II. Items that Should Ideally be Prescribed in the Safety Principles (B) Establishment of CSIRT, etc., and Agreement with the Relevant Departments on Division of Labor and Other Matters One of the organizational systems that are necessary for the execution of contingency plans and business continuity plans that take into consideration the characteristics of cyberattack risks, is the establishment of CSIRT16 (or an organization that fulfills the same functions) internally within the CI operators. It is important for an organization such as CSIRT to agree on the division of labor and response procedures with the relevant departments beforehand. In particular, for CI operators that have operating environments such as control systems, it is necessary to be fully aware of the possibility that the OT-related department will require specialized knowledge to deal with the situation during the occurrence of CISs outages. From the perspective of dealing promptly with cyberattacks, it is recommended to consider the need to establish, from times of normalcy, incident readiness, which includes organizations that have specialized knowledge of information security. For example, it is effective to collaborate with cyberspace-related operators and information security related agencies. (C) Preventing the Spread of Damage and Restoring Services Based on the Response Plans In cases where events such as a cyberattack are actually detected, and it is decided that response is necessary based on the results of triage, follow the contingency plan and business continuity plan to put in place response measures, including detailed analysis of the event (including forensics of the information system), sharing of information and coordination with the stakeholders (including PR activities directed toward customers), and efforts to prevent the spread of damage and restore services. With regard to new lessons drawn through the response to CISs outages, incorporate these into the continual improvement processes in the contingency plan and business continuity plan, with the aim of applying these lessons drawn to future response activities and countermeasures. (3) Conducting Exercises and Training Periodically conduct exercises and training to ensure the effectiveness of the response plans to CISs outages (contingency plan, business continuity plan, etc.), and to improve the skills of the personnel responsible for putting the measures in action. From the perspective of improving overall protective capability for CIP, it is also recommended to conduct joint exercises and training with CI operators in the same industry, supply-chain, and stakeholders, as well as to examine case studies (studies of past incident responses by other operators). 16 Abbreviation for Computer Security Incident Response Team. Refers to an organization established to deal with incidents related to computer security, such as information system failures caused by cyberattacks. There are cases where CSIRT is established as a permanent organization and where it is established only during the occurrence of an incident, depending on the operator. 23

Select target paragraph3