I. Introduction
3. Assessment of the Third Policy
With the aim of promoting voluntary efforts by CI operators, the Guidelines for Establishing Safety Principles for
Ensuring CI Security and Attachment thereof (the "Guidelines for Safety Principles") were revised in line with the
PDCA (Plan-Do-Check-Act) cycle. Each CI sector guideline and codes of conduct of respective CI operators such as
internal policies are now being reviewed on a voluntary basis in response to the revision of the Guidelines for Safety
Principles.
Given these, it is considered that the PDCA cycle itself, which allows CI operators to judge the necessity of review
and make improvements independently, is prevailing as their code of conduct.
However, the activities of "Check" and "Act" in the PDCA cycle are not sufficiently established, nor can be recognized
to have been disseminated to the degree that they are accepted as the code of conduct, as shown in the results of the
survey concerning the dissemination of safety principles, which was conducted by the Cabinet Secretariat with the aim
of ascertaining the current status of cybersecurity measures. The establishment of these activities is one of the remaining
challenges.
In the future, it is hoped that such behavior based on the abovementioned code of conduct is disseminated among all
stakeholders, encouraging them to continue efforts in line with this, and cybersecurity culture is thus formed among
them.
< Envisaged Future >
Stakeholders communicate with each other on a regular basis with the aim of strengthening measures in
preparation for any CISs outages and are making improvements to their measures constantly in order to reflect
experience concerning incident responses in their future efforts.
< Assessment >
Active information sharing between the public sector and the private sector is steadily progressing, with an increasing
number of reports being made from CI operators to responsible ministries and the National Center of Incident Readiness
and Strategy for Cybersecurity (NISC).
Regarding information sharing in the private sector, the secretariat of the CEPTOAR council was transferred to the
private sector, thereby enhancing their independence and positive attitude in information sharing among CEPTOARs.
Additionally, members of each CEPTOAR have increased and broader information exchanges have been contributing
to enriching knowledge on cybersecurity and creating ties among responsible personnel. The development of a better
environment for communication among stakeholders has thus been steadily advancing. Furthermore, ISACs2 have been
organized in some sectors and information sharing and countermeasures against cyberattacks are progressing.
Cross-sectoral exercises and training by CEPTOARs are also being conducted continuously to enhance incident
response capability. Participants are increasing significantly and response scenarios are made more and more
sophisticated. These activities are found to have contributed to enhancing response capability in line with the needs of
CI operators.
In the meantime, as threats are becoming increasingly serious, it is required to continue to improve communication
methods qualitatively and quantitatively through their classification and specification in light of respective purposes in
2
ISAC: Information Sharing and Analysis Center
4