To do List
Phase
Action Items
Check
Establish
Establish cyber incident detection features
□
Incident
(such as establishing CSIRTs) for the
Response
Government.
Capabilities
Encourage CII owners/operators to establish
□
incident detection features.
Preparation (As
Assess risks and threats.
□
in the CIIP
Identify critical business functions and critical
□
Guidelines 2-1)
IT resources.
Check usable resources.
□
Encourage CII owners/operators to do the same.
□
Take
Decide countermeasures to mitigate risks on
□
Countermeasures
your critical business functions and critical IT
for the Risks
resources.
Make implementation plans for
□
countermeasures.
Implement countermeasures based on the
□
implementation plan.
Encourage CII owners/operators to do the same.
□
Establish
Establish disaster recovery plans for quick
□
Disaster
recovery from cyber incidents.
Recovery
Procedure
Establish BCP
Establish business continuity plans (BCPs) to
Procedure
assure business continuity for your core
□
business functions in case your related critical
IT resources are not available.
These "to do" items are for the exercise organized by the Government. If private sectors
take the lead and Government just support them, make sure these "to do" items are
properly prepared/conducted, and if not, support them by following the description in the
CIIP Guidelines 2-6.
15