SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

The Risks of Modified Cars Without Inspection Running on Public Roads? Safety Governance for Digital Infrastructure Required by Administrative Apps

~[IT Report Card] Structural Issues in Administrative Digital Infrastructure: No Vehicle Inspection, No Accident Investigation Board~

The Two Major 'Pre- and Post-' Safety Nets Supporting Social Security

The background to the maintenance of social safety and order lies in the fact that two mechanisms function in every industrial sector: 'pre-checks (prevention)' to prevent incidents and accidents before they occur, and 'post-checks (investigation)' to determine the causes of problems once they have occurred.

Specific examples in major infrastructure and industries are as follows.

🚗 Automotive and Transportation Sector

  • Pre-check (Prevention): Vehicle Inspection and Driver's License System Prevents defective vehicles and unqualified drivers from entering public roads.

  • Post-check (Investigation): Police and Accident Investigation Committees Conducts objective cause investigation when an accident occurs and implements recurrence prevention measures.

📱 Telecommunications and Home Appliance Sector

  • Pre-check (Prevention): Technical Conformity Certification (Giteki) Prevents the distribution of equipment that causes interference or jamming of radio waves.

  • Post-check (Investigation): Radio Wave Monitoring and Regulatory Agencies Takes legal action against illegal radio wave usage.

🍔 Medical and Food Sector

  • Pre-check (Prevention): Food Sanitation Inspection and Pharmaceutical Approval Blocks the distribution of harmful substances or inappropriate food at an early stage.

  • Post-check (Investigation): Public Health Centers and Police Implements business suspension orders or compulsory investigations when food poisoning or similar incidents occur.

The Current State of Modern 'Administrative IT and Apps'

  • [Pre] Lack of Structural Audits: There are cases where processes proceed based solely on formal paperwork or vendor reports rather than verification that delves into technical details.

  • [Post] Absence of Third-Party Verification: Even when large-scale system failures or data defects occur, there is no mechanism for an independent external 'accident investigation committee' to intervene, as exists in aviation or railways. As a result, post-incident handling tends to remain limited to the parties involved.

Why IT Alone Can Become a 'Governance Vacuum Zone'

When compared to existing industrial products and infrastructure, administrative web apps and digital infrastructure are placed in an extremely unique environment. The structural factors for this are explained mainly from three perspectives.

1. Absence of [Pre-systems]: Lack of mechanisms for third parties to guarantee technical quality

Smartphones and Wi-Fi devices are required to obtain a 'Technical Conformity Mark,' which functions as a minimum rule to ensure they do not interfere with other people's communication infrastructure. However, for administrative apps that operate within those terminals and handle residents' personal information, a common system like an 'IT version of vehicle inspection,' where a third party strictly audits the technical quality of the source code, has not been sufficiently established. A system where the ordering party formally approves the development side's 'test complete' report without fully grasping the technical details leaves vulnerabilities in the structure for guaranteeing safety.

2. The Absence of [Post-Incident] Mechanisms: Structural Limitations in Objective Root Cause Analysis

When aircraft or trains are involved in serious accidents, mechanisms function where organizations independent of the parties involved, such as the Japan Transport Safety Board or the police, intervene to objectively investigate the causes. On the other hand, when troubles such as data linkage failures or information leaks occur in administrative systems, the IT field lacks a mature culture or system for independent legal investigative agencies or third-party committees to intervene immediately. In many cases, the system is set up so that the development vendor, who is the party that caused the trouble, investigates the logs themselves and submits a cause report to the administrative side. Structurally, this rarely goes beyond internal verification, making it difficult to ensure objective transparency.

3. The 'Robust Immunity Structure' Inherent in Tax-Funded Infrastructure

In private services, if actual damage occurs, there is the option to file a civil lawsuit seeking damages. However, when the target is an 'administrative system,' the legal barriers are even higher.

While it is possible to pursue liability in contracts between private parties, in the case of administrative systems, only the 'administrative agency' has a direct contractual relationship with the development vendor. Therefore, it is, in principle, extremely difficult for ordinary residents to obtain the legal standing (plaintiff standing) to sue a development vendor directly.

Furthermore, even if one attempts to file a lawsuit against an administrative agency, the barrier of the 'State Redress Act' exists. In reality, if the administration is judged to have 'taken appropriate measures toward recovery (within the scope of administrative discretion),' the hurdle for proving the administration's legal 'intent or negligence' in a system failure in court is extremely high.

Moreover, agencies such as the 'Board of Audit,' which checks the use of tax money, are adept at auditing budget execution procedures and the legality of contracts, but they have limited specialized resources to technically detect technical flaws lurking in source code or invisible defects in programs.

Given that mandatory pre-check functions are weak, there are no specialized agencies to conduct independent post-incident verification, and it is difficult for residents to pursue legal liability, it must be said that modern administrative IT has a structure that slips through the safety governance net that existing infrastructure possesses.

Conclusion: Complementary Self-Defense Measures in a Digital Society

There is no need to deny the promotion of digitalization or DX (Digital Transformation) itself. Just as aircraft have achieved high safety through the existence of strict third-party organizations, building independent 'IT Accident Investigation Committees' or 'IT-version Conformity Certification Systems' will, in the long term, become the foundation for a highly reliable digital society.

However, it is expected that it will take a considerable amount of time before such safety nets (governance) are fully implemented as social systems.

Therefore, rather than relying solely on the convenience of systems, a perspective that objectively assesses what risks may arise in the event of an emergency is required. Until the safety of the mechanisms is fully guaranteed as a system, it is considered a rational approach to surviving the modern digital society stably for individuals to have self-defensive measures as options, such as using 'conventional analog procedures' when necessary or strategically choosing 'physical cards or means' that have a lower risk of payment trouble, depending on the situation.

💡 Clear Distinction from Totalitarianism (Excessive Control)

These points are fundamentally different from calling for 'excessive control by the state or a tilt toward a surveillance society.' The goal is not to monitor the behavior of residents. Just as the Building Standards Act prohibits cutting corners on structural calculations and the Food Sanitation Act eliminates inappropriate food, this is an argument for applying the safety governance that should naturally be possessed as an industrial product to IT infrastructure as well: properly controlling the 'risk of spreading incomplete programs as infrastructure without verification' as a market rule (Pre-incident: vehicle inspection), and thoroughly investigating the cause in the event of trouble (Post-incident: accident investigation).

いいなと思ったら応援しよう!