4. Check lists to develop CIIP policies utilizing CIIP guidelines
4-1
Preparation for development of CIIP policies
Expectation for
To understand internal/external environment correctly
Governments
regarding CIIP.
To evaluate risks the Government may face in the future.
To identify CIIs that should be protected.
To estimate usable resources.
Possible Issues
Lack of information.
and Obstacles
Lack of skill/method to evaluate risks.
CII cannot be identified/Good criteria does not exist.
Lack of resources/lack of understandings of higher
management.
Possible
At this stage, important actions are 1) to understand
Countermeasures
current CIIP situations correctly inside/outside the country,
to Overcome
2) to evaluate possible risks correctly, and then 3) to
Issues and
estimate usable resources and understand gaps between
Obstacles
necessary resources.
With regard to 1) and 2)
If you cannot have enough information, or reliable criterial
or reference documents:
Refer to international standards such as ISO 27001:2013
“Information Security Management”, ISO 31000:2009
“Risk
Management”,
and
ISO
22301
“Business
Continuity Management”.
Refer to reference documents (see list of reference
material in the CIIP guidelines).
Invite experts from private sectors or other advanced
countries in terms of CIIP to ask advice or to hold
workshops.
With regard to 3)
If shortage of resources is due to lack of understandings of
your higher management:
Develop detailed plans to compensate gaps between
current situation and necessary resources.
4