Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Characteristics of Cyberattack Risks (vi)
Possibility for the occurrence of attacks that are difficult to detect
In cases where inadequate measures for detection are put in place against cyberattacks, there
is a possibility for a sustained attack over a long period of time without the attack being
recognized. There are cases where detection is avoided through the deletion of logs that lead
to the detection of illegal acts, and cases where figures that are different from the actual
figures are displayed in order to make it appear as if the systems were operating normally.
The longer it takes to detect an attack, the greater the possibility for the spread of damage.
Even after an attack is detected, there are many cases where it is difficult to identify the
attackers and objective of the attack.
Matters to Be Considered with Regard to Response and Countermeasures
[Basic point of view]
Clarification of disclosure procedures for information, etc. that are related to impact
investigations
[Matters to be considered in the formulation and revision of CP and BCP]
In countering attacks with scope of impact that maintenance operators such as system
vendors have difficulty in identifying, there may be cases where requests for cooperation
in investigation are made to external incident response organizations or external security
vendors. In such situations, it may sometimes be necessary to disclose logs or equipment
that has been breached. Hence, clarify the necessary procedures (person responsible for
disclosure, assessment criteria, organizations to which disclosure is permitted, and
means of provision in order to transmit the information, including confidential
information, safely), the information to be disclosed (log items, format, etc.) and any
restrictions (types of information that cannot be disclosed, such as confidential
information or personal information, etc.).
(Countermeasures during normal times, in preparation for the activation of CP and BCP)
To investigate indicators of anomaly caused by an attack, have a good grasp of the
configuration of critical information systems, and of the operations of the system during
normal times as well as the contents of its output logs. Put in place measures to protect
the systems against the tampering with and deletion of logs.
To investigate attacks that have not been detected for a long period of time by tracing
them back to the past, store various logs obtained during normal times for a certain
period. Review the storage period by taking into consideration the storage period for
logs recommended by information security related agencies and security vendors. Refer
to publicly available information from information security related agencies, and verify
43