II. Items that Should Ideally be Prescribed in the Safety Principles
(B) Establishment of CSIRT, etc., and Agreement with the Relevant Departments on Division
of Labor and Other Matters
One of the organizational systems that are necessary for the execution of contingency plans and
business continuity plans that take into consideration the characteristics of cyberattack risks, is
the establishment of CSIRT16 (or an organization that fulfills the same functions) internally
within the CI operators. It is important for an organization such as CSIRT to agree on the
division of labor and response procedures with the relevant departments beforehand.
In particular, for CI operators that have operating environments such as control systems, it is
necessary to be fully aware of the possibility that the OT-related department will require
specialized knowledge to deal with the situation during the occurrence of CISs outages.
From the perspective of dealing promptly with cyberattacks, it is recommended to consider the
need to establish, from times of normalcy, incident readiness, which includes organizations that
have specialized knowledge of information security. For example, it is effective to collaborate
with cyberspace-related operators and information security related agencies.
(C) Preventing the Spread of Damage and Restoring Services Based on the Response Plans
In cases where events such as a cyberattack are actually detected, and it is decided that response
is necessary based on the results of triage, follow the contingency plan and business continuity
plan to put in place response measures, including detailed analysis of the event (including
forensics of the information system), sharing of information and coordination with the
stakeholders (including PR activities directed toward customers), and efforts to prevent the
spread of damage and restore services.
With regard to new lessons drawn through the response to CISs outages, incorporate these into
the continual improvement processes in the contingency plan and business continuity plan, with
the aim of applying these lessons drawn to future response activities and countermeasures.
(3) Conducting Exercises and Training
Periodically conduct exercises and training to ensure the effectiveness of the response plans to
CISs outages (contingency plan, business continuity plan, etc.), and to improve the skills of the
personnel responsible for putting the measures in action. From the perspective of improving
overall protective capability for CIP, it is also recommended to conduct joint exercises and
training with CI operators in the same industry, supply-chain, and stakeholders, as well as to
examine case studies (studies of past incident responses by other operators).
16
Abbreviation for Computer Security Incident Response Team. Refers to an organization established to deal with incidents related to computer
security, such as information system failures caused by cyberattacks. There are cases where CSIRT is established as a permanent organization
and where it is established only during the occurrence of an incident, depending on the operator.
23