IV. Activities Taken by Stakeholders 1. Activities by the Cabinet Secretariat (x) Individually make collaboration with cyberspace-related operators as necessary to provide appropriate information on a timely basis in the event of CISs outages (xi) Provide appropriate information on a timely basis to businesses in and outside CI sectors that are newly incorporated in the scope of information sharing (3) Enhancement of incident response capability (i) Obtain information on other ministries' exercises and training for CISs outage responses and consider means for collaboration with other ministries (ii) Obtain cooperation of responsible ministries for CI to provide opportunities for verification of CEPTOAR information communication functions (CEPTOAR training), periodically or upon requests from CEPTOARs (iii) Plan cross-sectoral exercise scenarios, implementation methods and verification issues, etc. and implement cross-sectoral exercises (iv) Study measures for improving cross-sectoral exercises (v) On occasions of cross-sectoral exercises, ascertain conditions of risk analysis results verification, early recovery procedures implemented by CI operators during CISs outages, and IT-BCP etc. studies, and provide the results to exercise participants (vi) Collect, accumulate and provide knowledge related to cross-sectoral exercise implementation methods, etc. (development of a virtual exercise environment, etc.) (vii) Diffuse and spread knowledge related to CIP gained from cross-sectoral exercises (viii)Promote individual human resources development as company-wide activities through encouraging implementation of exercise scenarios beyond duties and positions (4) Risk management and preparation of incident readiness (i) The following activities relating to risk assessment for the Olympic and Paralympic games a. Provide the Risk Assessment Guidelines for Mission Assurance to entities conducting relevant risk assessment b. Independently or jointly hold briefing sessions and lectures concerning risk assessment (ii) Generalize the Risk Assessment Guidelines for Mission Assurance so that they can be utilized by CI operators in their risk assessment also in normal times and improve the Manual for Prioritization of Information Security Measures as necessary (iii) Provide the results of the studies and analyses in this policy as data to be reflected in CI operators' risk assessment and development of the safety principles (iv) Utilize the results of the studies and analyses in this policy as data to be reflected in other activities under this Cybersecurity Policy (v) Offer support as necessary for promoting risk communication and consultation of CI operators among internal stakeholders (vi) Support risk communication and consultation of CI operators via the CEPTOAR council and through crosssectoral exercises (vii) Offer support to CI operators such as through compiling and presenting points to be incorporated in BCPs and contingency plans and viewpoints for verifying their effectiveness based on the concept of mission assurance 32

Select target paragraph3