V. Assessment and Verification
1. Assessment of This Cybersecurity Policy
○ Voluntary activities based on each stakeholder's awareness of their responsibilities are disseminated as their
respective code of conduct and such behavior contributes to forming cybersecurity culture.
○ Stakeholders communicate with each other on a regular basis with the aim of strengthening measures in
preparation for any CISs outages and are making improvements to their measures constantly in order to reflect
experience concerning incident responses in their future efforts.
○ The fact that stakeholders are collaboratively making efforts for CIP is widely understood by the general public
and this gives them peace of mind. Well-established communication among diverse stakeholders enables them to
take calm responses in the event of CISs outage.
○ These efforts are publicized as the Cybersecurity Policy and are assessed regularly and revised properly as needed.
○ These efforts being made by stakeholders have become steadily rooted as measures contributing to the sustainable
development of society.
1.2.2 Detailed future visions for respective stakeholders
(1) For all stakeholders
Detailed future visions common to all stakeholders are as follows.
○ Stakeholders possess accurate awareness of their own status and independently establish their own activity goals.
○ All required initiatives are progressing and periodic verification is carried out individually on the progress of one's
own measures and policies. Stakeholders are also able to proactively cooperate with other stakeholders, while
mutually maintaining an understanding of their activity conditions.
○ In responses during CISs outages, stakeholders understand who should collect what kinds of information, with
whom they should share what kinds of information, and what they themselves should do in accordance with the
scale of the CISs outages.
○ In addition to independent responses, stakeholders are able to carry out controlled responses in collaboration with
other stakeholders as necessary.
(2) CI operators
Detailed future visions for CI operators are as follows.
○ The following matters related to cybersecurity governance are fully disseminated among CI operators.
-Cybersecurity measures are examined not just from information system construction and operation perspectives,
but also from a business management perspective.
-CI operators have put in place a system that allows appropriate involvement of each of the parties responsible
for system construction and operation and business management.
-CI operators understand what measures they themselves should implement in accordance with the CI services
they should protect and their service maintenance level.
- CI operators are endeavoring to disclose information on their approach to cybersecurity measures during normal
times and their responses upon occurrence of an incident.
41