ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC
1. Information Related to System Failures
ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION
SHARING FROM NISC
1. Information Related to System Failures
Information related to system failures, including CISs outages, and signs and Hiyari-Hatto events (hereinafter referred
to as "information related to system10 failures") needs to be handled with consideration given to the following three
aspects: [i] proactive prevention of CISs outages, [ii] prevention of the spread damages and quick recovery from CISs
outages, and [iii] prevention of recurrence through analysis and verification of CISs outage causes. Government
organizations must provide such information to CI operators properly as necessary, while there is also a need to further
enhance information sharing systems among CI operators and among interdependent CI sectors.
As signs or Hiyari-Hatto events with no visible phenomena may eventually lead to CISs outages involving multiple
CI sectors and CI operators, they should also be included in the scope of information sharing, in addition to actualized
system failures.
Therefore, the scope of information sharing in this Cybersecurity Policy is as shown in the figure below.
CI services
Actualization of
phenomenon
CISs outages
System failures
Signs and Hiyari-Hatto events
Phenomena requiring
cybersecurity security
measures
Impact level
phenomenon
Hindrance to safe
and continuous
provision of
services
Other services
Figure. Scope of Information Sharing
10
It should be noted that the term "system" here includes not only so-called information systems, but also control systems used in
plants or for system monitoring in various CI sectors, as well as IoT systems, etc. whose utilization is expected to spread rapidly in
the future.
48