JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada
The IPA also runs the J-CSIP (Initiative for Cybersecu - rity Information Sharing Partnership of Japan), which shares cybersecurity information of critical information infrastructure operators (ie, operators of businesses that provide infrastructure that is the foundation of people’s living conditions and economic activities, the functional failure or deterioration of which could have a highly significant impact on society). The NCO’s responsibilities include: • serving as the secretariat of the Cybersecurity Strategic Headquarters; • monitoring and analysing unauthorised activities targeting information systems of administrative organs; • providing necessary advice, information and other assistance, as well as conducting audits, to ensure cybersecurity; and • carrying out comprehensive co-ordination concern - ing the assurance of cybersecurity. The NCO was established in light of the enactment of the Active Cyber Defence Acts. For more on oth - er regulators, refer to 1.1 Cybersecurity Regulation Strategy and 1.2 Cybersecurity Laws . 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The Cybersecurity Policy for Critical Infrastructure Protection defines the following 15 sectors as critical information infrastructure:
• petroleum industry; • ports and harbours;
• railways; and • water supply.
The aforementioned cybersecurity policy also encour - ages critical information infrastructure operators to periodically assess their progress in implementing security measures and policies. 2.2 Critical Infrastructure Cybersecurity Requirements Under the APPI, handling operators not limited to criti - cal infrastructure must take necessary and appropri - ate action for security control over the personal data that they handle, including preventing the leakage, loss or damage of or to personal data (Article 23). The PPC is the regulator primarily responsible for the APPI and the My Number Act; it has published guidelines for the handling of personal information (the “PPC Guidelines”). The PPC Guidelines provide examples of these han - dling measures, such as establishing and implement - ing basic policies, internal rules, and organisational, personal and technical security measures, as well as understanding of the external environment. “Under - standing of the external environment” is a security measure, newly introduced by the amendments to the Guidelines, which requires handling operators who process personal data in foreign countries to under - stand the local legal systems for personal information protection and, taking into consideration those legal systems, to take necessary and appropriate measures to ensure the security of personal data. Effective since April 2024, the PPC Guidelines also require handling operators to take security control over personal infor - mation that is collected and expected to be treated as personal data to prevent cyber-attackers from inter - cepting it on the operators’ behalf. According to the APPI, when a handling operator allows its employees to handle personal data, it must exercise necessary and appropriate supervision over the employees to ensure security control over the per - sonal data (Article 24). The APPI also requires han - dling operators to ensure that the entities to whom
• airports; • aviation; • chemical industry; • credit cards; • electric power supply; • financial services; • gas supply;
• information and communication; • government and administration; • logistics and shipping; • medical;
233 CHAMBERS.COM
Powered by FlippingBook