Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
includes the means of attack as identified through the response and investigation, the
cause of damage (software vulnerability, misconfiguration, etc.), and status of response
to the attack (temporary measures to prevent the spread of damage, fundamental
measures to address the cause of damage), occurrence of secondary damage to
customers, etc., and possibility of future occurrences.
(Countermeasures during normal times, in preparation for the activation of CP and BCP)
Consider, where necessary, the introduction of countermeasures in preparation for the
spread of an attack. Examples of countermeasures include the segregation of network
segments (isolation of critical information systems), IPS/proxy servers (blocking off
suspicious external communications), and EDR1 (specification of the scope of impact
and isolation of the damaged terminals).
1
Abbreviation of Endpoint Detection and Response.
38