Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Characteristics of Cyberattack Risks (iv)
Possibility of a persistent attack
It is possible for a cyberattack to continue persistently until its goal is accomplished. Some
possible cases include cases where the same attack is carried out and the same damage
incurred during system recovery when the system is returned with no specific measures taken
to the state it was in before the damage, cases where an attack is carried out once again during
system recovery, and cases where an attack is carried out once again after countermeasures
have been taken to deal with the attack, using means to avoid those countermeasures.
Even in closed environments that are not connected to the Internet or environments that are
comprised of systems with a low level of versatility, there can also be cases where an attack
is carried out after the collection of information about the system configuration and
specifications through various means, over a long period of time.
Matters to Be Considered with Regard to Response and Countermeasures
[Basic point of view]
Consideration of the possibility for the recurrence of a cyberattack and characteristics of the
environment
[Matters to be considered in the formulation and revision of CP and BCP]
Analyze, identify, and respond to (applying patches, removing malware, rebuilding
systems, etc.) the causes of the damage (software vulnerability, misconfiguration, etc.)
before engaging in the recovery of CISs. Even when restoring services that make use of
an emergency system, put the system into operation only after putting in place measures
to counter an attack by the same means on the emergency system.
In preparation for coming under another cyberattack during recovery, separate the
system into a team that is responsible for taking countermeasures against the
cyberattack, and a team that is responsible for the recovery of CISs. At the same time,
review the division of roles and method of coordination and cooperation.
In cases where signs of a persistent cyberattack are identified (such as repeated attack
attempts over a long period of time, recurrence of an attack after measures have been
put in place) as a result of investigations based on log analysis and other means,
strengthen monitoring functions and systems for a certain period of time even after the
recovery of CISs.
If system recovery must be carried out in situations where the cause of damage has not
been identified adequately, make assumptions for the possibility that programs, etc.
created by the attacker remain, and strengthen monitoring functions and systems on the
39