governments and/or regulators can offer support to encourage the private sector to share information, such as opportunities for information sharing with the private sector. d) For information sharing from governments and/or regulators to the private sector, for example, in order to evoke attention from the CII owners/operators, or to encourage them to make necessary preparations, the governments and/or regulators could gather necessary information and provide it to the CII owners/operators. 2-6 IT security crisis management 2-6-1 Incident handling a) It is important for the governments and/or regulators to develop capability to detect cyberattacks against the governmental organizations, and encourage CII owners/operators to develop their own cyberattacks detection capability. b) It is important for the governments and/or regulators to take necessary measures to protect their critical business functions, and require CII owners/operators to take appropriate measures according to best practices, for example: Access control Raising awareness and training Ensure data security Establish data protection procedures Anti-malware controls DoS / DDoS mitigation APT detection Establish monitoring systems Establish computer security incident response procedures c) It is important for the governments and/or regulators to provide timely necessary information to relevant persons/organizations when there is an incident which may jeopardize governments or CII owners/operators to continue their critical business functions. The governments and/or regulators should be careful not to reveal unnecessary information to public, or irrelevant organizations so as not to cause overreaction or panic for the incident. Media statements should be prepared in advance to be delivered by a designated spokesperson.

Select target paragraph3