4.3
International rulemaking for cybersecurity
In cyberspace, various countries with different values and systems coexist. Moreover,
cyberspace is used in a variety of ways by diverse entities. In order to maximize the
benefits of cyberspace, it is important to ensure that it can be used in a stable manner. In
this regard, international rules need to be made for various activities which make use of
cyberspace, while strengthening personnel ties in the medium and long term.
4.3.1
Formulation of international standards of technology
As cybersecurity systems are increasingly traded internationally, maintaining
technological standards of such systems is growing in its importance so as to ensure their
interoperability and security level.
While various initiatives are underway for international standardization, it is important to
formulate and disseminate international standards of cybersecurity technology and to
create mutual recognition frameworks. In this regard, public-private partnership is
essential since enterprises and other such entities are the main actors to actually use
such standards in their business activities.
Japan established the Control System Security Center (CSSC) in 2013, which serves
as the basis for setting up evaluation and authentication technology for control system
security. Japan will institute an evaluation and authentication organization for promoting
the use of such technology and will also contribute to activities of enterprises and
organizations participating in the CSSC to propose new international standards using the
CSSC. Additionally, as part of the cybersecurity measures, Japan will actively promote the
Common Criteria Recognition Arrangement (CCRA) for procurement, which is an
international framework for mutual recognition of authentication. Furthermore, Japan has
also contributed to formulation of the Cybersecurity Information Exchange Framework
(CYBEX) at the International Telecommunications Union (ITU), and will continue to
promote this activity in cooperation with other countries.
As for cloud services, Japan is leading the activities for international standardization of
cloud security at the International Organization for Standardization (ISO) and ITU so that
cloud services can be used safely and securely. In addition to actively contributing to the
prompt adoption of international standards, Japan will promote the formulation and
dissemination of a concrete manual together with relevant enterprises both in Japan and
overseas, and will promote the sharing of knowledge acquired through this process.
It is important to note that, while ensuring cybersecurity remains an important agenda,
excessive control over what technology to be used, for instance by giving priority to
domestic technology over those from abroad, may result in reduction of domestic security.
In the spirit of mutual prosperity of all the relevant countries, Japan seeks consistency
with international trade rules taking into consideration transparency and fairness so that
regulation does not become excessive.
8