Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness Characteristics of Cyberattack Risks (ii) Growing sophistication of means of attack The means of cyberattacks are constantly evolving and becoming increasingly sophisticated. Some possible attacks include attacks that are difficult to avoid simply through countermeasures that are based on existing technology, such as attacks that target new vulnerabilities, and attacks that are carried out using new means that business operators have not anticipated at all. In the event that an attack is carried out using new means, there is a possibility that the organization will not be able to accurately grasp the degree and scope of its impact. Matters to Be Considered with Regard to Response and Countermeasures [Basic point of view] Regular gathering of information on the means of attack, and timely reviews of CP and BCP [Matters to be considered when formulating or revising the CP and BCP]  With regard to the means of attack, regularly gather information provided by stakeholders such as JPCERT/CC, verify if the new means of attack can be handled based on the existing CP and BCP, and revise the plans where necessary.  When information about new means of attack are obtained, quickly verify the status of countermeasures put in place by the organization, the effectiveness of these measures,   and the presence of any damage. At the same time, strengthen the monitoring functions and systems for a certain period of time in preparation for an attack on the organization. In order to keep up with the growing sophistication of the means of cyberattacks, add human resources with adequate knowledge and ability to make judgements in the area of cybersecurity to the systems when formulating or revising CP and/or BCP, and during treatment. Where necessary, actively utilize external specialist organizations. Even in situations where the scope of impact and other information are not accurately grasped, review the necessary items to be investigated and the order of priority for the investigation when formulating the CP and BCP, so as to maintain the minimum required service level in the provision of CISs. (Countermeasures during normal times, in preparation for the activation of CP and BCP)  When a new means of attack is identified as a cyberattack risk, take thorough steps to familiarize key personnel, who may be involved in the treatment when the plans are activated, with the management policies of the risks in question, and the CP and BCP that have been revised. 36

Select target paragraph3