Instiq
Chapter 6 · Reporting & follow-up·v1.0.0·Updated 7/11/2026·~14 min

What's changed: Initial version

6.4Related laws and guidelines

Key points

Covers the related laws (the Personal Information Protection Act, the Act on Prohibition of Unauthorized Computer Access) on which a systems auditor bases their judgment, and various guidelines such as the Systems Audit Standards and Systems Management Standards that frame the audit and the Information Security Management Standards that serve as the yardstick for control evaluation—from the applied audit viewpoint of against which standard or law a deficiency is evaluated.

A systems audit does not decide good or bad by "the auditor's subjectivity"; it evaluates whether controls are sufficient against the objective yardstick of codified laws, standards, and guidelines. A systems auditor must judge, according to the target information system and its risks, which laws (the Personal Information Protection Act, the unauthorized-access law, and so on) and which standards (the Systems Audit Standards, the Systems Management Standards, the Information Security Management Standards) to base the evaluation on, and diagnose deficiencies against that norm. They also grasp the difference in roles: audit standards show "how to conduct the audit," while management standards and management-standard-type guidelines show "the benchmark of controls the audited side should have."

6.4.1Related laws: the Personal Information Protection Act and the unauthorized-access law

  • Personal Information Protection Act imposes on businesses handling personal information obligations such as specifying the purpose of use, security control measures, restrictions on third-party provision, and responding to the individual's rights. In auditing a system that handles personal data, whether the security control measures this act requires (access control, encryption, oversight of subcontractors, breach response) are in place and operating becomes the yardstick of evaluation, and the auditor points out deficiencies against these legal requirements.
  • Act on Prohibition of Unauthorized Computer Access is a law that prohibits and punishes acts such as using another person's identification code (ID/password) without authorization, or evading restrictions by exploiting a security hole to gain access. In an audit, it serves as the basis for evaluating the state of controls (authentication, access control, log monitoring) that prevent and detect such unauthorized access, diagnosing whether the acts the law prohibits are technically and operationally deterred.

6.4.2Systems Audit/Management Standards and Information Security Management Standards

  • Systems Audit Standards are the norm showing how a systems audit should be conducted (the auditor's stance, independence, and the manner of planning, execution, and reporting). They are the basis for the "auditing side" that secures the quality and objectivity of the audit—a yardstick for the appropriateness of the auditor's own independence, working papers, and reporting, not a direct indication of the audited side's control level itself.
  • Systems Management Standards are the norm showing the benchmark of controls an organization should establish and operate in the planning, development, operation, and maintenance of an information system. The auditor evaluates whether the audited side's controls are sufficient against these management standards. Whereas audit standards are "how to conduct the audit," management standards are "the yardstick of controls the audited side should have"—a difference in role.
  • Information Security Management Standards and various guidelines are a norm that systematizes the benchmark of controls based on information-security management (the ISMS way of thinking), serving as the yardstick for control evaluation in the security domain. There are also field-specific guidelines (cloud, personal information, critical infrastructure, and so on), and the auditor selects and applies the standard or guideline most suited to the target system's risk and purpose. Since applying the wrong standard skews the evaluation, the selection of what to apply is itself an audit judgment.
Exam point

Most-tested points: "Personal Information Protection Act = obligations such as security control measures; the yardstick for evaluating personal-data systems," "unauthorized-access law = prohibits unauthorized use of another's ID; the basis for anti-unauthorized-access controls," "Systems Audit Standards = how to conduct the audit (the auditing side)," "Systems Management Standards = the benchmark of controls the audited side should have," and "Information Security Management Standards = the yardstick for security-control evaluation." Questions test the difference in role between audit and management standards and selecting the standard suited to the target.

6.4.3Judgment in selecting the law and standard to rely on

Suppose a systems auditor audits the information-security controls of an online service that handles a large volume of customer personal information. What to use as the yardstick to evaluate deficiencies is the question. First, because this system handles personal data, the auditor evaluates whether the security control measures required by the Personal Information Protection Act (access control, encryption, oversight of subcontractors, a breach-response setup) are in place and operating, against the objective yardstick of legal requirements—rather than the auditor subjectively saying "somehow insufficient," they diagnose deficiencies against the level the law requires. In addition, since external unauthorized logins are a serious risk, they base the evaluation on whether the authentication, access-control, and log-monitoring controls that prevent and detect the "unauthorized use of another's ID / access evading restrictions" prohibited by the unauthorized-access law are functioning. Next, distinguishing standards. "How to conduct" this audit (the appropriateness of the auditor's independence, working papers, and reporting) follows the Systems Audit Standards, but as the yardstick for evaluating the "controls the audited-side information system should have," they apply not the Systems Audit Standards but the Information Security Management Standards (and the Systems Management Standards as needed), which systematize security controls. Confusing "the audit standards showing how to conduct the audit" with "the management standards showing the benchmark of controls the audited side should have"—using audit standards as the yardstick for control level—would skew the evaluation. Furthermore, if the service runs on the cloud, a cloud-oriented guideline would apply, and so on: selecting the standard or guideline most suited to the target system's risk and purpose is itself an audit judgment. Selecting the laws (Personal Information Protection Act, unauthorized-access law) and standards to rely on according to the target's risk and the data handled (how to conduct = Systems Audit Standards / the benchmark of controls = Information Security Management Standards, Systems Management Standards), and diagnosing deficiencies against an objective yardstick, is the judgment of applying related laws and guidelines.

NormRoleHow used in audit
Personal Information Protection ActObligations and security controls for personal infoYardstick for evaluating personal-data controls
Unauthorized-access lawProhibits unauthorized use of another's IDBasis for anti-unauthorized-access controls
Systems Audit StandardsHow to conduct the audit (auditing side)Appropriateness of independence, papers, reporting
Systems Mgmt / Info Security Mgmt StandardsBenchmark of controls to have (audited side)Yardstick for control design/operation
Warning

Trap: "The Systems Audit Standards are the yardstick showing the very control level the audited side should have" is wrong—audit standards are the norm for how to conduct the audit (the auditing side's stance, independence, reporting), while the benchmark of controls the audited side should have is the Systems Management Standards / Information Security Management Standards. "Evaluating a deficiency may be decided by the auditor's subjectivity" is also wrong—diagnose against the objective yardstick of codified laws and standards. "Always apply the same standard mechanically to any system" is wrong too—selecting the law, standard, or guideline most suited to the target's risk and the data handled is itself an audit judgment.

Where laws & guidelines fit.
Aligning with external frameworks

6.4.4Section summary

  • The Personal Information Protection Act (security controls, etc.) and the unauthorized-access law (prohibiting unauthorized use of another's ID) are yardsticks for control evaluation according to the data handled and its risk
  • Systems Audit Standards = how to conduct the audit (auditing side) / Systems Management / Information Security Management Standards = the benchmark of controls the audited side should have—their roles differ
  • Diagnose deficiencies not by subjectivity but against the objective yardstick of codified laws and standards, selecting the standard or guideline most suited to the target's risk

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You audit the information-security controls of a system handling a large volume of customer personal information. Which yardstick for evaluating deficiencies is most appropriate?

Q2. Which is the most appropriate explanation of the difference in role between the Systems Audit Standards and the Systems Management Standards?

Q3. When evaluating in an audit the state of controls that prevent and detect intrusion using an ID/password without authorization, which law is the most relevant basis?

Check your understandingPractice questions for Chapter 6: Reporting & follow-up

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.