III. Policies for CIP
5. Enhancement of the Basis for CIP
5. Enhancement of the Basis for CIP
As the social and technological environment surrounding CI continue to constantly change, it is necessary to raise
public awareness about cybersecurity and create shared awareness through making appeals to the top management of
CI operators, etc. in order to enhance the level of cybersecurity of the whole nation.
As shown in Figure "Critical Infrastructure Operator Measure Examples" and "Government Activities" it is
indispensable to enhance common foundation activities which support the entirety of this Cybersecurity Policy, for
maintaining the effectiveness of cybersecurity measures. The activities include establishment of basic plans,
development of human resources and career paths/proper personnel allocation, external explanations of cybersecurity
measures and identification of issues for new risks and risk sources resulting from IT related environmental changes.
Therefore, during the term of this Cybersecurity Policy, the Cabinet Secretariat continues review of the scope of
information sharing in and outside CI sectors as under the Third Policy, cooperates with other stakeholders in PR
activities, international collaboration and awareness-raising activities targeting top management, and also prepares
manuals on CIP-related regulations so that stakeholders can easily refer to appropriate regulations on a timely basis.
The Cabinet Secretariat also provides the knowledge obtained through the implementation of this policy for
application in other policies in this Cybersecurity Policy.
5.1 Review of the protection scope of CI
(1) Activities towards "protection as plane"
In order to achieve CIP for the purpose of mission assurance, "protection as plane" including supply chains need to
be ensured in consideration of the current status of interdependency among CI sectors and dependency on external
services (services provided by outsources or other peripheral businesses other than conventional CI operators) and in
light of environmental changes, a situation such that the advancement and expansion of new technologies are increasing
risks and possible damage for socioeconomic systems as a whole.
Efforts are being made to encourage CEPTOAR participation in existing CI sectors, ascertain the current status of
external services on which existing CI sectors are highly dependent, and review the scope of CI to be protected. However,
in the meantime, new types of businesses in multiple sectors have come to join CEPTOARs or have come to receive
certain information (such as newsletters compiling disclosed information) from the Cabinet Secretariat and new moves
to seek collaboration beyond the existing business fields are observed. The Cabinet Secretariat continues the review of
the CIP scope to cover a broader area for ensuring safe and continuous provision of CI services, while flexibly
responding to changes in social environment.
(2) Activities from the perspective of securing national security
Threats of increased cyberattack damage and changes in the social and technological environment in recent years
have increased the need of a security perspective in the protection of national life and socioeconomic activities. It is
necessary to continuously review the scope of CI sectors in order to strengthen measures in sectors where information
26