Incident Response capability is critical per FSA Cybersecurity Guidelines. (1) Incident Response Plan: (a) Documented IR Plan + per FFIEC IT Examination Handbook reference; (b) ISO/IEC 27035 Information Security Incident Management; (c) NIST SP 800-61 Computer Security Incident Handling Guide; (d) Sector-specific - FISC + JFSA reference; (e) Annual review + update; (f) Board approval; (g) Plan accessible to CSIRT + SOC + Senior Management. (2) Incident Classification + Severity: (a) Severity 1 (Critical) - widespread outage + significant customer impact + sensitive data breach; (b) Severity 2 (High) - localised outage + limited customer impact; (c) Severity 3 (Medium) - operational disruption + no customer impact; (d) Severity 4 (Low) - minor issue + procedural; (e) Per-Severity response procedures + escalation. (3) CSIRT Computer Security Incident Response Team: (a) Dedicated CSIRT - Tier 3; (b) Designated incident responders - Tier 2; (c) Outsourced IR retainer - Tier 1/2; (d) 24x7 coverage; (e) Communications channels + roles; (f) IR Coordinator + Tech Lead + Comms Lead + Legal Lead; (g) Executive Sponsor (CISO + CIO + CEO depending on severity). (4) Incident Response Lifecycle (NIST SP 800-61): (a) Preparation - tools + processes + training; (b) Detection and Analysis - alert triage + scope determination; (c) Containment - short-term + long-term + evidence preservation; (d) Eradication - root cause removal + clean state restoration; (e) Recovery - service restoration + monitoring; (f) Post-Incident Activity - lessons learned + improvement. (5) Containment Strategies: (a) Network Segmentation + Isolation; (b) Account Disablement + Credential Reset; (c) System Quarantine via EDR; (d) Egress traffic blocking; (e) DNS sinkholing; (f) WAF rule deployment; (g) Capacity scaling for DDoS; (h) Forensic image capture before changes. (6) Forensics + Evidence Preservation: (a) Chain of Custody; (b) Memory acquisition (Volatility); (c) Disk imaging (FTK + EnCase + dd); (d) Network packet capture; (e) Log preservation + WORM storage; (f) Timeline analysis; (g) Malware analysis (sandbox + reverse engineering); (h) Forensic readiness program. (7) FSA Notification: (a) Banking Act Article 52-2 + Insurance Business Act Article 100-2 + Financial Instruments and Exchange Act Article 19; (b) Notification triggers - material impact + customer impact + service disruption + data breach + ransomware; (c) Initial notification typically within 30 days (more rapid for critical); (d) Detailed report follow-up; (e) FSA dialogue + supervisory engagement; (f) Public disclosure considerations; (g) FSA Inspection follow-up. (8) Customer + Public Communication: (a) APPI Article 26 personal data breach notification to PIPC; (b) Customer notification per APPI Article 26-2; (c) Public disclosure for material incidents; (d) Media coordination; (e) Customer service surge handling; (f) Compensation + remediation programs; (g) Trust restoration program. (9) Tabletop Exercises + Drills: (a) Annual tabletop minimum per FSA expectation; (b) Cross-functional participation (technical + legal + comms + executive); (c) Scenario diversity (ransomware + insider + DDoS + supply chain + data breach); (d) FSA-coordinated industry-wide exercises (Delta Wall); (e) FISC industry drills; (f) Realistic tempo + decision-making; (g) After Action Review + improvement actions. (10) Industry-Wide Coordination: (a) FS-ISAC Japan information sharing during incidents; (b) FISC + FSA coordination; (c) JPCERT/CC engagement; (d) Bilateral peer notifications (early warning); (e) Sector ISAC sharing (Banking + Insurance + Securities + Asset Mgmt); (f) International coordination via FSB + G7 + Bilateral arrangements. (11) Ransomware-Specific Response: (a) Do Not Pay default position per FSA + NISC + government guidance; (b) Negotiation considerations (limited + with legal counsel); (c) Decryption tool research; (d) Backup restoration; (e) Forensic investigation; (f) FSA + customer + public communication; (g) Insurance claim coordination; (h) Law enforcement coordination (Japan Cybercrime Division). (12) Post-Incident Activities: (a) Detailed Root Cause Analysis (RCA); (b) Blameless Post-Mortem; (c) Lessons Learned documentation; (d) Control improvement actions; (e) Detection improvement (new SIEM rules + EDR signatures); (f) Process improvement; (g) Training updates; (h) Industry sharing where appropriate; (i) Annual incident statistics review by Board. Coordinates with NIST SP 800-61 Computer Security Incident Handling + ISO/IEC 27035 Incident Management + ISO/IEC 27037 Digital Evidence + FFIEC IT Examination Handbook + Banking Act Article 52-2 + Insurance Business Act Article 100-2 + APPI Article 26 + 26-2 + PIPC + FISC + FS-ISAC Japan + JPCERT/CC + NISC + Japan Cybercrime Division + G7 Fundamental Elements + FSB Effective Practices for Cyber Incident Response. Japan FSA Cybersecurity Incident Response applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.