III. Policies for CIP 4. Risk Management and Preparation of Incident Readiness (ii) Generalize the Risk Assessment Guidelines for Mission Assurance so that they can be utilized by CI operators in their risk assessment also in normal times and improve the Manual for Prioritization of Information Security Measures, thereby further disseminating the purpose and methods of risk assessment based on the concept of mission assurance widely among CI operators Through these activities, it is expected that individual CI operators' risk assessment will achieve a certain standard and a certain level of accuracy in the future. 4.2.2 Investigation and analysis of new risk sources and risks, etc. In light of changes in the environment surrounding CI sectors, the Cabinet Secretariat conducts surveys on the current status and trends of major facilities and technologies from the perspective of cybersecurity, and analyses new risk sources inherent to such facilities and technologies and risks arising therefrom (hereinafter referred to as "new risk sources and risks"). Additionally, the Cabinet Secretariat continues analysis of spillover effects of CISs outages. In detail, the following activities are carried out, also taking into account viewpoints of the efficiency of each study/analysis and mutual reflection with other policies, and the results of the studies/analyses are provided to CI operators and are also utilized for improving measures under this Cybersecurity Policy. (1) Environmental change studies The Cabinet Secretariat carries out current status studies on environmental changes including analyses of new risk sources and risks, targeting IoT, FinTech, and other new technologies and systems expected to spread in CI sectors in the medium- and long-term, as well as institutions related thereto. As these studies and analyses produce better results when conducted over time in accordance with environmental changes, the Cabinet Secretariat conducts them continuously by flexibly changing the targets and scopes. New risk sources and risks that are common only across specific sectors, such as control systems or information systems, but could have a significant influence if not on all sectors will also be targeted. When any new risk sources and risks are identified through these studies and analyses or any new CI sectors are newly targeted, analysis of commonality across these sectors are to be carried out as a detailed investigation, as necessary. (2) Interdependency analysis As utilization of ICT continues to develop in each CI sector and interdependent relationships among CI sectors and with other sectors continue to grow, the understanding of interdependency in CI sectors becomes more and more important for conducting risk assessment and taking effective recovery measures in the event of CISs outages. For this reason, in this Cybersecurity Policy, the Cabinet Secretariat continuously carries out interdependency analysis, and also conducts restudy or reanalysis based on the results of the analyses under preceding Cybersecurity Policies if there are any changes in interdependency due to environmental changes or addition of new CI sectors. In addition, as the degree of IT dependency in CI sectors is closely related to interdependency analysis, detailed IT dependency studies are also periodically implemented. 23

Select target paragraph3