discuss scenarios and detailed plans of exercises in advance.
This is one way for governments and/or regulators to give support by providing
opportunities for discussion or fundamental information to build a scenario so
that the private sector can smoothly conduct cyber exercises.
c)
The governments and/or regulators should consider the situation in its own
country and industry, and consider appropriate support, as well as industrylevel exercises.
2-8 Awareness-raising activities for CII owners/operators
a)
In order to improve the level of CIIP in the private sector, it is important to
deepen the understanding of basic guidelines, its significance, and the content
of safety standards established by the governments and/or regulators, and the
related international standards.
b)
It is also important to promote awareness-raising activities among the private
sector by conducting publicity activities.
2-9 ASEAN regional partnership
a)
As information technology is advancing, regional partnership becomes much
more important to handle cyber threats. It is preferable for governments and/or
regulators of ASEAN Member States to establish and strengthen the regional
partnership in consideration of this situation.
b)
For example, strengthening information sharing systems by establishing a POC
(Point of Contact) in the ASEAN region, and conducting periodical meetings. It
is also helpful to periodically conduct cyber exercises in the area and check the