III. Policies for CIP
2. Enhancement of Information Sharing System
awareness sharing among stakeholders and ensuring prompt and effective information sharing. Through these efforts,
the Cabinet Secretariat works on promoting effective information sharing among stakeholders based on concrete criteria
with regard to information on cyberattacks, etc. that are highly likely to have an expansive influence within and outside
the relevant sector. In addition, considering the recent trend that cyberattacks have come to target control systems, which
used to be considered closed and safe, this Cybersecurity Policy clearly states that attacks to control systems, including
IoT systems that are expected to be further disseminated in the future, are also included in the information to be shared.
During the term of this Cybersecurity Policy, stakeholders are requested to conduct information sharing to and from
NISC and thus promote information sharing in line with the ATTACHMENT under the reviewed information sharing
system. When any change occurs in the environment, the system is to be reviewed as needed.
Review of the protection scope of CI is also continued in order to achieve "protection as plane" covering a broader
area for the purpose of ensuring safe and continuous provision of CI services (refer to 5.1(1) below for details).
2.3 Promotion of CI operators' activities
Enrichment of information sharing within and between CEPTOARs is expected for further activating activities of CI
operators, in addition to individual efforts by CI operators themselves.
In particular, CI operators should proactively work towards their own information sharing activities, in addition to
constructing and enhancing CISs outage response structure, such as CSIRT. CEPTOARs are also expected to continue
sharing information provided by the Cabinet Secretariat as during the term of the Third Policy, while applying rules
decided upon by constituent members regarding agreements on the handling of such provided information, maintenance
of confidentiality and provision of information to parties outside the constituent members, under a situation where a
PoC4 is established to allow contact between constituent members and with non-members in case of emergency.
It is also expected that efforts for further activating sharing activities are made such as through appointing coordinators
who will carry out information collection and decision making within CEPTOARs, sharing predictive information and
CISs outage examples during ordinary situations, and enhancing functions required for information sharing between
CEPTOARs and with the CEPTOAR council. ISACs have already been organized in some sectors that are carrying out
leading activities, and sharing, examination and analysis of information within respective ISACs and information
sharing with foreign ISACs are now being promoted. Promoting participation in ISACs and information sharing among
different ISACs will contribute to further activating information sharing among CI operators and their further positive
activities for cybersecurity measures.
Additionally, expansion of internal and external information sharing should be maintained through the expansion of
constituent members of respective CEPTOARs and establishment of new CEPTOARs. Qualitative and quantitative
improvements are expected for sharing information handled by CI operators, covering not only IT but also OT, for the
purpose of ensuring collaboration with domestic and foreign diverse entities, and safe and continuous provision of CI
services.
4
PoC: Point of Contact
16