4-6 IT security crisis management Expectation for To enhance capabilities for incident detection for the Governments Government and encourage CII owners/operators to do the same. To take necessary countermeasures to mitigate risks of cyber incidents and encourage CII owners/operators to do the same. To develop disaster recovery plans for Governments and BCP for critical business functions identified in the CIIP Guidelines 2-1-b, and encourage CII owners/operators to do the same. Possible Issues Lack of information/best practices. and Obstacles Lack of skills/methods to introduce disaster recovery plans or BCP. Lack of resources/understandings of higher management. Possible See best practices and reference documents in the CIIP Countermeasures Guidelines and other international standards (ISO22301, to Overcome etc.) Issues and Join the exercise to introduce disaster recovery plans or Obstacles BCP. Try to explain to higher management the importance of exercises to make them assign more resources. 14

Select target paragraph3