Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Characteristics of Cyberattack Risks (vii)
Possibility for the occurrence of an attack that triggers an erroneous judgement or response
A cyberattack can trigger an erroneous judgement or response. Examples of such cases
include cases where alerts and figures that are different from reality being displayed on the
management systems used for monitoring and control, leading to erroneous judgement, and
cases where unauthorized changes are made to the system (such as reducing figures through
the operation for increasing figures, system not coming to a stop through the operation used
for stopping the system) aiming for system operations undertaken in response to an outage to
cause unintended actions.
Matters to Be Considered with Regard to Response and Countermeasures
[Basic point of view]
Get an accurate grasp of the situation through the combined use of various types of monitoring
information
[Matters to be considered in the formulation and revision of CP and BCP]
At the stage where the scope of impact of the cyberattack has not yet been identified,
consider the possibility that the impact of the attack may have spread to the management
systems, and verify if there are any indicators of tampering or misalignment between
different sources of monitoring information.
In cases where there is suspicion that the management systems have been tampered with,
consider multiple procedures for response, such as monitoring and control using other
reliable means, including visual confirmation of the status of provision of CISs, and
physical control operations by hand.
(Countermeasures during normal times, in preparation for the activation of CP and BCP)
Consider the structure and mechanisms for verifying if any unauthorized changes have
been made to the systems. An example of items that should be checked include hardware
configuration (connection devices, etc.), software configuration, file configuration, and
system settings.
Prepare multiple means for monitoring, in preparation for the display of monitoring
information that differs from reality, as a result of a cyberattack on the monitoring
functions of CISs.
45