4-2
Establishment of information security policy or strategy
Expectation for
To establish basic idea of CIIP to be included in information
Governments
security policy.
To decide items to be included in the policy (examples are
described in the CIIP guidelines 2-2).
To periodically review policy/strategy to make sure it is not
outdated.
Possible Issues
Lack of examples/templates.
and Obstacles
Lack of human resources/information.
Conflict among stakeholders (Ministries/Agencies, CII
owners/operators, etc.).
Possible
If you cannot establish information security policy:
Countermeasures
Refer to the information security policy of the other
to Overcome
countries listed on the CIIP guidelines.
Issues and
If there is conflict of the interest between stakeholders,
Obstacles
following are the examples to solve the problem.
Establish an organization that has enough authority to
coordinate conflicts among stakeholders.
Conduct series of intensive discussions in which every
stakeholders can freely discuss their opinions to
compromise.
Give enough authorities to certain regulatory
ministries/agencies to solve the conflicts.
It is desirable to put periodical review as a responsibility of
the government in the information security policy so that
you can have enough human resources or organizations
within the government.
6