III. Policies for CIP
1. Maintenance and Promotion of the Safety Principles
The main section, measures section, and manual are to be reviewed once every three years in principle, but this does
not apply when any significant changes beyond expectations occur in social trends, etc. In particular, looking toward
the Olympic and Paralympic games in 2020, reviews are to be conducted on a timely basis.
1.2 Continual improvement of the safety principles
CI operators and responsible ministries for CI continually improve the safety principles based on knowledge learned
from experiences of each CI operators' incident responses in order to maintain and enhance the protective capability of
CI as a whole.
In detail, they make continual improvement of the safety principles through risk assessment, by identifying issues
from operation of cybersecurity measures, internal/external audits, results of studies and analyses of environmental
changes concerning IT, exercises, training and CISs incident responses. When verifying the safety principles, the
Guidelines as well as social trend changes and new knowledge released by the Cabinet Secretariat are to be used.
Additionally, the Cabinet Secretariat and responsible ministries for CI continue efforts for appropriately improving
institutional frameworks as necessary for maintaining safety, by means such as through positioning cybersecurity
measures as safety regulations among relevant laws and embodying the service maintenance level in relevant laws so
that appropriate cybersecurity measures are surely taken from the viewpoint of mission assurance.
The Cabinet Secretariat carries out survey on the improvement of the safety principles by the responsible ministries
for CI each fiscal year and releases the results thereof.
1.3 Promotion of the safety principles
The Cabinet Secretariat conducts a questionnaire survey and visits to CI operators every year for the purpose of
examining their concrete measures and further accurately ascertaining how the safety principles have been promoted
among CI operators. Survey items are to be reviewed as needed to better promote the safety principles and improve CI
operators' activities.
Specifically, survey items that enable more detailed and accurate understanding of the current status and survey items
for ascertaining the level of reaching the envisaged future are to be added. Furthermore, questionnaires are designed to
enable CI operators to conduct a self-check and ascertain their own achievement levels, issues and solutions through
responding to questions.
Visits to CI operators are also conducted with the aim of verifying hypotheses formed on the results of the
questionnaire survey and collecting best practices.
Results of these questionnaire survey and visits are released every fiscal year, in principle, and are utilized for the
improvements of measures under this Cybersecurity Policy.
13