From: Forbes

The following is a guest post from Mihoko Matsubara, a cybersecurity analyst and adjunct fellow at the Center for Strategic and International Studies Pacific Forum.

On June 10, the Japanese government adopted the Cybersecurity Strategy to replace the Information Security Strategy for Protecting the Nation, which was crafted in May 2010 and expires in March 2014. This is the first time for Tokyo to employ the word, “cybersecurity,” in its strategy to deal with information security issues and cyber threats to its national interests. Japan is planning on creating an action plan based on this strategy by the end of June.

In the past, Tokyo focused its efforts on minimizing cyber espionage although the 2010 strategy briefly mentions about potential risks of disruption to critical infrastructure. A series of cyber espionage incidents against the Japanese government and defense industry were revealed recently which has served to elevate the issue of cyber security for Japan. Indeed there have been notable espionage attacks on Mitsubishi Heavy Industries and the Japanese Diet in 2011.

Yet, information theft is just one of many potential consequences from cyber-attacks. Physical disruption of critical services can occur and such cases have happened elsewhere in the world. For example, in August 2003, a computer worm penetrated the network of the Davis-Besse nuclear plantin Ohio and disabled two monitoring systems for five hours. Needless to say, a similar scenario could be potentially devastating for Japan’s already beleaguered nuclear program.

While the Information Security Strategy notices that cyber-attacks can bring grave impacts on national security and crisis management, the true wake-up call did not ring until 2013. On March 20, cyber-attacks were launched against South Korean banks and TV broadcasters and paralyzed their business operations.

Following this incident, both the Japanese public and private sectors became more concerned about cyber incidents and their adverse effects. Despite a rapid growth in cybersecurity-related projects and an increasing demand for experts, Japan continues to struggle with building an adequate capacity to fend off this threat. The country recognizes the necessity for public-private or academia-public-private partnerships to share information; however, most of organizations are unable to take advantage of this information flow due to a lack of financial and human resources. While the Cybersecurity Strategy points out the necessity of developing human resources, the Action Plan needs to elucidate how to recruit, educate, or train such experts and how to utilize the expertise within each organization.

The Cybersecurity Strategy refers to the survey result regarding the shortage of cybersecurity experts, but focuses on technical expertise only. According to the Information-technology Promotion Agency, Japan is short of 80,000 technical experts, whereas the country has about 265,000 experts and 160,000 of them need further education or training. Still, because cyber threats can affect any aspect of human activities, cybersecurity efforts also demand anthropological, defense, geopolitics, legal, linguistic, and technical expertise. This wide variety of skill collaboration calls forcareful selection of trustworthy partners to work together in the academia, government, and industry — most likely not only within Japan but also outside the country. Japan has no domestic anti-virus software manufacturer known in the international market.

On the other hand, the strategy addresses epoch-making initiatives by the government. For example, echoing the first cybersecurity principle of the Ministry of Defense (MOD) and Self-Defense Forces (SDF), the government emphasizes that the SDF is responsible for countering cyber-attacks when they constitute armed attacks although the strategy does not elucidate what is “armed attack” in cyberspace. Accordingly, the MOD is launching the Cyber Defense Unit. Next , the document proposes to add new categories to critical infrastructure if necessary in order to minimize disruption to the lives of citizens and their socioeconomic activities.

In September 2012, Harold Koh, Legal Advisor to the U.S. Department of State, gave three examples of “use of force” in cyberspace. Interestingly enough, all of them are sabotage against critical infrastructure: a nuclear plant meltdown; disruption to a dam to cause flood; and airplane crashes.

This interpretation certainly raised a sensitive question for the Japan-U.S. alliance and prompted officials on both sides to ponder the need to transcend beyond the traditional scope of the alliance. Tokyo and Washington are currently discussing the revision of their bilateral defense-cooperation guidelines and the modification may cover cybersecurity for the first time. Japan has interpreted that the constitution does not allow the country to execute the right of collective self-defense. Under the 2nd Shinzo Abe administration, his national security advisory panel started studying if the execution of this right should cover cyberspace. Because attribution is difficult and there is no internationally-agreed definition of “armed attack” or “use of force” in cyberspace, this makes collective self-defense in the domain challenging. Still, Washington is pursuing collective cybersecurity with allies and this may have a symbolic meaning for the alliances to show the strong will to counter cyber threats collaboratively.

The U.S. government would appreciate information-sharing about the defense industry, given the series of cyber espionage targeting American and Japanese defense contractors. The United States counts the defense industry as part of its critical infrastructure. Also, Washington is expanding an information-sharing framework this year, based on the cooperative mechanism of the defense industrial base under the Executive Order to improve critical infrastructure’s cybersecurity. Thus, Washington would find it encouraging that Japan’s Cybersecurity Strategy specifically argues that Tokyo will start discussions on including the critical infrastructure sector.

The Cybersecurity Strategy surely presents Tokyo’s determination to deal with growing cyber threats and would send positive signals to its ally, the United States. The Japanese government should incorporate specific steps for human resources and domestic or international cooperation in the action plan.