I. Introduction 4. Outcome of the Review for the Revision of this Cybersecurity Policy ○ Continue efforts for appropriately improving institutional frameworks as necessary for maintaining safety, such as through positioning cybersecurity measures as safety regulations among relevant laws and embodying the service maintenance level in relevant laws from the viewpoint of mission assurance ○ Review items of the questionnaire survey so that the survey leads to further improvement and dissemination of the safety principles among CI operators 2. Enhancement of information sharing system Basically keep the element of "[2] Enhancement of information sharing system" in the Third Policy ○ Further promote information sharing ・ Eliminate obstacles that hinder information sharing by diversifying the contact formation (addition of a new route for information provision via the CEPTOAR secretariat, which enables data anonymization) ・ Promote efficient and effective responses through information sharing based on severity schema on CISs outages ・Develop the information sharing system to allow opening of a hotline to achieve prompt and efficient sharing of information on cyberattacks, 24 hours a day, 365 days a year ・Share awareness among stakeholders regarding the inclusion of OT and IoT in the scope of information sharing to and from NISC by clarifying the relevant scope 3. Enhancement of incident response capability Basically keep the element of "[3] Enhancement of incident response capability" in the Third Policy ○ Continuously improve cross-sectoral exercises and CEPTOAR training that would be more practical for CI operators ○ Promote voluntary exercises by CI operators by broadly disseminating knowledge and know-how obtained through cross-sectoral exercises and providing a virtual exercise environment 4. Risk management and development of incident readiness Basically keep the element of "[4] Risk management" in the Third Policy and develop the element as "Risk management and preparation of incident readiness" ○ Expand the scope of measures and add those for assisting preparation of incident readiness based on the results of risk assessment from the viewpoint of mission assurance (including measures aimed at the Olympic and Paralympic games) ○ Promote "risk communication and consultation" and "monitoring and review," which are significant from the viewpoint of mission assurance 5. Enhancement of the basis for CIP Basically keep the element of "[5] Enhancement of the basis for CIP" in the Third Policy ○ Continue review of the scope of information sharing within and outside the CI sectors ○ Positively provide information obtained from international conferences, etc. to stakeholders ○ Promote security by design ○ Make appeals to the management layer of CI operators ○ Assist human resources development (cooperation among government, industry and academia for specific human resources development) 9

Select target paragraph3