Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Characteristics of Cyberattack Risks (i)
The presence of attackers, and diverse motives of attack
Cyberattacks, unlike natural disasters, are caused by attackers with a motive. The motives of
attack are becoming increasingly diverse, including stealing money and/or information,
declaration of principles or assertions, and suspension of services through the destruction of
systems. Attacks carried out through various means, corresponding with the diverse range of
attackers and motives of attack, are conceivable, ranging from attacks planned and carried out
by organizations to attacks carried out through internal criminal acts. However, in many cases
it is difficult to identify the attacker and motive of attack beforehand.
Matters to Be Considered with Regard to Response and Countermeasures
[Basic point of view]
Recognition of cyberattack risks, and formulation of scenarios leading up to the occurrence
of damage
[Matters to be considered in the formulation and revision of CP and BCP]
Identify the threat of a cyberattack that could lead to CISs outages in the organization
(such as targeted attacks using malware and DDoS attacks) as well as the impact of such
an attack. For attacks that have a particularly significant impact on the business, draw
up scenarios leading up to the occurrence of damage, and consider the treatment to that
scenario.
▶ Example of scenario leading up to the occurrence of damage
Due to devices infected with malware (terminals, USB drives, etc.) brought in by
maintenance personnel, malware infects the information systems within the
organization, and further via the network, invades critical information systems that
are the ultimate target of the attack, leading to manipulation and destruction of the
system, and leakage of confidential information. As a result, a serious impact on the
continuation of services and businesses is made.
Even in cases where there are concerns for the occurrence of a cyberattack, such as in
cases that advanced notification of an attack, suspicions of information leakage, or
indicative signs of an attack (such as suspicious communications and increase in logs)
is detected, consider the possibility for the need to take steps, such as moving to an alert
status in preparation for the occurrence of an attack or outage, or carrying out emergency
inspections of the countermeasure status.
▶ Examples of situations where there are concerns for the occurrence of a cyberattack
Suggestions of a DDoS attack on systems that provide CISs through the Internet, in
which money or the suspension of specific business activities is demanded.
35