or agencies that regulate CII industries in each ASEAN Member State.
1-3 Fundamental ideas of CII
a)
In these guidelines, CII is defined as follows:
“Information infrastructures whose failure or limited operation due to natural
or man-made disasters would surely cause tremendous impact on the vast
majority of citizens”
b)
“Tremendous impact on the vast majority of citizens” means not only direct
damage due to CII failure but also indirect damage caused by the effect of
CII’s failure on other information infrastructures which are highly dependent
on the CII based on formal impact assessment.
c)
‘CII owner/operator’ in this guideline refers to the owner of the CII as well as
the service provider operating the CII.
1-4 Significance of CIIP
1-4-1 Purpose of CIIP
a)
In order to continuously provide services using CII and to avoid serious effects
on public welfare and socioeconomic activities caused by outages of the
information technology (IT) supporting the CII resulting from cyber-attacks
or other causes, all stakeholders concerned should protect CII by taking
proactive actions to minimize the risk of the IT outages and by ensuring
prompt recovery from the outage should one occur.
1-4-2 Fundamental issues and concerns of CIIP
a)
When providing necessary guidelines and support with regards to
information security measures, the relevant governments and/or regulators
for the CII sector should take into consideration the situation in each country,
as well as the size and capability of each CII owner/operator.
b)
If
the
governments
and/or
regulators
request
the
same
level
of
implementation of measures regardless of the size of the CII owners/operators,
it may overburden SME operators and negatively affect their business
viability.
c)
It is preferable that all stakeholders concerned, including the governments
and/or regulators and each CII owner/operator, periodically check the
progress of their own measures and policies as a part of the initiative to
accurately recognize the current CIIP circumstances, and assess the