IPA Revises Guide for Systems Handling Critical Information

Overview

IPA has published and revised a requirements-development guide to balance the stable provision of services by systems handling critical information with autonomy that preserves control during emergencies and convenience that enables adaptation to environmental changes. The guide presents three steps that allow administrators to evaluate system characteristics, organize issues, risks, and convenience factors, and select necessary measures and requirements. In the Version 1.1 revision dated July 27, 2026, notes and related descriptions concerning in-progress data encryption technology were removed in light of progress toward its practical implementation.

This summary was automatically generated by AI. Please refer to the original article for accuracy.

Key points

  • The guide presents a requirements-development framework for considering stable service provision and adaptation to environmental changes at the same time.
  • The process advances in three stages, from evaluating system characteristics to selecting measures.
  • Managing software bills of materials remains an industry-wide challenge involving standardization and interoperability.
  • Version 1.1 removed notes concerning in-progress data encryption.

Overview

The Information-technology Promotion Agency, Japan (IPA) published a guide, following a request from the Ministry of Economy, Trade and Industry, to help administrators of systems handling critical information develop necessary measures. The target systems include those handling critical information for telecommunications and electric power.

Systems handling critical information require autonomy that preserves their own control during emergencies to ensure stable service provision. At the same time, convenience, including cloud services that respond to changing business and technology environments, is also emphasized. The guide organizes an approach for balancing these two considerations when developing requirements specifications.

Requirements development consists of three steps: evaluating system characteristics, selecting issue, risk, and convenience factors, and selecting necessary measures.

Key figures

Initial publication date
July 18, 2023
Last updated
July 27, 2026
Guide version
Version 1.1
Guide page count
48 pages
PDF file size
2.7 MB
System characteristic evaluation items
9 items
2024 update date
July 29, 2024

Impact

Administrators who own systems can more easily compare, within the same framework, factors that impede stable service provision and functions needed to respond to change during construction, procurement, and operation. They can determine the scope required for the target system while confirming the purpose of each requirement.

For businesses and related companies handling critical information in telecommunications and electric power, the guide provides practical material for prioritizing, according to system characteristics, preparations against information leaks and tampering and preparations against data becoming unavailable or systems stopping.

Integrating software and hardware bills of materials across industries requires supplier management and standardized, interoperable formats, leaving initiatives that cannot be completed by individual organizations alone.

Details

In Step 1, system characteristics are evaluated using 9 items to identify the matters that should be prioritized for realization. For autonomy, the process organizes whether to prioritize preventing data leaks and tampering, preventing data from becoming unavailable and systems from stopping, or both. For convenience, it considers priorities for responding to the business environment and the technology environment.

In Step 2, issues and risks related to autonomy and factors related to convenience are clarified in a tree diagram based on the matters organized in Step 1. Viewing the tree diagram as a whole makes it easier to consider which issues require measures and what convenience those measures will provide.

In Step 3, measures linked to the clarified issues, risks, and convenience factors are selected from the tree diagram. The purpose of each measure and the requirements that describe its details are listed in a table, enabling users to select requirements after understanding their purposes.

The guide is provided as the Requirements Development Guide for Systems Handling Critical Information, Version 1.1, with 48 pages and a 2.7 MB PDF file. Some requirements are still being addressed across the industry, and IPA shares the status of those efforts on this site.

To manage software bills of materials comprehensively across all software, each supplier must prepare a bill of materials and those bills must be integrated. Challenges remain in standardizing bill-of-materials formats and ensuring interoperability, and guidance on SBOM promoted by the Ministry of Economy, Trade and Industry is presented as a reference. Hardware bills of materials likewise require similar efforts.

According to the revision history, an explanatory page for a separate practical-use guide was added and supplementary explanations of software bill-of-materials management were updated on July 29, 2024. In the revision dated July 27, 2026, notes and related descriptions on this page concerning in-progress data encryption technology were removed in response to progress toward its practical implementation. Further revisions are expected to reflect the latest technology trends and user feedback.

Related Articles