Appendix 2. Business Continuity Planning (BCP) 1. Objective This appendix is intended to encourage governments to ensure the availability of critical IT resources in the government and CII operators, by implementing necessary countermeasures against disruptions in their IT resources and putting in place appropriate BCP policies. 2. Expectation for government It is desirable that the government ensures that government agencies and CII operators identify necessary IT resources in their organizations, take appropriate countermeasures to protect them, and make sure that the BCP management cycle is effectively working in their respective organizations. It is also desirable that the government provides policies or guidelines for government agencies and CII operators to encourage them to make their BCP more effective, as well as advices or supports if needed. 3. BCP management cycle In order to make BCP effective, it is desirable to establish BCP management cycle in each governmental organization or CII operator. BCP management cycle contains the following 4 items: 3-1 Understanding the organization An organization should understand the internal/external environment surrounding their organization. It also has to recognize the characteristic of risks they may face, and evaluate the impact of these risks. Once they become clear, the organization should identify critical IT resources to be protected, utilizing evaluating method such as a Business Impact Analysis (BIA) 3-2 BCP planning and BCP policy development The organization should plan necessary countermeasures to mitigate risks on the critical IT resources that were identified in the understanding phase (3-1). Moreover, the organization should establish a BCP policy which describes basic ideas and instructions that members of the organization should follow: The items in the BCP policy should include: - Objective of BCP - Risks to be mitigated - Identified critical IT resources - Response team and their responsibilities - Initial actions

Select target paragraph3