III. Policies for CIP 3. Enhancement of Incident Response Capability 3. Enhancement of Incident Response Capability During the term of this Cybersecurity Policy, efforts for comprehensively strengthening the CISs outage response structure are continued based on the achievement of various exercises and training that have been conducted under the Third Policy for the purpose of improvement and verification of incident response capability. Cross-sectoral exercises are further improved, while maintaining the current mechanism incorporating CI operators' needs, as core means of strengthening the incident response system in CI sectors, by reviewing and revising exercise scenarios in consideration of the latest attack techniques. More specifically, cross-sectoral exercises will be improved so that they better fit the actual state of CI operators' incident handling and internal rules. Furthermore, cross-sectoral exercises should be mutually linked and complement CEPTOAR training and other exercises and training implemented by responsible ministries for CI, and the vertical-directional systems within each CI sector and the horizontal-directional systems between CI sectors should be enhanced to reap synergistic benefits. 3.1 Improvement of cross-sectoral exercises During the term of this Cybersecurity Policy, the Cabinet Secretariat continues to implement cross-sectoral exercises, which are initiatives unique to Japan bringing together all CI operators, while constantly improving them in order to contribute to the maintenance and improvement of CIP capability through the dissemination of the results of the exercises to overall CI sector. In this process, accumulated operation methods and outcome should be fully utilized to enhance the content of the exercises so that these cross-sectoral exercises surely contribute to strengthening the incident response system. 3.1.1 Qualitative improvement in planning cross-sectoral exercises During the term of this Cybersecurity Policy, the Cabinet Secretariat positively takes measures to ensure that the exercises incorporate knowledge and issues obtained through exercise operation in the past, issues revealed in other policies and exercises conducted by other organizations, as well as the latest trends related to risk sources which may cause CISs outages, with the aim of continually improving cross-sectoral exercises. In addition, the Cabinet Secretariat plans and organizes exercises, considering the participation of not only CI operators but also other stakeholders closely relating to the maintenance of CI operators' information systems and businesses outside CI sectors that support the provision of CI services. The Cabinet Secretariat also continues improving exercise processes in order to contribute to the further enhancement of verification related to CI operators' cybersecurity measures, CISs outage early recovery process and IT-BCP. Additionally, the Cabinet Secretariat provides knowledge and issues obtained through these exercises as reference data for other policies in this Cybersecurity Policy. 3.1.2 Promotion of lessons learned from cross-sectoral exercises During the term of the Third Policy, the number of exercise participants increased significantly, and the percentage 18

Select target paragraph3