To do List Phase Action Items Check Establish Establish cyber incident detection features □ Incident (such as establishing CSIRTs) for the Response Government. Capabilities Encourage CII owners/operators to establish □ incident detection features. Preparation (As Assess risks and threats. □ in the CIIP Identify critical business functions and critical □ Guidelines 2-1) IT resources. Check usable resources. □ Encourage CII owners/operators to do the same. □ Take Decide countermeasures to mitigate risks on □ Countermeasures your critical business functions and critical IT for the Risks resources. Make implementation plans for □ countermeasures. Implement countermeasures based on the □ implementation plan. Encourage CII owners/operators to do the same. □ Establish Establish disaster recovery plans for quick □ Disaster recovery from cyber incidents. Recovery Procedure Establish BCP Establish business continuity plans (BCPs) to Procedure assure business continuity for your core □ business functions in case your related critical IT resources are not available. These "to do" items are for the exercise organized by the Government. If private sectors take the lead and Government just support them, make sure these "to do" items are properly prepared/conducted, and if not, support them by following the description in the CIIP Guidelines 2-6. 15

Select target paragraph3