IV. Activities Taken by Stakeholders 1. Activities by the Cabinet Secretariat IV. Activities Taken by Stakeholders 1. Activities by the Cabinet Secretariat (1) Maintenance and promotion of the safety principles (i) Revise the Guidelines for Safety Principles and officially release the results with the aim of promoting measures cited in this Cybersecurity Policy (ii) Implement studies on changes in social trends and newly obtained knowledge as necessary, and officially release the results (iii) Support continued improvements of the CI sector safety principles through (i) and (ii) above (iv) Obtain cooperation of responsible ministries for CI to implement studies every year to ascertain the conditions of continued improvements of the safety principles in each CI sector, and officially release the results; Continue efforts, together with responsible ministries for CI, for appropriately improving institutional frameworks, such as positioning cybersecurity measures as safety regulations among relevant laws as necessary for maintaining safety and embodying the service maintenance level in relevant laws for ensuring implementation of proper cybersecurity measures from the viewpoint of mission assurance (v) Obtain cooperation of responsible ministries for CI and CI operators to implement studies every year on the conditions of the dissemination of the safety principles, and officially release the results (vi) Utilize the results of the survey on the dissemination of the safety principles in improving activities under this Cybersecurity Policy (2) Enhancement of information sharing system (i) Operate the information sharing system during normal circumstances and upon a CISs crisis and review the system as necessary (ii) Collect information to be provided to CI operators and share information from NISC in an appropriate and timely manner (iii) Collect and analyze information on domestic and overseas incidents and cooperate with cybersecurity related agencies that are offering support (iv) Appropriately operate the mechanisms of recommendations, etc. prescribed in the Basic Act on Cybersecurity (v) Promote the establishment of a mechanism to collect information on CISs outages and risks in a cross-sectoral manner and secure resources necessary for the operation of the mechanism (vi) Obtain cooperation of responsible ministries for CI to periodically implement studies, hearings, etc. for ascertaining conditions of each CEPTOAR's functions and activities; Introduce leading CEPTOAR activities (vii) Offer support to the CEPTOAR secretariat and CI operators through the provision of the environment necessary for information sharing (viii)Continue cooperating with CEPTOAR participating in the CEPTOAR council and implement support for management and activities of the council (ix) Prepare environments required for enhancement of activities of the CEPTOAR council and for accumulation and sharing of know-how 31

Select target paragraph3