Let's Start SECURITY ACTION: A Recommendation for the IPA's 'Information Security Measures Guidelines for Small and Medium-sized Enterprises'
In this article, security analysts from the CEC Security Operation Center (CEC SOC) will share know-how for small and medium-sized enterprises (SMEs) to 'start with what they can' regarding information security measures.
SMEs are being targeted
In recent years, 'supply chain attacks' targeting SMEs have been increasing. A supply chain attack is a cyberattack method that uses related companies or business partners as a stepping stone to infiltrate a target company with robust security. SMEs, which tend to have relatively weaker information security measures, are often targeted as these stepping stones.
Case study of a supply chain attack
In February 2022, a situation occurred where a company supplying parts to a major manufacturer suffered a malware infection, making it impossible to provide parts and causing all of the manufacturer's domestic factories to shut down.
In the investigation report published by the parts supplier, it was explained that there was a vulnerability in the remote connection equipment used by a subsidiary of the company, and that the malware infection occurred after unauthorized access through that equipment led to an intrusion into the company's network.

Why are they targeted?
For attackers, it is easier to infiltrate SMEs, where security measures tend to lag behind, than large companies with relatively robust security measures. Therefore, they first try to infiltrate the systems of related SMEs and then use those companies to impersonate them and infiltrate the target large company. Even if unauthorized external communication can be blocked, it is difficult to identify impersonation from within, and there are cases where the defenses are ultimately breached.

SMEs may face many barriers to implementing information security measures, such as 'not having a sufficient budget' or 'not having skilled personnel.' Nevertheless, measures against cyberattacks are now an urgent issue that SMEs cannot afford to ignore.
Let's start with what we can do
Are you familiar with the 'Information Security Measures Guidelines for Small and Medium-sized Enterprises'? These guidelines, issued by the Information-technology Promotion Agency, Japan (IPA), provide easy-to-understand explanations of policies and methods for SMEs to promote information security measures. They are considered an excellent guide for organizations that are unsure how to begin their information security measures. As of January 2024, version 3.1 has been released, and the content is structured as follows.

In addition, the main text, 'Part 2: Practical Edition,' describes how to utilize the guidelines in steps so that they can be started according to the organization's situation.

*1 *2
Source: Information-technology Promotion Agency, Japan (IPA)
Information Security Measures Guidelines for Small and Medium-sized Enterprises Version 3.1
In this article, I will explain 'SECURITY ACTION,' which is mentioned in a column within the guidelines.
What is SECURITY ACTION?
'SECURITY ACTION' is a system where SMEs self-declare that they are working on information security measures. Depending on the level of their efforts, they can use the 'One-Star' or 'Two-Star' logos for free to promote their activities. To use the logo, it is necessary to apply to the IPA and have the application accepted.
Let's declare SECURITY ACTION One-Star
To use the "One-Star" logo, you must implement the "Five Information Security Rules" (*3) and declare the start of organizational efforts.
【Five Information Security Rules】
1. Keep your OS and software up to date!
2. Install antivirus software!
3. Strengthen your passwords!
4. Review your sharing settings!
5. Learn about threats and attack methods!
Step up to SECURITY ACTION Two-Star
To use the "Two-Star" logo, you must implement the following two items and declare the start of organizational efforts.
Understand your company's situation with the "5-Minute Information Security Self-Diagnosis" (*4)
Establish a policy by referring to the "Information Security Basic Policy (Sample)" (*5) and publish it externally
Source: Information-technology Promotion Agency, Japan (IPA)
Information Security Measures Guidelines for Small and Medium-sized Enterprises Version 3.1 Appendix
*3 Five Information Security Rules
*4 New 5-Minute Information Security Self-Diagnosis
*5 Information Security Basic Policy (Sample)
Summary
Cyberattacks are on the rise, regardless of whether it is a large enterprise, a small or medium-sized business, or an individual.
There is no such thing as a security measure that is "perfect if you just do this," but attackers are thinking of new methods every day to target our information assets. It is important to build a system to protect your organization by starting with what you can do, even if it is just a little at a time. Please start by making a SECURITY ACTION declaration.
CEC SOC Managed Security Service | Multi-vendor support available [Cyber NEXT] (cec-ltd.co.jp)
CEC SOC (Security Operation Center) provides security operation services that support the "initial response" and "permanent support" phases. We monitor 24 hours a day, 365 days a year, and report immediately when we determine an anomaly. During investigations, we check logs of peripheral devices as necessary and provide support to prevent re-infection from the same cause.
