SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

SECURITY ACTION: A discussion on what to organize before the changes in April

When it comes to information security measures for small and medium-sized enterprises, it often tends to become a conversation about how it is difficult to know where to start.

Unlike large corporations, there is no dedicated staff. However, there are increasing inquiries from business partners, and minimum rules and systems are becoming necessary within the company...

security check sheetsI feel that there are more and more cases where responses to these are being requested.

In such a situation, a realistic entry point that is easy to position is the SECURITY ACTION program by the IPA (Information-technology Promotion Agency, Japan).
It is also a requirement for applying for the Digitalization and AI Introduction Subsidy (formerly IT Introduction Subsidy).

Admittedly, even if one knows the name SECURITY ACTION itself, it is a bit difficult to understand what it is and what it is intended to address.

Moreover, the application method is scheduled to change from April 2026, and the "Information Security Measures Guidelines for Small and Medium-sized Enterprises," which serves as the premise, is also scheduled to be revised within March 2026. At the time of writing this article, it is a somewhat awkward period where the framework of the system is visible, but the details are yet to change.


What is the purpose of the SECURITY ACTION program?

In the first place, "SECURITY ACTION" is a self-declaration system for information security measures for small and medium-sized enterprises operated by the IPA.
It is easy to understand it as a mechanism to demonstrate to the outside world that the company is working on information security measures, based on the "Information Security Measures Guidelines for Small and Medium-sized Enterprises."

What is important here is that, unlike ISMS or Privacy Mark, it is not a system for obtaining certification through strict examination, but rather a practical entry point for the company to face information security measures and proceed with necessary initiatives.

For small and medium-sized enterprises, information security is not a binary choice of
“doing it perfectly or doing nothing at all.”
There is a middle ground.

It is important to first grasp the current situation and organize things from where you can, and this system is easy to use as a foothold for that.

One-star and Two-star

SECURITY ACTION has two levels: one-star and two-star.

One-star is a declaration to work on the 5 Information Security Principles. I think it is close to the position of starting by being aware of basic measures and having a minimum common understanding within the company.

Two-star is a step further from there, 5-Minute Information Security Self-Diagnosis” after grasping the company's situation with , declaring that the information security basic policy has been established and publicly disclosed. This is a stage of verbalizing how the company thinks and how it will proceed, rather than just saying "we are being careful."

Looking at this difference, it can be seen that SECURITY ACTION is not just a procedure, but something that reflects how well the company has organized its information security measures.

Application method changes from April

Regarding that SECURITY ACTION, the application method is scheduled to change from April 2026.

A new system will be released, and the method of application and management will be switched. A major difference is that G-Biz ID will be used to log in, and it will be possible to check and change registration information and download logos on the My Page.

Currently, it takes one week from application until the self-declaration ID is notified, and another 1-2 weeks until the logo can be downloaded, but it seems that both the self-declaration ID and the logo will be obtainable immediately after application.

Rather than thinking that the system itself is changing significantly, it is better to view it as a change in the prerequisites for the application process.
However, since practical work is prone to stumbling over such "changes in prerequisites," it is easier to organize things now rather than waiting until April.

Things to keep an eye on

Another point to be careful about this time is that the "Information Security Measures Guidelines for Small and Medium Enterprises," which serves as the foundation for SECURITY ACTION, is also scheduled to be revised.

In other words, not only will the application method change from April, but it will also be operated based on the new guidelines from now on.

However, at this point (March 8th), the full text of the revised version has not yet been released.
Therefore, it is too early to say definitively that you are "fully compliant with the new rules." On the other hand, it is not very realistic to "do nothing because the revised version has not been released yet."

Therefore, at this stage, I think the most reasonable approach is to organize your company's situation based on the current approach, and then check for differences and make adjustments once the revised version is published.

Things you can do in advance

Even though the revised version is not yet visible, there are things you can do in the meantime.

First, confirm how much your company has organized its information security measures.
Who is in charge, are there basic rules, and how much do you understand about the IT tools and cloud services you are using? These basic checks for security measures are necessary regardless of whether the SECURITY ACTION system changes.

Next, consider whether you will proceed with one star or aim for two stars.
This is not just a difference in the system, but also a question of how much you want to be able to demonstrate your status to the outside world.

When applying for the Digitalization/AI Introduction Subsidy (formerly: IT Introduction Subsidy), one star is generally sufficient, but if you are applying under the Security Measures Promotion category, you must declare two stars.

And another important thing is not to just copy and paste templates for documents and policies.
You can create a basic information security policy and self-diagnosis just to make it look good. However, documents that do not match reality will need to be reviewed later, and it will also be difficult to handle inquiries from business partners or manage internal operations.

The relationship with subsidies comes out "as a result"

As I have written so far, SECURITY ACTION is not originally a system that exists only for subsidies.
I think it is closer to the main point to view it as a practical mechanism for small and medium-sized enterprises to organize their information security measures in a reasonable way.

As a result, this SECURITY ACTION declaration is sometimes a requirement for applying for various subsidies, such as the Digitalization/AI Introduction Subsidy (formerly: IT Introduction Subsidy) mentioned earlier.

Note that when making a SECURITY ACTION self-declaration regarding an application for the Digitalization/AI Introduction Subsidy, the application must be made by the applicant themselves. It is not permitted for the IT tool provider to apply on their behalf.

Given this situation, it can also be an opportunity to actually review information security measures, which tend to be put off. The significance lies in the fact that it is an initiative that is necessary in the first place, and it is also required by the system—that is the order of priority.

Therefore, companies planning to apply for IT-related subsidies should definitely pay attention to it, but I also think it is a system worth looking at properly from the perspective of responding to business partners and developing your own company's structure.

To avoid ending up with just a formality

When working on SECURITY ACTION, the place where you actually get stuck is not in reading the overview of the system.
It is easy to get stuck on how to write the self-diagnosis, how to summarize the basic policy, and how much to organize according to your company's actual situation.

Especially if you are considering up to two stars, consistency between internal operational practices and documentation is essential, otherwise you will need to review it later.
Whether you are preparing for regulatory compliance or to explain it to business partners, the most important thing is ultimately whether it matches your company's actual situation.

As an entry point for security measures

SECURITY ACTION is a program that is too valuable to be viewed only as a procedure for subsidies.
If you consider it as an entry point for small and medium-sized enterprises to reasonably establish information security measures, it is well worth the effort.

Therefore, it is important to organize your company's situation now rather than waiting for the new system to be released in April to think about everything.
However, since the full text of the revised guidelines has not yet been seen, it is safer to avoid claiming that you have fully aligned with the new standards.
I believe that balancing these two is a realistic approach to take at this time.

In practice, people often get stuck at the stage of self-diagnosis or organizing basic policies.
If you want to proceed in accordance with your company's actual situation or want to properly prepare for regulatory compliance, I have summarized the information here.
Information on SECURITY ACTION Support

If you would like to organize how to approach SECURITY ACTION and prepare your declaration together, please take a look at this as well.

SECURITY ACTION Support Page (Beans Security Service)

If you would like to consult about your situation first, please also make use of our 30-minute free consultation.

Click here for a free consultation (Beans Security Service)


いいなと思ったら応援しよう!