JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada
3.6 Threat-Led Penetration Testing The CSFS Guidelines require that threat-led penetra - tion testing be carried out on a regular basis.
6.2 Cybersecurity and AI MIC and METI published the AI Business Guidelines for AI developers, service providers and users in April 2024. These Guidelines urge businesses to invest in and implement robust security management through - out the entire AI lifecycle, including cybersecurity. They also suggest considering appropriate cyber- access controls. On 25 December 2025, MIC published draft guidelines outlining technical measures to ensure AI security and prevent information leakage, as well as unintended changes to or shutdowns of AI systems caused by unauthorised operations. These guidelines apply to AI developers and service providers as defined in the AI Business Guidelines. 6.3 Cybersecurity in the Healthcare Sector The MHLW issued the Guidelines on Safety Manage - ment of Medical Information Systems (last amended in May 2023). While the MHLW guidelines and an announcement issued by the Ministry in October 2018 indicate that medical service providers should report cybersecurity incidents to the authorities, no spe - cial rules have been issued for statutory data breach reporting or notification in this regard. MIC and METI jointly issued the Guidelines on Safety Management for Providers of Information Systems and Services Handling Medical Information (last amended in July 2023).
4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
There is no uniform legislation on cyber-resilience. Specific aspects of cyber-resilience are stipulated in each of the individual regulations. 4.2 Key Obligations Under Legislation Specific aspects of cyber-resilience are stipulated in each of the individual regulations. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The Labelling Scheme based on the Japan Cyber- Security Technical Assessment Requirements (JC- STAR) provides an evaluation index for the security functions of IoT products. This system is provided by the IPA, and its application began in March 2025. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Handling operators must establish appropriate safe - guards to protect personal data (Article 23 of the APPI) and report data breaches to the PPC and, in cases where their rights or interests are likely to have been infringed, notify affected data subjects (Article 26 of the APPI).
237 CHAMBERS.COM
Powered by FlippingBook