Appendix 3. List of References on Best Practices of CIIP All chapters - Critical Information Infrastructure Protection Good Practice Guide (November 2016, Global Forum on Cyber Expertise (GFCE)) Available at https://www.thegfce.com/documents/reports/2016/11/10/ciip-goodpractice-guide Chapter 1-1 to 1-5 Outline/Overview - The Basic Policy of Critical Information Infrastructure Protection (3rd Edition) (May 2014, NISC, Japan) Available at http://www.nisc.go.jp/eng/archive.html#CIP Chapter 2-1Preparation for development of CIIP policies - Methodologies for the identification of Critical Information Infrastructure assets and services(Guidelines for charting electronic data communication networks December 2014, ENISA) Available at https://www.enisa.europa.eu/publications/methodologies-for-theidentification-of-ciis - Presidential Policy Directive -- Critical Infrastructure Security and Resilience (February 2013, DHS, US) Available at https://www.whitehouse.gov/the-press-office/2013/02/12/presidentialpolicy-directive-critical-infrastructure-security-and-resil Chapter 2-2 Establishment of information security policy or strategy - The Basic Policy of Critical Information Infrastructure Protection (3rd Edition) (May 2014, NISC, Japan) - The Second Action Plan on Information Security Measures for Critical Infrastructures(NISC, Japan) Above material are available at http://www.nisc.go.jp/eng/archive.html#CIP - COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS on Critical Information Infrastructure Protection‘Achievements and next steps: towards global cyber-security’ (March 2011 EU Commission, EU) Available at http://www.sicurezzacibernetica.it/db/[2011]%20COM%20163%20-%20Achievement s%20and%20next%20steps%20towards%20global%20cyber-security.pdf Chapter 2-3 Establishment of guidelines for security standards

Select target paragraph3