c) The governments and/or regulators should consider appropriate support based on the situation in its own country and industry. 2-7-3 Government support for cross-industry exercises in the private sector a) It is preferable to conduct cross-industry exercises among the highly interdependent industries after careful interdependency analysis. “Highly interdependent” means if production or services in a certain company or industry stop, it affects other companies or industries such as a supply chain or the settlement system in financial industries. b) As many industries may participate in the cross-industry exercises, participants have to discuss scenarios and detailed plans of exercises in advance. This is one way for governments and/or regulators to give support by providing opportunities for discussion or fundamental information to build a scenario so that the private sector can smoothly conduct cyber exercises. c) The governments and/or regulators should consider the situation in its own country and industry, and consider appropriate support, as well as industrylevel exercises. 2-8 Awareness-raising activities for CII owners/operators a) In order to improve the level of CIIP in the private sector, it is important to deepen the understanding of basic guidelines, its significance, and the content of safety standards established by the governments and/or regulators, and the related international standards. b) It is also important to promote awareness-raising activities among the private sector by conducting publicity activities. 2-9 ASEAN regional partnership a) As information technology is advancing, regional partnership becomes much more important to handle cyber threats. It is preferable for governments and/or regulators of ASEAN Member States to establish and strengthen the regional partnership in consideration of this situation. b) For example, strengthening information sharing systems by establishing a POC (Point of Contact) in the ASEAN region, and conducting periodical meetings. It is also helpful to periodically conduct cyber exercises in the area and check the

Select target paragraph3