Instiq
Chapter 6 · Reporting & follow-up·v1.0.0·Updated 7/11/2026·~14 min

What's changed: Initial version

6.4Related laws and guidelines

Key points

Covers the related laws (the Personal Information Protection Act, the Act on Prohibition of Unauthorized Computer Access) on which a systems auditor bases their judgment, and various guidelines such as the Systems Audit Standards and Systems Management Standards that frame the audit and the Information Security Management Standards that serve as the yardstick for control evaluation—from the applied audit viewpoint of against which standard or law a deficiency is evaluated.

A systems audit does not decide good or bad by "the auditor's subjectivity"; it evaluates whether controls are sufficient against the objective yardstick of codified laws, standards, and guidelines. A systems auditor must judge, according to the target information system and its risks, which laws (the Personal Information Protection Act, the unauthorized-access law, and so on) and which standards (the Systems Audit Standards, the Systems Management Standards, the Information Security Management Standards) to base the evaluation on, and diagnose deficiencies against that norm. They also grasp the difference in roles: audit standards show "how to conduct the audit," while management standards and management-standard-type guidelines show "the benchmark of controls the audited side should have."

6.4.1Related laws: the Personal Information Protection Act and the unauthorized-access law

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.