Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness The characteristics of cyberattack risks as well as the treatment and countermeasures to be considered, presented from the following page, should be taken into consideration by CI operators when formulating or revising mainly contingency plans (hereinafter, “CP”) and business continuity plans (hereinafter, “BCP”). The definitions of CP and BCP are as described in section 4.2.1. (2) (A) of this document. However, as there are cases where the names, scope of description, and timing for the start of the operations may differ depending on the sector or operator, it is necessary to consider, in response to the situation of the respective operators, the target documents that should be formulated or revised in consideration of the characteristics and other factors presented on the following pages (hereinafter referred to as “applicable target documents”). Figure 1 shows an example of the flow from the occurrence of a cyberattack to recovery, as a reference when considering the applicable target documents. Both examples shown in Figure 1 (examples 1 and 2) show the series of processes from the occurrence of an anomaly due to a cyberattack, followed by decline in service levels with time, and then to recovery in service levels after treatment based on the CP and BCP. In Example 1, treatment has been commenced based on the BCP at an early timing, in order to ensure the early recovery of services. By contrast, in Example 2, treatment has been commenced based on the BCP, after services have been suspended intentionally as a safety measure, and after the implementation of treatment according to safety management provisions. In both examples, the CP and BCP are applicable target documents for which the characteristics and other factors presented on the following pages should be taken into consideration. Treatment based on safety regulations, as shown in Example 2, focuses on reducing and suppressing damage, and generally does not change whether or not the cause of damage is a cyberattack. On the other hand, in cases where IT is used in the treatment, it would be preferable to consider the characteristics and other factors presented on in the following pages. 33

Select target paragraph3