III. Policies for CIP 4. Risk Management and Preparation of Incident Readiness The Cabinet Secretariat promotes risk communication and consultation implemented by stakeholders related to CI protection with the aim of encouraging information and opinion exchanges among internal stakeholders and also contributing to the development of cross-sectoral information and opinion exchanges. Concrete activities are as follows. (i) Promote risk communication and consultation among top management, cybersecurity departments, departments responsible for information systems and control systems, user departments, and other internal stakeholders (ii) Utilize the CEPTOAR council and cross-sectoral exercises and promote enhancement of information and opinion exchanges in cooperation with diverse stakeholders, and collect information necessary for studies and analyses of new risk sources and risks 4.2.5 Promotion of monitoring and review The status ascertained as a result of risk assessment is expected to change over time. In order to identify any circumstances or other factors that may change or invalidate risk assessment results and properly respond to fluctuations in risks, it is necessary to create a mechanism to manage risks in an appropriate manner such as constantly monitoring and revising risk assessment results as needed or otherwise, and maintain risk management functions continuously and effectively. Therefore, the Cabinet Secretariat promotes CI operators' monitoring and review of their risk management and incident readiness. More specifically, the Cabinet Secretariat provides key points for audits compiled based on the viewpoint of mission assurance to assist CI operators' voluntary internal audits, etc., thereby promoting their monitoring and review. 4.3 Establishment of a process of synergizing the relevant policies The Cabinet Secretariat utilizes the results of studies and analyses of the abovementioned measures in activities under other key policies as reference data for the purpose of contributing to other policies in this Cybersecurity Policy. In addition, the Cabinet Secretariat conducts studies and analyses as necessary regarding new risk sources and risks requiring cross-sectoral measures that are revealed as a result of implementing other policies. 25

Select target paragraph3