Japan's Personal Information Protection Commission (PPC) presented measures to strengthen security for companies in response to a series of large-scale personal information leaks, including phishing-resistant multi-factor authentication, adoption of endpoint detection and response (EDR), and deletion of unnecessary personal information.
On Oct. 8, Japanese media outlet ITmedia reported that the PPC issued a notice the previous day titled "Response based on large-scale leak incidents". It brought forward and disclosed some response examples that it plans to include in a revised personal information protection guideline due to be amended in April next year. It especially urged strengthened protective measures for operators that hold large volumes of personal information or sensitive information, or data with a high risk of being misused for fraud.
In the area of authentication, it presented applying phishing-resistant multi-factor authentication when accessing external networks, administrator accounts or important personal information. FIDO2-based passkeys are a representative example. It also included evaluating access location and time and device security status each time and allowing access depending on the level of risk, and restricting access to personal information to approved devices only.
For intrusion detection, it called for using IDS/IPS and EDR to identify anomalies early, and to immediately isolate compromised systems or deactivate accounts to prevent damage from spreading. It also cited as an example using methods that cannot be easily restored when deleting personal information stored in the cloud, such as secure deletion functions provided by service providers or deletion through encryption.
The PPC also pointed to the continued retention of personal information that is no longer needed as a problem. The Personal Information Protection Act stipulates that efforts should be made to delete data without delay once it is no longer necessary to use it. The commission said there were cases in actual leak incidents where the scale of damage grew because information was left behind unnecessarily, and urged a recheck of the need for retention together with the legal basis.
A representative case is the Times Car car-sharing service incident that occurred last month. Personal information from about 6.6 million accounts was leaked, and about 1.6 million cases included identity verification documents such as driver's license images. Information on people who had withdrawn from the service was also kept for about 7 years and was included among those affected.
The PPC also updated "WARNING" materials summarising nine types of unauthorised access incidents and their causes and countermeasures. Key cases included delayed responses to vulnerabilities, account takeovers and breaches of cloud services.