Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness Characteristics of Cyberattack Risks (v) Possibility for the occurrence of simultaneous and multiple attacks In the case of cyberattacks, regardless of the physical distance, attacks can be carried out simultaneously on targets spreading out across a wide area. Some possible cases include cases where attacks are carried out simultaneously on multiple business locations of an organization, cases where attacks are carried out simultaneously on the organization’s system and supplier’s systems, and cases where attacks are carried out simultaneously on main systems and emergency systems. Matters to Be Considered with Regard to Response and Countermeasures [Basic point of view] Response to simultaneous and multiple attacks, based on the premise of cooperation with stakeholders [Matters to be considered in the formulation and revision of CP and BCP]  In the event where multiple incidents occur simultaneously, it is necessary to assess the need and order of priority for response based on factors such as the impact on business, risk tolerance, and resources necessary for response. Hence, clarify the assessment criteria when formulating the plans.  In preparation for a cyberattack on suppliers or external contractors who is involved in the provision of CISs, verify the status of preparation of CP and BCP by suppliers and  external contractors, as well as the contents of cooperation with the organization during response. Consider the possibility for the occurrence of the same cyberattack on multiple CI operators. Through the industry organizations, CEPTOAR, and information security related agencies of each sector, actively share information that contributes to the prevention of damage in other organizations, such as the means by which one’s own organization came under a cyberattack, the source of attack, and any characteristic indicators, and strive to prevent the further occurrence of damage across the entire sector. (Countermeasures during normal times, in preparation for the activation of CP and BCP)   Consider measures to reduce the possibility of the main system and emergency system becoming unavailable at the same time. Examples of such measures include blocking off communications other than those necessary for the business (such as data copies and back-ups between the main system and emergency system), and segregation of the networks of the main system and emergency system. Based on the assumption of situations in which it becomes difficult to maintain CISs 41

Select target paragraph3