II. Items that Should Ideally be Prescribed in the Safety Principles
that status.
From the perspective of realizing the safe and continuous provision of CISs across the entire
CI sector that the organization belongs to, it is also effective to exchange opinions with other
stakeholders, including other CI operators and responsible ministries for CIP and agencies with
jurisdiction, on the respective roles and the sharing of responsibility, and structure of
information sharing and reporting.
4.2. The “Do” Perspective
4.2.1. The Operational Perspective
(1) Introduction and Operation of Information Security Measures
(A) The Introduction of Security Management Measures, and Establishment and Execution of
Operational Processes
Based on the plans for addressing information security risks, move forward on the introduction
of the security management measures that have been decided upon in the information security
risk treatment, and establish and execute processes to ensure the effective and secure operation
of these measures.
(B) Detection of Events That Lead to CISs Outages, and Making Prompt Decisions to Tackle
the Problem
In addition to building mechanisms that are capable of the early detection of events that could
lead to CISs outages (such as cyberattacks and the anomalous condition of information systems)
by grasping the baseline for data that shows the operational status of information systems
related to the provision of CISs and combining multiple monitoring results such as alerts and
logs, continue sharing events with the relevant departments, etc. following detection, and
establish operational processes such as triage (conducting an impact analysis of events such as
cyberattacks, and assigning degree of priority for responses).
Through the aforementioned monitoring and detection systems, in situations where specific
signs of cyberattack have been identified, it is important to make a prompt decision on the
advisability of taking action against the cyberattack through security management measures
that have already been introduced (deployment of monitoring functions). At the same time,
corresponding to the results of the decision, it is also important to implement dynamic response
measures, such as by reviewing the security management measures that have already been
introduced (including tuning work for the various devices), or by introducing new security
management measures.
(C) Threat Information, Its Analysis, and Verification of Information on Countermeasures
21