Event Categories
Event Examples
Description
Events that have not
occurred yet
Signs, Hiyari-Hatto
events
Signs such as cyber-attack warnings, detection of vulnerability of systems, or
Hiyari-Hatto events (potentially serious damage) without occurrence of events that
threaten confidentiality, integrity or availability, such as minor mistakes or receipt
of malware attached to suspicious emails
Information leakage
Events that threaten confidentiality, such as the leakage of organization's
confidential information
Events that threaten
confidentiality
Events that have occurred
Events that threaten
integrity
Data corruption
Events that threaten integrity, such as website defacement or corruption of
organization's confidential information
Events that threaten
availability
Problems in using
systems
Events that threaten availability, such as loss of stable operation of control systems
or inability of viewing websites
Malware infections
Infection of systems by malware
Execution of
unauthorized code
Execution of unauthorized code exploiting the vulnerability of systems
System intrusions
Intrusions into systems caused by cyber-attacks
Events that can lead to
those above
Others
Events other than those above
Cause Categories
Cause Examples
Deliberate causes
Receipt of suspicious emails, fraudulent of user IDs, mass access such as DDoS attacks, unauthorized
acquisition of information, internal fraud, lack of appropriate system operation, etc.
Accidental causes
Mistaken user operation, mistaken user management, execution of suspicious files, viewing of suspicious
websites, unsupervised work by outsourcing contractor, failure of equipment, vulnerabilities, cascading effect
from other sectors' failures, etc.
Environmental causes
Others
Disasters, illnesses, etc.
Threats and vulnerabilities other than those above, unknown causes, etc.
61
ANNEX 3. CATEGORIES OF EVENTS AND CAUSES FOR INFORMATION
SHARING TO NISC
ANNEX 3. CATEGORIES OF EVENTS AND CAUSES FOR INFORMATION SHARING TO NISC