IV. Activities Taken by Stakeholders
6. Voluntary Activities by CEPTOARs and the CEPTOAR Secretariat
(iii) Utilize the reference information provided as the results of the studies and analyses in this policy in own risk
assessment
(iv) Carry out the following for promoting and strengthening risk communication and consultation among
stakeholders directly or indirectly involved in risk management in providing CI services
a. Enhance risk communication and consultation among top management, cybersecurity departments,
departments responsible for information systems and control systems, user departments, and other internal
stakeholders; Ensure allocation of resources and develop own organizational structure required therefor
b. Enhance risk communication and consultation among stakeholders by fully utilizing opportunities for
information sharing, such as the CEPTOAR council and cross-sectoral exercises
(v) Propose environmental changes and risk sources which are difficult to analyze oneself but are worth studying
and analyzing as targets for the studies and analyses in this policy
(vi) Participate in the discussion and examination of the studies and analyses in this policy
(vii) Carry out the following for developing incident readiness
a. Develop BCPs and contingency plans based on the concept of mission assurance, create an organizational
structure for implementing these plans, and verify their effectiveness
b. When the relevant operator conducts risk assessment for the Olympic and Paralympic games, cooperate with
stakeholders with relationships to the core organization responsible for incident information sharing (the
"Olympic and Paralympic CSIRT (provisional title)")
(viii) Promote the strengthening of monitoring and review, such as the implementation of internal audits based on key
points for audits provided by the Cabinet Secretariat (including audits voluntarily outsourced to external
organizations)
(5) Enhancement of the basis for CIP
(i) Promote diversified and multilateral international cooperation by ascertaining overseas trends through expansion
of domestic CI operators' initiatives related to cybersecurity measures to foreign companies in the same industry
(ii) Understand the necessity of the matters indicated in "Responsibility of CI operators' executives and senior
managers" and implement them
(iii) Cooperate with the Cabinet Secretariat and compile relevant regulations and make them visible
(iv) Consider the use of products certified under a third-party certification system for control systems and related
equipment
(v) Secure and allocate management resources, such as budgets, systems and personnel, necessary for cybersecurity
measures in a planned manner
6. Voluntary Activities by CEPTOARs and the CEPTOAR Secretariat
(1) Enhancement of information sharing system
(i) Cooperate with the CEPTOAR council, CI operators, responsible ministries for CI, and the Cabinet Secretariat
and operate the information sharing system during normal circumstances and upon a CISs crisis
(ii) Carry out information sharing from NISC to CI operators in accordance with the information handling rules for
37