Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment
and Countermeasures that Are Associated with Incident Readiness
The characteristics of cyberattack risks as well as the treatment and countermeasures to be
considered, presented from the following page, should be taken into consideration by CI
operators when formulating or revising mainly contingency plans (hereinafter, “CP”) and
business continuity plans (hereinafter, “BCP”).
The definitions of CP and BCP are as described in section 4.2.1. (2) (A) of this document.
However, as there are cases where the names, scope of description, and timing for the start of
the operations may differ depending on the sector or operator, it is necessary to consider, in
response to the situation of the respective operators, the target documents that should be
formulated or revised in consideration of the characteristics and other factors presented on the
following pages (hereinafter referred to as “applicable target documents”).
Figure 1 shows an example of the flow from the occurrence of a cyberattack to recovery, as a
reference when considering the applicable target documents. Both examples shown in Figure 1
(examples 1 and 2) show the series of processes from the occurrence of an anomaly due to a
cyberattack, followed by decline in service levels with time, and then to recovery in service
levels after treatment based on the CP and BCP.
In Example 1, treatment has been commenced based on the BCP at an early timing, in order to
ensure the early recovery of services. By contrast, in Example 2, treatment has been commenced
based on the BCP, after services have been suspended intentionally as a safety measure, and
after the implementation of treatment according to safety management provisions. In both
examples, the CP and BCP are applicable target documents for which the characteristics and
other factors presented on the following pages should be taken into consideration. Treatment
based on safety regulations, as shown in Example 2, focuses on reducing and suppressing
damage, and generally does not change whether or not the cause of damage is a cyberattack.
On the other hand, in cases where IT is used in the treatment, it would be preferable to consider
the characteristics and other factors presented on in the following pages.
33