SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

[Grandpa Saw It!] Part 1: Taking a Look at the (Draft) SCS Evaluation System!

I am Grandpa, a supporter of Gen Z and the future generation!

Well, this is the second installment of the "Grandpa Saw It!" series for the new year.
Last time it was convenience stores, and this time the theme is cybersecurity.

SCS (Supply Chain Security) evaluation system is being built by the government.
The official name, which will likely be decided by the Cabinet during the ordinary Diet session, is the Policy for Establishing a Security Measure Evaluation System for Strengthening Supply Chains (Draft).

System design is proceeding under this long-winded name.
Let's take a look together at what they are thinking.


1️⃣ Background

The year 2025 was characterized by cyberattacks, particularly a surge in supply chain attacks, the worsening of ransomware damage, and unauthorized access due to phishing and credential stuffing, leading to large-scale information leaks and business suspensions in major insurance, logistics, food, and securities industries.

In particular, cases with large-scale damage stood out, such as Asahi GHD (ransomware damage), ASKUL (ransomware damage), and 10 securities firms (524 billion yen in unauthorized transactions).

Management's excuse that they are "IT illiterate" is no longer acceptable.
Further involvement of management and the strengthening of multi-factor authentication have become urgent tasks.

For ordering companies, it is difficult to visualize security measures at business partners, and ensuring the appropriateness of requirements (checklists, etc.) is also difficult. Because companies act individually, suppliers are forced to meet various requirements from various business partners within a complex supply chain, resulting in excessive burdens being placed on small and medium-sized enterprises.

Therefore, it seems they are proceeding with a system design to ensure appropriateness through a certification system such as "This company is a 3-star security company. ★★★".

Excerpt from meeting materials ①

● It is expected that for both ordering and receiving parties, determining appropriate security measures and explaining the status of measures will become easier and more appropriate.
● Furthermore, by properly implementing security measures at business partners, the reduction of supply chain risks for ordering companies and the strengthening of cyber resilience across the entire economy and society are expected.

Quote from meeting materials ①

2️⃣ The policy draft is supervised by the Ministry of Economy, Trade and Industry and the National center of Incident readiness and Strategy for Cybersecurity

Established in January 2015 under the Cabinet Secretariat, the National center of Incident readiness and Strategy for Cybersecurity (NISC) was strengthened in 2022 to function as a more powerful command tower under the "Cybersecurity Strategic Headquarters". Judging from damage cases like Asahi HD and ASKUL, its importance has recently been increasing from the perspective of economic security as well.

Excerpt from meeting materials ②
Excerpt from meeting materials ③

Even if you are a management team that has never written a single line of code, you must learn the basics; you cannot just leave everything to IT engineers.

In the coming era, it will be difficult for companies that cannot take appropriate measures against business suspension risks (if you leave it to an SIer, management won't be able to judge if they are being charged 200 million yen for measures that could be done for 2 million yen) to survive (they will be cut from the supply chain).

Next, let's look at the outline of the evaluation system and measures to promote its introduction in order.

3️⃣ Overview of the Evaluation System (1)

1) Proposed Operational Structure of the System

Excerpt from meeting materials ④

I am concerned that the relationship between the Ministry of Economy, Trade and Industry (METI), IPA (*1), and the Digital Agency is siloed, but this time, it seems they are creating a structure where the IPA (METI) takes the lead. It really bothers me that the Digital Agency's name doesn't even appear here, though.
*1 IPA: Information-technology Promotion Agency, Japan
*2 Schemes for training security experts are scheduled to be considered in the future

Excerpt from meeting materials ⑤

2) Organizations Subject to the System

Excerpt from meeting materials ⑥

Since cooperation from the ordering party may be necessary for supply chain companies to implement measures, the scope of target businesses (system users) envisioned by the system shall be the area enclosed in the red frame. Note that supply chain companies can also become ordering parties depending on the transaction.
The applicant for the evaluation shall be the unit responsible for improving its own security measures, centered on its own IT infrastructure (basically a corporate entity, corporate group unit, or business division unit).

Quoted from meeting materials ②

3) Levels Established in the System (★3 / ★4)

Excerpt from meeting materials ⑦
Excerpt from meeting materials ⑧

★3 Basic is, in the end, equivalent to Lv1 of the security guidelines of the automotive industry, which is a representative Japanese industry (a rip-off), and ★4 Standard seems to refer to (a rip-off of) Lv2 and part of Lv3.

As expected, the automotive industry, which has high international competitiveness, is quick to prepare for industry-wide optimization. It is proof that they have a firm grasp on distinguishing between areas where individual companies compete and areas where they should standardize to enhance international credibility, and

the management team has high IT literacy!

Excerpt from JAMA/JAPIA Cybersecurity Guidelines V2.3

Let's leave it at that for the first half.

Read the rest

Thank you for reading to the end.
If you liked it, please click the "Like" 🤍 button 😊😊
If you leave a comment, I'll be jumping for joy 😂😂😂

This is an archive of Grandpa's posts👇

🌳The most popular series on the Retiree's Channel🌳
[The Story of Mototaka Ikawa Before the Meltdown]

🌳A series about making memories with Grandpa and his granddaughter🌳
[Grandpa's Grumbling]

🌳
Grandpa's initial 3-post set + era retrospective series🌳
What were you doing at that time? (1985–2020)
[Japan-US Growth Gap] ~Japan will definitely make a comeback~
[The Blind Spot of Climate Change] ~What Japan can do as a forest-rich nation~
[Let's Help the Earth Together] ~A decarbonized society will be created by you, Gen Z~

🌳
A series where Grandpa picks up information from government ministry websites, etc.🌳
[Grandpa Saw It!] Site Map Part 1
[Grandpa Saw It!] Site Map Part 2

🌳These are Grandpa's posts related to politics, economy, environment, and occasionally education🌳
[Grandpa's Odds and Ends] Site Map
[A Little Break] Site Map
[Whispers of Society (1)] Magazine

🌳Grandpa's Current Events Senryu Series🌳
[note Senryu]

🌳
Series of stories that moved Grandpa🌳
[Grandpa is Moved!]

🌳Magazine for Grandpa's preparation series for retirement🌳
[Grandpa's Preparation] Magazine

😄
Please support Grandpa, the Gen Z cheering squad leader😄
Self-introduction of Grandpa, the Gen Z cheering squad leader!?

For other things, please see
[Grandpa's A La Carte].

いいなと思ったら応援しよう!