Ministry mum on cyber-attacks / Lack of public disclosure reflects lack of government-wide standards (Japan)
From: The Yomiuri Shimbun
Nearly a year after becoming aware that highly secret data may have been stolen in cyber-attacks on its computers, the Agriculture, Forestry and Fisheries Ministry has yet to announce that the attacks actually took place.
At a time when electronic espionage is rampant, Japan falls far short of managing confidential government information in an integrated fashion. Individual government ministries and agencies are left to take cybersecurity measures on their own. Officials are increasingly worried about the nation’s state of defenselessness.
One of the secret documents suspected to have been stolen describes remarks exchanged between then Prime Minister Yoshihiko Noda and Motohisa Furukawa, then state minister for national policy, during a meeting with senior ministry officials and others that started 11 a.m. on Oct. 4, 2011, ahead of an Asia-Pacific Economic Cooperation summit in November 2011.
According to the document, Noda said, “It seems to be we have no choice other than going with Plan A or Plan B.” The first plan would be to announce, during the summit, Japan’s decision to start talks with relevant countries toward Japan’s participation in Trans-Pacific Partnership free trade negotiations. The second plan would be to put off making the announcement until as late as early 2012. The document states that Furukawa replied: “There is no point in delaying the announcement. We have to make the announcement in November. I will tell agriculture minister Michihiko Kano about it myself.”
The documents on discussions of the timing to announce Japan’s intention of participating in the negotiations also vividly show a ministry official opposed to the early announcement since it might divide the nation or the then ruling Democratic Party of Japan.
Sources said the possible theft of the confidential documents surfaced about a year ago, and some stolen documents were specifically identified around last spring.
A source close to the ministry said it is a clear case of cyberspying. “I shivered as I sensed the intention of a cyber-attacker who tried to sneak a look at Japan’s trade policy,” the official said.
But the ministry made no announcement about the issue. It also failed to touch on the matter in its information security report for fiscal 2011, a document released by each ministry every year.
The ministry disclosed in February last year that it had been the target of another cyber-attack, which had been discovered the previous month. In that case, the ministry received an e-mail with a virus, but there were no tangible ill effects as the mail was disposed of with antivirus software.
In a section of the report for system failure or interruption, the ministry said an infection with the e-mail virus had been prevented.
A senior member of the Cabinet Office’s National Information Security Center, which is in charge of the nation’s information security policies, questioned whether it was appropriate for the ministry not to inform the public of a case that may have been a theft of important information in which the assets of the nation were exposed to danger, even while announcing a case in which there were no tangible ill effects.
Under the government’s unified rules on administrative organizations, established in April 2011, certain measures are required when they come under cyber-attack. But it is not specified in the rules whether the organizations should reveal such cases to the public, or what standards they should follow in doing so.
Because of these vague areas, public organizations’ responses to cyber-attacks vary. The Internal Affairs and Communications Ministry announced its computers were infected with a virus in November 2011. The Finance Ministry, whose computers’ virus infection was found in July last year, announced how, when and how many of its computers were infected, but did not say what information may have been stolen.
Meanwhile the Economy, Trade and Industry Ministry, where 20 personal computers were infected with viruses in November 2010, and the Foreign Ministry, whose computers at diplomatic establishments abroad were hit by cyber-attacks in October 2011, have not officially announced the cases.
| Print article |