governments and/or regulators can offer support to encourage the private
sector to share information, such as opportunities for information sharing with
the private sector.
d)
For information sharing from governments and/or regulators to the private
sector, for example, in order to evoke attention from the CII owners/operators,
or to encourage them to make necessary preparations, the governments and/or
regulators could gather necessary information and provide it to the CII
owners/operators.
2-6 IT security crisis management
2-6-1 Incident handling
a)
It is important for the governments and/or regulators to develop capability to
detect cyberattacks against the governmental organizations, and encourage CII
owners/operators to develop their own cyberattacks detection capability.
b)
It is important for the governments and/or regulators to take necessary
measures to protect their critical business functions, and require CII
owners/operators to take appropriate measures according to best practices, for
example:
Access control
Raising awareness and training
Ensure data security
Establish data protection procedures
Anti-malware controls
DoS / DDoS mitigation
APT detection
Establish monitoring systems
Establish computer security incident response procedures
c)
It is important for the governments and/or regulators to provide timely
necessary information to relevant persons/organizations when there is an
incident which may jeopardize governments or CII owners/operators to continue
their critical business functions. The governments and/or regulators should be
careful not to reveal unnecessary information to public, or irrelevant
organizations so as not to cause overreaction or panic for the incident. Media
statements should be prepared in advance to be delivered by a designated
spokesperson.