III. Policies for CIP
4. Risk Management and Preparation of Incident Readiness
4. Risk Management and Preparation of Incident Readiness
Cases of personal information leakage caused by cyberattacks or information system failures and economic loss due
to suspension of CI services have come to be frequently reported along with the increase in ICT utilization. Damage to
the real world is becoming more and more serious. It is necessary to note that highly sophisticated cyberattacks, such as
zero-day attacks targeting undisclosed vulnerability, and internal fraud "can no longer be prevented completely in
advance."
Under such circumstances, CI operators should inevitably position preparedness for cybersecurity risks in their
business strategy and strategically take risk response measures based on the results of risk assessment. From the
viewpoint of mission assurance, they need to put in place appropriate risk assessment-based incident readiness to ensure
safe and continuous provision of CI services even in the event of a cyberattack, etc. It is also important for them to build
a mechanism under which these activities as a whole (risk management) function sustainably and effectively.6
In order to prioritize measures to be taken by CI operators based on the concept of mission assurance, this
Cybersecurity Policy expansively positions the key policy "risk management" under the Third Policy as "risk
management and preparation of incident readiness," and newly introduces measures for supporting CI operators'
initiatives for strengthening internal control to enable proper decision making based on risk assessment and their
voluntary and autonomous efforts for preparing incident readiness for business continuity, while maintaining measures
for risk management under the Third Policy.
4.1 Basic view of risk management
Risk management should be independently implemented by each CI operator. However, in circumstances where
information sharing and discussions based on common risk management views or terms are not observed among
stakeholders, there is a possibility that the activities in this Cybersecurity Policy will not be effectively utilized in the
risk management of each CI operator.
For this reason, it is preferable for each stakeholder to utilize the internationally standard views of risk management
and related terminology definitions for cybersecurity etc. In details, views based on the framework shown in Table 3
below and the terminology definitions used therein should be adopted to the extent possible in concrete activities and
related materials.
6
From the viewpoint of mission assurance, CI operators should conduct risk assessment to comprehensively ascertain impacts on the
provision of CI services, taking into account not only the influence of system failures directly relating to CI services but also spillover
effects of indirectly related system failures.
21