4. Check lists to develop CIIP policies utilizing CIIP guidelines 4-1 Preparation for development of CIIP policies Expectation for To understand internal/external environment correctly Governments regarding CIIP. To evaluate risks the Government may face in the future. To identify CIIs that should be protected. To estimate usable resources. Possible Issues Lack of information. and Obstacles Lack of skill/method to evaluate risks. CII cannot be identified/Good criteria does not exist. Lack of resources/lack of understandings of higher management. Possible At this stage, important actions are 1) to understand Countermeasures current CIIP situations correctly inside/outside the country, to Overcome 2) to evaluate possible risks correctly, and then 3) to Issues and estimate usable resources and understand gaps between Obstacles necessary resources. With regard to 1) and 2) If you cannot have enough information, or reliable criterial or reference documents: Refer to international standards such as ISO 27001:2013 “Information Security Management”, ISO 31000:2009 “Risk Management”, and ISO 22301 “Business Continuity Management”. Refer to reference documents (see list of reference material in the CIIP guidelines). Invite experts from private sectors or other advanced countries in terms of CIIP to ask advice or to hold workshops. With regard to 3) If shortage of resources is due to lack of understandings of your higher management: Develop detailed plans to compensate gaps between current situation and necessary resources. 4

Select target paragraph3