Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness Characteristics of Cyberattack Risks (vi) Possibility for the occurrence of attacks that are difficult to detect In cases where inadequate measures for detection are put in place against cyberattacks, there is a possibility for a sustained attack over a long period of time without the attack being recognized. There are cases where detection is avoided through the deletion of logs that lead to the detection of illegal acts, and cases where figures that are different from the actual figures are displayed in order to make it appear as if the systems were operating normally. The longer it takes to detect an attack, the greater the possibility for the spread of damage. Even after an attack is detected, there are many cases where it is difficult to identify the attackers and objective of the attack. Matters to Be Considered with Regard to Response and Countermeasures [Basic point of view] Clarification of disclosure procedures for information, etc. that are related to impact investigations [Matters to be considered in the formulation and revision of CP and BCP]  In countering attacks with scope of impact that maintenance operators such as system vendors have difficulty in identifying, there may be cases where requests for cooperation in investigation are made to external incident response organizations or external security vendors. In such situations, it may sometimes be necessary to disclose logs or equipment that has been breached. Hence, clarify the necessary procedures (person responsible for disclosure, assessment criteria, organizations to which disclosure is permitted, and means of provision in order to transmit the information, including confidential information, safely), the information to be disclosed (log items, format, etc.) and any restrictions (types of information that cannot be disclosed, such as confidential information or personal information, etc.). (Countermeasures during normal times, in preparation for the activation of CP and BCP)  To investigate indicators of anomaly caused by an attack, have a good grasp of the configuration of critical information systems, and of the operations of the system during normal times as well as the contents of its output logs. Put in place measures to protect  the systems against the tampering with and deletion of logs. To investigate attacks that have not been detected for a long period of time by tracing them back to the past, store various logs obtained during normal times for a certain period. Review the storage period by taking into consideration the storage period for logs recommended by information security related agencies and security vendors. Refer to publicly available information from information security related agencies, and verify 43

Select target paragraph3