Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Figure 1: Example of Flow from the Occurrence of a Cyberattack to Recovery
(Various other flows, apart from the following, are also possible.)
Example 1: In the case of working toward swift recovery of services
Service provision level (ability)
High
Cyberattack
Occurrence
of anomaly
Recovery time objective
Normal service
level
Recovery level
objective
Treatment
based on
contingency
plan
Operation during
normal times
Treatment based
on business
continuity plan
Treatment for full
recovery
Low
Time
Example 2. In the case of treatment based on safety regulations, etc. before the start of
recovery work (treatment of damage in the case of disaster, accidents, or other emergencies)
Service provision level (ability)
High
Cyberattack
Safety measures
(Suspension of services, etc.)
Occurrence
of anomaly
Recovery time objective
Normal service
level
Recovery level
objective
Operation during
normal times
Treatment
based on
contingency
plan
Treatment based
on safety
regulations,
etc.*
↑
Treatment based
on business
continuity plan
Treatment for full
recovery
Low
Time
* Treatment based on safety regulations, etc. refers to treatment that focuses on reducing and
suppressing damage, and generally does not change whether or not the cause of damage is a
cyberattack. On the other hand, in cases where IT is used in the treatment, it would be preferable to
consider the characteristics of cyberattack risks.
The characteristics of cyberattack risks described hereafter are mutually connected, and the
matters to be considered for a certain characteristic may also be effective on other
characteristics. Consequently, in the formulation or revision of the CP and BCP, in addition to
the matters to be considered with regard to a specific characteristic, it is also necessary to review
the treatment and countermeasures based on matters to be considered for other characteristics.
34