Presentation is loading. Please wait.

Presentation is loading. Please wait.

Cybersecurity Strategy in Japan May 2016 Yasu TANIWAKI Deputy Director-General National center of Incident readiness and Strategy for Cybersecurity (NISC)

Similar presentations


Presentation on theme: "Cybersecurity Strategy in Japan May 2016 Yasu TANIWAKI Deputy Director-General National center of Incident readiness and Strategy for Cybersecurity (NISC)"— Presentation transcript:

1 Cybersecurity Strategy in Japan May 2016 Yasu TANIWAKI Deputy Director-General National center of Incident readiness and Strategy for Cybersecurity (NISC) Cabinet Secretariat, Government of JAPAN

2 ✔ Integrating and advancing cybersecurity policies crossing over governmental bodies ✔ Monitoring, analyzing, and handling cyber attacks to governmental bodies on 24/7 basis as a governmental CSIRT The Leading Organization of Government of Japan for Cybersecurity Issues The Roles of NISC 1

3 “Cybersecurity Strategy” [June 2013] Adopted by the Information Security Policy Council New “Cybersecurity Strategy” based on the Act [September 2015] After accepting opinions from NSC and IT Strategic HQs, the strategy was adopted as a Cabinet Decision, and reported to the National Parliament Based on agreements with other governmental bodies Cybersecurity audit: self audit Incident analysis: NISC provides supports to other governmental bodies on request basis Authority with concrete grounds based on the Act Cybersecurity audit: 3 rd Party audit by NISC Management audit Penetration test Incident analysis: NISC has authority to conduct cause investigation in serious incidents Mandatory reports from other governmental bodies Send formal recommendation to other governmental bodies The Basic Act on Cybersecurity [Enforced from 9 th January 2015] Institutional Framework Authority to GovernmentalBbodies Strategy Before the Act After the Act Strengthened authority Raised status Cabinet of Japan Information Security Policy Council IT Strategic Headquarters (Director-General : Prime Minister) NSC (Chair : Prime Minister) National Information Security Center NISC Clear legislative backgrounds NISC IT Strategic Headquarters NSC Cybersecurity Strategic Headquarters (Director-General:Chief Cabinet Secretary) Established by a Cabinet Order Cooperation National center of Incident readiness and Strategy for Cybersecurity Cabinet of Japan Established by the Act Decision by Director- General of IT strategic HQs Decision by Prime Minister 2 2

4 4 Policy Measures Building a Safe and Secure Society for the People Peace and Stability of International Community and Japan’s National Security Improvement of Socio-Economic Vitality and Sustainable Development Advancement of R&D Development of cybersecurity human resources 1 Understanding on Cyberspace 2 Objective 3 Principles 5 Organizational Framework Cybersecurity Strategy ✔ Free Flow of Information ✔ Rule of Law ✔ Openness ✔ Autonomy ✔ Collaboration among Multi- Stakeholders Cybersecurity Strategy - Principles - 3

5 4 Policy Measures Building a Safe and Secure Society for the People Peace and Stability of International Community and Japan’s National Security Improvement of Socio-Economic Vitality and Sustainable Development Advancement of R&D Development of cybersecurity human resources 1 Understanding on Cyberspace 2 Objective 3 Principles 5 Organizational Framework Cybersecurity Strategy ■ Creation of Secure IoT Systems A guideline for a framework of security standards of IoT systems [Preparing for a Request For Proposal] An IoT security guideline [To be published soon] ■ Encouraging enterprises to report their cybersecurity efforts to the market To consider the way to create a social environment where business leaders would positively tackle with cybersecurity issues as their strategic business challenges [by summer 2016] ■ Supporting information sharing between the private and the public sectors, and within the private sector Cybersecurity Strategy - Promoting Industry by Ensuring Cybersecurity - 4

6 Analytical Framework on IoT Security (draft) - 5 Devices Network Platform Service IoT system System of Systems (SoS)

7 4 Policy Measures Building a Safe and Secure Society for the People Peace and Stability of International Community and Japan’s National Security Improvement of Socio-Economic Vitality and Sustainable Development Advancement of R&D Development of cybersecurity human resources 1 Understanding on Cyberspace 2 Objective 3 Principles 5 Organizational Framework Cybersecurity Strategy ■ Advancing information sharing on software vulnerabilities ■ Conducting constant review on the scope of CIIP and enhancing information sharing on CII The Basic Policy of CIIP 3 rd Ed. [May 2014] Adopting the Roadmap for CIIP Policy Update [March 2016], which aims to enhance CII’s cyber protection Based on the roadmap, NISC started to review & renew measures, such as public-private information sharing scheme and implementation [To be finished by March 2017] ■ Improving cybersecurity measures for governmental bodies The Common Standards for the Governmental Bodies [May 2014] To revise the Common Standards [by summer 2016] Extending NISC’s scope of network monitoring by amending the Basic Act on Cybersecurity [April 2016] Cybersecurity Strategy - Enhancing Cybersecurity Capability - 6

8 4 Policy Measures Building a Safe and Secure Society for the People Peace and Stability of International Community and Japan’s National Security Improvement of Socio-Economic Vitality and Sustainable Development Advancement of R&D Development of cybersecurity human resources 1 Understanding on Cyberspace 2 Objective 3 Principles 5 Organizational Framework Cybersecurity Strategy ■ Advancing discussion on cybersecurity in bilateral cyber dialogues and multilateral frameworks ■ Contributing to the efforts to develop international rules and norms in cyberspace at various fora including UN Cyber GGE National Security Strategy [December 2013] G7 Summit 2016 in Ise-Shima [May 2016] ■ Active contribution to the cybersecurity capacity building in developing countries Cybersecurity Strategy - Improving International Cooperation - 7

9 4 Policy Measures Building a Safe and Secure Society for the People Peace and Stability of International Community and Japan’s National Security Improvement of Socio-Economic Vitality and Sustainable Development Advancement of R&D Development of cybersecurity human resources 1 Understanding on Cyberspace 2 Objective 3 Principles 5 Organizational Framework Cybersecurity Strategy ■ R&D of IoT security for critical infrastructure in the framework of SIP (Cross-Ministerial Strategic Innovation Promotion Program) ■ Promotion of human resources development by partnership between the public and the private sectors Adopting the Comprehensive Policy for Enhancing Cybersecurity Human Resources Development [March 2016] Establishing a new national cybersecurity professional certification by a legislative amendment [April 2016] Building a national cyber range as a NICT’s facility by a legislative amendment [April 2016] ■ Building up institutional framework towards the Tokyo 2020 Cybersecurity Strategy – R&D, Human Resource Development - 8

10 Governmental Organization for the Security of Tokyo 2020 Chair: Deputy Chief Cabinet Secretary for Crisis Management Members: All relevant ministries and organizations. The Tokyo metropolitan government and Tokyo Organizing Committee of the Olympic and Paralympic Games are attending as observers Dealing with security issues regarding Tokyo 2020 Security Board The HQs for Tokyo 2020 Olympic and Paralympic Games Chair: Prime Minister Works as the TOGC (Tokyo Olympic Games Council) requested as a mandatory by IOC The Vice Ministers Meeting for Tokyo 2020 Chair: Deputy Chief Cabinet Secretary Chair: NISC Dealing with cybersecurity issues with all relevant ministries Counter Terrorism WT Cybersecurity WT 9

11 Issues to be dealt with toward Tokyo 2020 10 Human Resources Development Research & Development Enhanced Critical Information Infrastructure Protection Risk Management Government CSIRT for the Tokyo 2020 cooperation TOCOG’s CSIRT ( CIRT2020 ) Cyber Exercise and Training InternationalPartners To identify critical service operators whose services affect Tokyo 2020 operation To establish cybersecurity risk assessment methods To implement cybersecurity risk assessment procedure based on the methods (should be conducted multiple times) To advance efforts in unity To establish an info-sharing and coordinated counter cyber attack framework among government agencies, CII operators, and other related organizations under the leadership of NISC The CSIRT will start its operation for the Rugby World Cup as a first step (summer 2019) Conduct cyber exercises and trainings multiple times among above related organizations, cooperating with TOCOG Bilateral int’l info- sharing frameworks via cyber dialogues, etc. Multilateral int’l info- sharing frameworks such as IWWN Increase and develop cybersecurity workforces especially by increasing cybersecurity education courses, building infrastructure for cyber exercise and training, and revealing individual’s cybersecurity skill by a certification scheme etc., based on the Comprehensive Policy for Enhancing Cybersecurity Human Resources Development [March 2016] R&D topics: Information sharing platform technologies among CII operators and capacity building for cybersecurity operation in CII field [Budgeted by the Cross- ministerial Strategic Innovation Promotion Program ( SIP ) for FY2015 to FY2019] Consider and implement protection improvement measures based on the Roadmap for CIIP Policy Update [March, 2016] Determine concrete measures for enhancement of cyber protection by March, 2017 Responsibility for cybersecurity of games (e.g. stadiums, etc.) cooperation

12


Download ppt "Cybersecurity Strategy in Japan May 2016 Yasu TANIWAKI Deputy Director-General National center of Incident readiness and Strategy for Cybersecurity (NISC)"

Similar presentations


Ads by Google