ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC 1. Information Related to System Failures ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC 1. Information Related to System Failures Information related to system failures, including CISs outages, and signs and Hiyari-Hatto events (hereinafter referred to as "information related to system10 failures") needs to be handled with consideration given to the following three aspects: [i] proactive prevention of CISs outages, [ii] prevention of the spread damages and quick recovery from CISs outages, and [iii] prevention of recurrence through analysis and verification of CISs outage causes. Government organizations must provide such information to CI operators properly as necessary, while there is also a need to further enhance information sharing systems among CI operators and among interdependent CI sectors. As signs or Hiyari-Hatto events with no visible phenomena may eventually lead to CISs outages involving multiple CI sectors and CI operators, they should also be included in the scope of information sharing, in addition to actualized system failures. Therefore, the scope of information sharing in this Cybersecurity Policy is as shown in the figure below. CI services Actualization of phenomenon CISs outages System failures Signs and Hiyari-Hatto events Phenomena requiring cybersecurity security measures Impact level phenomenon Hindrance to safe and continuous provision of services Other services Figure. Scope of Information Sharing 10 It should be noted that the term "system" here includes not only so-called information systems, but also control systems used in plants or for system monitoring in various CI sectors, as well as IoT systems, etc. whose utilization is expected to spread rapidly in the future. 48

Select target paragraph3