III. Policies for CIP
4. Risk Management and Preparation of Incident Readiness
Table 3 Standard Risk Management Process (example)
Risk management
Establishing the context of organization
Risk assessment
Risk identification
Risk analysis
Risk assessment
Risk treatment
Risk acceptance
Risk communication and consultation
Monitoring and review
4.2 Promotion of risk management
Risk management should basically be optimized by each CI operator individually to suit their organization. The
significance of risk assessment seems to have been widely recognized by many CI operators as suggested by the fact
that an increasing number of CI operators mention the implementation of risk assessment in cybersecurity basic policies
they voluntarily establish. On the other hand, some CI operators, despite being aware of the significance, have yet to
conduct risk assessment due to such reasons as the lack of knowledge on concrete measures. The concept and
implementation methods of risk assessment have not been necessarily disseminated sufficiently. It is also true that some
activities, such as cross-sectoral study/analysis and opinion exchanges, are not easily carried out solely within individual
CI operators.
Therefore, the Cabinet Secretariat takes the following measures to promote risk management of CI operators.
4.2.1 Dissemination of risk assessment
It is necessary to maintain safe and continuous provision of CI services, which are fulfilling indispensable roles and
functions in socioeconomic systems. Accordingly, what should be prioritized is the concept of mission assurance, under
which CI operators fulfill expected roles and functions and conduct risk assessment for the purpose of ensuring safety
of CI services they provide and continue providing services by preventing suspension or quality loss unacceptable for
themselves and other stakeholders to the extent possible, and promote risk countermeasures under top management's
comprehensive judgement based on the results of risk assessment, thereby aiming to achieve their goals.
Given these, the Cabinet Secretariat endeavors to encourage more and more CI operators to conduct risk assessment
based on the concept of mission assurance. Concrete activities are as follows.
(i) Disseminate the purpose and methods of risk assessment based on the concept of mission assurance widely among
relevant entities by encouraging them to refer to the Risk Assessment Guidelines for Mission Assurance7 in risk
assessment looking toward the Olympic and Paralympic games, and also promote such risk assessment at related
briefing sessions and lectures
7
Guidelines established by the Cabinet Secretariat in September 2016, targeting providers of CI services that may exert significant
influence on the operation of the Olympic and Paralympic games
22