II. Items that Should Ideally be Prescribed in the Safety Principles
Verify the threat information that is provided regularly by information security related agencies
and information on the analysis and countermeasures on the threat information. In cases where
the threat information is assessed to have a high degree of urgency, conduct an information
security risk assessment urgently, and decide on the need for additional risk treatment measures.
(D) Participation in Information Sharing Activities for Sectors with a High Level of Expertise
With cyberattackers constantly coming up with new means to carry out cyberattacks, the
possibility for high-level cyberattacks that target specific CI sectors is also conceivable. Hence,
one of the countermeasures is to participate in information sharing activities for sectors with a
high level of expertise, such as ISAC,13 and to apply the information collected through these
activities to daily efforts toward risk treatment.
(2) Addressing CISs Outages
(A) Formulation of Contingency Plans and Business Continuity Plans in Preparation for
Cyberattacks
In the event of CISs outages, in addition to securing safety, it is also necessary to restore
conditions to an acceptable level within an acceptable timeframe. As such, it is important to
ensure incident readiness in preparation against the occurrence of CISs outages.
In view of that, formulate a contingency plan,14 which sets out the policies for initial response
(response during an emergency), and the business continuity plan,15 which sets out the policies
for recovery measures aimed at ensuring continuity of the business (or formulate plans that sets
out the same policies as these plans), and establish the necessary organizational systems to
execute these plans.
In particular, when formulating or revising contingency plans and business continuity plans
with the aim of ensuring readiness against cyberattacks, which is one of the events that can lead
to CISs outages, it is recommended to refer to Annex 3: Characteristics of Cyberattack Risks
Associated with Incident Readiness, and Matters to Be Considered in the Response and
Countermeasures. CI operators that have already prepared a business continuity plan should
also draw up a separate plan aimed at achieving complete restoration from the target restoration
level to normal service level (business recovery plan).
13
Abbreviation for Information Sharing and Analysis Center. The ICT-ISAC JAPAN includes ICT-ISAC, Financials ISAC Japan, and JEISAC, among others.
14
In the 4th Cybersecurity Policy, it refers to plans that specifically set out beforehand, from the implementation aspect, the policies, procedures,
and readiness on the initial response (emergency response) that should be taken by the management and employees after the occurrence of
CISs outages in a CI operator, or after identifying the possibility for the occurrence of CISs outages.
15
In the 4th Cybersecurity Policy, it refers to plans that aim to restore CISs that have been impacted by CISs outages in a CI operator to an
acceptable level within an acceptable timeframe, based on the concept of mission assurance, and which sets out beforehand the target level,
order of priority, and other policies, procedures, and readiness toward recovery.
22