I. Introduction
3. Assessment of the Third Policy
order to further strengthen preventive measures against CISs outages. On the other hand, it should also be said that
efforts to reflect experience of CISs outages in future measures in a cross-sectional manner are not necessarily sufficient
although efforts have been made to enhance incident response capability through exercises and training. This needs to
be addressed. Additionally, in order for CIP covering a broader area ("protection as plane"), constant improvements
through analysis and sharing of case examples are indispensable and efforts therefor must be continued.
< Envisaged Future >
The fact that stakeholders are collaboratively making efforts for CIP is widely understood by the general public
and this gives them peace of mind. Well-established communication among diverse stakeholders enables them
to take calm responses in the event of CISs outage.
< Assessment >
Stakeholders have reliably come to have better communication as mentioned above. Additionally, the Third Policy
and the achievement thereunder are publicized and videos of cross-sectoral exercises are publicly made available online.
In this manner, PR activities have been carried out with the aim of reassuring the general public by having them better
understand diverse efforts being made based on the Third Policy.
On the other hand, public concern over CIP cannot be fully relieved partly due to increasing news reports on
information leakage caused by targeted mail attacks. Such concern needs to be eliminated.
Efforts to enhance incident response capability have been made through constantly checking the current status of
incident response through exercises and training as mentioned above. Collaboration with overseas organizations, etc.,
such as information sharing under various frameworks, has also been promoted.
In order to reassure the general public and ensure calm responses upon CISs outages, it is necessary to continue and
strengthen these efforts in collaboration with diverse entities in and outside Japan, while sharing collected and analyzed
information on new risks, sources of risks and the latest incidents among stakeholders, and actively providing
information to the general public based on the concept of mission assurance.
< Envisaged Future >
These efforts are publicized as the Cybersecurity Policy and are assessed regularly and revised properly as
needed.
< Assessment >
Cybersecurity measures have been compiled and publicized as the Cybersecurity Policy since 2000 and the progress
of the activities thereunder in each fiscal year has been checked and verified from the perspective of measuring the
output of individual activities. Activities during the Cybersecurity Policy term have also been assessed once every three
to five years from the perspective of measuring the outcome, i.e., to what extent society has come closer to the envisaged
future, and the Cybersecurity Policy has been reviewed based on the results of the assessment.
Through these efforts, CIP in Japan has been implemented steadily for 16 years since the establishment of the Special
Action Plan, or for 11 years under the current style of the First Policy to the Third Policy, and has been progressing
5