Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Characteristics of Cyberattack Risks (iii)
Possibility of an attack that could lead to the rapid spread of damage
Damage from cyberattacks could potentially spread rapidly via networks that originate from
the location, which was hit by the attack. There are cases where damage spreads when the
malware that has infected a specific terminal duplicates itself on different terminals on the
network within the same organization, cases where damage from a cyberattack that has hit an
external contractor spreads to the systems within the company, or cases where the company’s
systems are operated illegally and used for an attack on another company, thereby making the
company the perpetrator of the attack.
Matters to Be Considered with Regard to Response and Countermeasures
[Basic point of view]
Response to spread of damage that also takes into consideration means that lead to service
interruptions
[Matters to be considered in the formulation and revision of CP and BCP]
To prevent the spread of damage from a cyberattack, consider measures such as blocking
off communication or suspending critical information systems. Get a good grasp of the
configuration of networks and systems, and review in advance the points for such
blocking or suspension measures.
When blocking off communications or suspending systems, clarify the parties
responsible for making the decision to implement such measures, as there is a possibility
that they could have a significant impact on the continuation of CISs. Furthermore, in
order to make an accurate judgement, organize information such as the timing and
period when suspension of services can be carried out, the scope of impact in the event
of suspension, and whether there are any alternative means, when formulating the plans.
As some information necessary for investigations may become unobtainable after
blocking off or suspension, gather the information prior to blocking off or suspension,
as far as time permits. Examples of such information that should be collected include
memory data and process data that would be lost as a result of the blocking off or
suspension, and logs that would be inaccessible during the blocking off or suspension.
Consider the methods and procedures for acquiring such information, corresponding
with the environment.
Consider sharing information about the status of response with external contractors for
whom there is a possibility for the mutual spread of damage from a cyberattack, and
consider disclosing the status of response with users of CISs. The characteristic
information for which disclosure should be considered in the event of a cyberattack
37