Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness Characteristics of Cyberattack Risks (iv) Possibility of a persistent attack It is possible for a cyberattack to continue persistently until its goal is accomplished. Some possible cases include cases where the same attack is carried out and the same damage incurred during system recovery when the system is returned with no specific measures taken to the state it was in before the damage, cases where an attack is carried out once again during system recovery, and cases where an attack is carried out once again after countermeasures have been taken to deal with the attack, using means to avoid those countermeasures. Even in closed environments that are not connected to the Internet or environments that are comprised of systems with a low level of versatility, there can also be cases where an attack is carried out after the collection of information about the system configuration and specifications through various means, over a long period of time. Matters to Be Considered with Regard to Response and Countermeasures [Basic point of view] Consideration of the possibility for the recurrence of a cyberattack and characteristics of the environment [Matters to be considered in the formulation and revision of CP and BCP]  Analyze, identify, and respond to (applying patches, removing malware, rebuilding    systems, etc.) the causes of the damage (software vulnerability, misconfiguration, etc.) before engaging in the recovery of CISs. Even when restoring services that make use of an emergency system, put the system into operation only after putting in place measures to counter an attack by the same means on the emergency system. In preparation for coming under another cyberattack during recovery, separate the system into a team that is responsible for taking countermeasures against the cyberattack, and a team that is responsible for the recovery of CISs. At the same time, review the division of roles and method of coordination and cooperation. In cases where signs of a persistent cyberattack are identified (such as repeated attack attempts over a long period of time, recurrence of an attack after measures have been put in place) as a result of investigations based on log analysis and other means, strengthen monitoring functions and systems for a certain period of time even after the recovery of CISs. If system recovery must be carried out in situations where the cause of damage has not been identified adequately, make assumptions for the possibility that programs, etc. created by the attacker remain, and strengthen monitoring functions and systems on the 39

Select target paragraph3