ATTACHMENT: INFORMATION SHARING TO NISC AND INFORMATION SHARING FROM NISC
3. Information Sharing from NISC
3. Information Sharing from NISC
3.1 Cases requiring information sharing from NISC
If it is found that the case falls under any of the following as a result of collecting and analyzing information on system
failures provided broadly from responsible ministries for CI, cybersecurity related ministries, crisis management
ministries, disaster prevention related ministries, cybersecurity related agencies, cyberspace-related operators, and CI
13
operators, the Cabinet Secretariat provides relevant information positively.
(i) Cases where the obtained information is regarding a security hole, program bug, etc. and it is recognized that
serious problems related to said information may occur at other CI operators
(ii) Cases where there is a cyber-attack or advance notice of such an attack, where there are predicted damages
from a disaster, or where it is otherwise recognized that the information poses a risk to the critical information
systems of other CI operators
(iii) Other cases where information sharing is considered to be effective for CI operators' cybersecurity measures
The Cabinet Secretariat provides information after taking appropriate measures, such as anonymizing or otherwise
processing information, so as not to cause any disadvantage to data sources.
The scope to which the Cabinet Secretariat provides information is limited to CI sectors that are found to have a
relevant connection with said information by the Cabinet Secretariat, within the scope permitted in advance by data
sources. If the Cabinet Secretariat considers it necessary to share information beyond the scope permitted by data sources,
necessary change to the scope is to be discussed and adjusted with data sources.
3.2 Framework for information sharing from NISC
The procedures for information sharing from the Cabinet Secretariat to CI operators via responsible ministries for CI
are as follows.
(i) When the Cabinet Secretariat shares information, such sharing is carried out through liaisons to the Cabinet
Secretariat for respective jurisdictional sectors of responsible ministries for CI. At that time, appropriate
information identification methods are devised so that information receivers can recognize the classification
and scope of handling of the information based on its severity and can utilize the information easily.
(ii) Liaisons of responsible ministries for CI convey the information to the relevant CEPTOAR's point of contact
(PoC).
(iii) CEPTOARs convey the information to CI operators which make up respective CEPTOARs.
(iv) In particularly urgent cases, such as the case of early warning information, etc., regardless of procedures (i)
13
For information to be provided, the accuracy thereof should be enhanced through cross-check of data, or otherwise, efforts should
be made to improve the quality of information. Concrete measures include studies of CISs outages caused by suspension or
deterioration of services in CI sectors, estimates of possible impacts of CISs outages due to common risk sources on other CI sectors,
and judgment of severity based on these studies and estimates.
52