V. Assessment and Verification 2. Verification of This Cybersecurity Policy their readiness for CISs outages, and when they encounter CISs outages, they should assess their responses by themselves and should preferably disclose their self-assessment if possible. 2.3 Verification of policies by government organizations Under key policies of this Cybersecurity Policy, the government offers support in order to improve the effectiveness of cybersecurity measures taken by CI operators. Verification of policies is to be based on their contribution to the cybersecurity measures taken by CI operators under this Cybersecurity Policy. Detailed indexes are set as follows based on the "Goals of this Cybersecurity Policy" above. (1) Indexes for the key policy "maintenance and promotion of the safety principles" ○ Ratio of CI operators carrying out cybersecurity measures, which serve as the baseline as ascertained through the survey of the dissemination of the safety principles ○ Ratio of CI operators carrying out leading cybersecurity measures as ascertained through the survey of the dissemination of the safety principles (2) Indexes for the key policy "enhancement of information sharing system" ○ Number of cases of information sharing to and from NISC ○ Number of constituent members of each CEPTOAR (3) Indexes for the key policy "enhancement of incident response capability" ○ Number of participants in cross-sectoral exercises ○ Ratio of participants who assess the knowledge obtained through exercises as having contributed to the cybersecurity measures of the organization to which they belong ○ Participation in exercises and training implemented both inside and outside the organization, including cross-sectoral exercises (4) Indexes for the key policy "risk management and preparation of incident readiness" ○ Number of copies of Risk Assessment Guidelines for Mission Assurance distributed (or when it is publicized on the website, number of accesses to the relevant webpage), and number of participants in briefing sessions and lectures concerning risk assessment ○ Number of cases of interdependency analysis and environmental change studies implemented by the Cabinet Secretariat ○ Number of occasions of provision of opportunities for information exchanges for the CEPTOAR council and crosssectoral exercise stakeholders 45

Select target paragraph3