TRAFEED

Implementing Risk Mitigation Measures: How Far to Go with the Seven Examples in Research Security

Published2026-07-24Ryuta Hamamoto

A practitioner's walkthrough of how universities and research institutions can implement the seven risk mitigation measures set out as examples in Japan's Cabinet Office procedures manual. Access rights to facilities and equipment, research locations, who attends meetings, employment contracts, training, data access rights and cyber defence, plus how DMPs, the Common Standards and TICS fit in, and what "reasonable measures proportionate to the degree of risk" actually means in practice.

Implementing Risk Mitigation Measures: How Far to Go with the Seven Examples in Research Security
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

Of everything in research security, the topic that splits the room most reliably is risk mitigation measures. Due diligence, meaning the work of checking the items you are expected to verify about a counterpart or a researcher, at least tells you what to look up. The task has edges. Move one step further into the measures, and hands stop moving.

The reason is not mysterious. In Japan's Cabinet Office procedures manual, each measure is a single heading-length line. "Managing access rights to facilities and equipment" is the whole of it. Whether that means issuing door cards, or partitioning rooms, or something else entirely, the manual does not say. Because it does not say, the person responsible cannot tell how much is enough, cannot explain the choice upwards, and ends up picking the heaviest available reading of the text.

Let me put one premise in place before anything else. None of this applies uniformly to all research. The scope is Specified Research and Development Programs: competitive research funding, meaning research money that researchers and institutions win by applying to open calls, where the results are expected to be published, and where the responsible government ministry, in consultation with the funding agency that distributes the money (JST is one), has designated the programme as potentially involving technologies on the critical technology areas list. Institutions applying to a designated programme are asked to run a four-stage cycle: risk verification, risk assessment, risk mitigation measures, and follow-up. This article is about stage three.

I will take the seven example measures one at a time and translate them into something you can act on. First, though, the principle that sits above all seven, because getting that wrong makes everything downstream heavier than it needs to be. For the wider picture, see the complete guide; for how to gather the verification items themselves, see how to answer the questionnaire. If you also want a reading on where your export control arrangements currently stand, our export compliance self-check gives you a baseline before you read on.

Reading "reasonable measures are sufficient" accurately

Start with how to read the manual at all. Skip this and all seven items below will look like obligations.

The manual opens by defining the strength of its own sentences. Passages marked "necessary" describe the minimum measures that should be implemented; passages marked "desirable" describe measures that are desirable but whose implementation is not required at this time1. So a single document deliberately mixes two grades of instruction, and it tells you upfront to read the verb endings. Around risk mitigation, the two grades are interleaved quite finely.

With that in hand, here is the central sentence about measures.

Research institutions must implement risk mitigation measures in light of the results of risk verification and risk assessment, and where a funding agency requests the implementation of additional risk mitigation measures, must respond appropriately. The risk mitigation measures implemented by research institutions may be considered to include those set out below by way of example, and reasonable measures proportionate to the degree of risk are sufficient1.

That sentence has two layers. Implementing measures is "necessary." The content is illustrative, and reasonable measures proportionate to risk are sufficient. Reading the two together is the accurate reading. Doing nothing is not on the table. Covering all seven is not an obligation either.

The manual is also open about why it was built this way. Chasing zero risk would mean "expending considerable effort and cost to verify information about counterparties, or making research institutions and researchers excessively restrictive about international joint research and the like, with adverse effects on the research environment. If that were to obstruct research as a result, it would defeat the purpose"1. The regime itself rejects overreaction, in writing.

And the manual is not law. It explains that, given that appropriate responses may differ according to the characteristics of a research field, the maturity of a technology and the circumstances of an institution, it was formulated as a guideline, as in other G7 countries, to provide a flexible framework1. The intent not to run this as a uniform rulebook is right there on the page.

Sufficiency is ultimately judged by the responsible ministry and the funding agency. That is not a one-way examination, though. The manual says that "the content of risk mitigation measures shall be considered through consultation and coordination between the funding agency and the research institution as appropriate"1. Consultation is not merely permitted; the design assumes it. Institutions that do not know this and try to reach perfection alone pick the most exhausting possible route.

The seven example measures, put to work

Here are the measures the manual lists, in the order of the original1.

  1. Managing access rights to facilities and equipment
  2. Securing off-campus and other research locations
  3. Considering who attends meetings and similar, according to the sensitivity of the information handled
  4. Strengthening governance through employment contracts (for instance where a research participant is a student)
  5. Improving research security literacy through training
  6. Managing access rights to research data and other information
  7. Strengthening defences against cyberattack

That this is not an exhaustive list is clear from the template questionnaire in the annex. Alongside checkboxes for the seven items sits an "other" box with free text1. The manual itself expects measures outside its own examples.

In what follows I separate what the primary source actually says from my own reading as a practitioner. Blurring the two is how bad internal documents get written, so I would rather be explicit about which is which.

Places and equipment (measures 1 and 2)

On access rights to facilities and equipment, the manual gives exactly one handhold. Among the items whose appropriateness it is desirable to verify at application, it lists the "management policy for the facilities and equipment used in the research (buildings, rooms, laboratories, experimental apparatus and the like)"1. Buildings, rooms, laboratories, apparatus. Those four granularities are the management units the manual has in mind.

The flip side is that nothing beyond that is written. No instruction to install an access control system. No instruction to convert to electronic locks. In practice, for a great many institutions, listing the apparatus and rooms used by the programme and writing down on a single sheet who may enter and who may not is enough to start. My sense is that a good number of institutions could satisfy this by adding one column to the key management register they already keep.

Measure 2, securing off-campus and other research locations, has no further explanation in the manual at all. One line, and that is it. The idea appears to be physically separating the more sensitive parts of the work from ordinary shared space, but since nothing more is written I will not pretend to a firmer reading. Using an external experimental facility, or running certain procedures in a dedicated room, is about as far as the text supports.

People and contracts (measures 4 and 5)

The employment contract measure has students in mind. In relation to a university, a student is an enrolled learner rather than an employee, and without an employment relationship the legal footing for imposing confidentiality obligations and information handling rules by contract is thin. Put a research assistant (RA) employment contract in place and governance becomes enforceable. I covered this in detail in taking on students and RAs.

What people miss is the footnote attached to this item. "Where a research participant is a secondee from another institution, a dispatched worker, an employee of a contractor or similar, verifying the content of the contract relating to their research participation is desirable"1. This is not only about students. When someone with no employment relationship to your institution works on the research, you go and look at the contract they do have. Note the grade, though: this one is "desirable," not required.

Training is split across three layers in the manual. Research institutions: encouraging attendance at training is desirable where affiliated researchers are applying, or plan to apply, to a Specified Research and Development Program. Researchers themselves: actively attending training is desirable. And the Cabinet Office: preparing training materials on ensuring research security, holding briefings and conducting training is necessary1. Producing the materials is written as the Cabinet Office's job, which is worth remembering because it takes weight off your shoulders. The regime does not ask you to build a curriculum from nothing.

Information and systems (measures 3, 6 and 7)

Try to manage access rights to research data and you stall immediately on one question: which data is in scope? The manual answers it. "Managed data" is defined in government policy as "research data whose scope is determined by the researcher as subject to management and utilisation, in accordance with the standards of the university, inter-university research institute corporation, national research and development agency or other research institution to which the researcher belongs, or of the funding agency"1. The person who sets the scope is the researcher. So implementing measure 6 does not begin with choosing a permissions tool. It begins with drawing a boundary.

Access rights also have a contractual entrance that is easy to overlook. For joint research contracts and other agreements, the manual says verifying the appropriateness of the content of cooperation, access to research data, the treatment of inventions, patents and other intellectual property, and the confidentiality obligations is necessary1. That is the "necessary" grade, not the "desirable" one. However finely you slice permissions in a system, it means little if the contract grants broad access to the data. Contract first, then system, is the order that makes sense to me.

Measure 3, considering who attends meetings, reads at first like a matter of etiquette, but it runs continuous with measure 7. The manual's footnote lists three representative cases where information security should be verified: outsourcing the development, operation or maintenance of systems; use of cloud services such as virtual servers and web conferencing; and procurement of IT-related equipment1. Web conferencing being named explicitly is a very practical touch. Who you invite into a meeting and where the tool running that meeting actually lives are not separable questions.

One caution. Access control systems, zero trust, endpoint management, log monitoring: none of these terms appear anywhere in the manual. Neither do most of the specifics I have suggested above, which are my practitioner's reading and nothing more. If you transcribe them into an internal document as though the manual required them, your explanation will fall apart the first time someone checks the source.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

What holds the measures up: the DMP and three management policies

Try to implement the seven and you discover a shared foundation underneath them. The manual places that foundation somewhere other than the list of measures, which is part of why it gets missed.

The first layer is routine information gathering. The manual lists three kinds of information that it is desirable for research institutions to collect: information on data management plans (DMPs, meaning documents prepared in advance setting out how research data will be managed and released) prepared in accordance with the government's Basic Policy on the Management and Utilisation of Research Data Funded by Public Money; information on the management of information systems at the institution; and information on the management of its facilities and equipment1.

The second layer is verification at application. It is described as desirable for the lead institution to verify the appropriateness of four things: the DMP for the research; the management policy for material that cannot be managed in electronic form, such as physical samples; the management policy for the information systems used; and the management policy for the facilities and equipment used1.

Of those four, the information systems item carries a parenthesis you should not skim past. "(Including those managed by the PI.)"1 In the passage addressed to researchers it reads "(including those managed by the PI and Co-PIs)." PI is principal investigator and Co-PI is co-principal investigator, the researcher leading the work at a partner institution; think of them as the professors running the labs. Servers and NAS boxes the lab stood up itself. Cloud storage bought with grant money. Shadow IT, meaning equipment and services the organisation's IT department does not know about, is explicitly inside the scope of the management policy. The regime clearly understands that a discussion of information security which excludes it does not touch reality.

There is something else to be precise about, though. The DMP and all three management policies sit on the "desirable" side, and none of them appear in the annex checklist or the questionnaire. The questionnaire is limited to matters graded "necessary." So an institution without a mature DMP practice is not thereby barred from applying.

And yet this is where effectiveness is decided. You cannot design access rights without a defined scope of managed data, and you cannot decide who gets into which room without a management policy for rooms and apparatus. The measures are the superstructure; this is the foundation. Not obligatory, but needed first. Holding that distinction from the outset keeps you from starting in the wrong place.

The division of labour is written down too. The institution produces the management policies; PIs and Co-PIs are expected to prepare appropriate DMPs and to instruct participating researchers on managed data and on the management of facilities and equipment1. The institution builds the frame, the lab operates within it.

The Common Standards and TICS: do not confuse the grades

On strengthening defences against cyberattack, the body text gives you one line, but the footnote points to specific references. The grading here is delicate, so I will follow the original closely.

For national administrative organs, incorporated administrative agencies and designated corporations (hereinafter "agencies and the like"), the "Common Standards" have been prepared to enable the information security measures commonly required of all such bodies. Accordingly, agencies and the like must verify whether information security is ensured for information on critical technologies handled under a Specified Research and Development Program, against the information security policies, operational rules and the like that each such body has formulated in light of the Common Standards. Research institutions (other than agencies and the like) may also consider verifying whether information security is ensured, with reference to the Common Standards1.

The distinction turns on one point. For agencies and the like, meaning national administrative organs and incorporated administrative agencies, verification is necessary. For every other research institution, verification with reference to the Common Standards may be considered. A national university corporation or a national research and development agency and a private university are not in the same position under this footnote. Work out which side your institution is on before you read any further into it.

For completeness: the full name is the Common Standards for Cybersecurity Measures for Government Agencies and Related Agencies, comprising the unified norms, the unified standards, and guidelines for formulating countermeasure standards. The FY2025 standards were adopted by the Cybersecurity Strategic Headquarters on 27 June 2025, and the FY2025 guidelines were prepared by the National Cyber Office of the Cabinet Secretariat on 1 July 20252. Responsibility moved from NISC to the National Cyber Office, and the published URLs moved with it. All of that comes from the Common Standards side, not from the procedures manual, which says only "the Common Standards." Cite the two separately in internal material.

Higher education institutions get a second pointer. The manual notes that the "Sample Regulations for Information Security Measures at Higher Education Institutions" (National Institute of Informatics) may also be considered as a reference1. For a university, that document is closer to daily practice than the Common Standards are, and I would start there.

TICS deserves a mention as well. The manual's footnote says: "Where risk mitigation measures are implemented, it is necessary to build a comprehensive organisational and information management structure. As a related initiative, there is the Technology Information Management Certification System (TICS), under which bodies accredited by the state examine and certify an organisation's information security structure on the basis of national standards"1.

The important thing here is that the manual does not ask you to obtain TICS. Not "necessary," not "desirable." It is presented as a related initiative and nothing more. TICS itself is a scheme for businesses, which METI describes as "a system under which certification bodies accredited by the state examine and certify a company's information security measures against standards formulated by the state"3. Some certification bodies limit their scope to manufacturers or to small and medium-sized enterprises. No primary source anywhere says universities should obtain it.

If it is worth mentioning at all, it is because the thinking behind it matches. METI explains that under TICS "companies can select measures suited to their own level and obtain certification accordingly," and notes that it can take "as little as one to two months, at a cost in the region of several hundred thousand yen," which may be reduced by limiting the departments in scope3. Choose according to your level; narrow the scope and the burden falls. That is precisely the same idea as "reasonable measures proportionate to the degree of risk." Worth having in mind if your research institution is a company, or as a reference when you are considering a comprehensive management structure.

Is the measure on paper actually running?

Deciding the measures and writing them on the questionnaire is not the end. After the seven items and the "other" box, the template asks for this: "You need to confirm that the responses above are feasible. □ I have confirmed that they are feasible"1. Listing measures is not enough; confirming that they can actually be carried out comes with it.

At the foot of the template sit the conditions for starting the research. Agreement from the PI, the Co-PIs and the research participants in the research structure on everything stated, and confirmation from the responsible departments of both the lead institution and the partner institutions. The note says research cannot begin unless both boxes are ticked1. Researcher consent and administrative confirmation, both wheels. An administrative office that decides the measures on its own, without the researchers behind it, has produced paperwork rather than a control.

Follow-up continues after the research starts. The manual states that "after the commencement of research conducted under a Specified Research and Development Program, research institutions must verify the status of implementation of risk mitigation measures as appropriate, and implement initiatives in light of the results"1. That is the "necessary" side. It adds that where a research participant is added, conducting due diligence on that person is necessary, and that where an error is discovered in declared information, promptly reporting to the funding agency and conducting due diligence again is necessary1.

Read through all of that and the shape of the work becomes clear. Risk mitigation is not a large systems investment. It is deciding who can reach which place and which information, recording the decision, and correcting it when things change. Then repeating that.

There is one part institutions genuinely struggle to cover alone. To decide how heavy a measure should be, you need the risk assessment first, and the manual defines assessment as looking at what impact a risk would have and how likely it is to occur1. Magnitude of impact and likelihood of occurrence. Without material to support those two axes, you cannot calibrate anything. The most labour-intensive material of all is the relationships between people and organisations. Co-authored papers, joint patent filings, joint research, named co-presentations at conferences. Without tracing those connections backwards through time, there is no basis for deciding how much access a given researcher should have. The manual acknowledges this too, noting that where the publicly available tools alone make adequate due diligence difficult, using commercial information analysis tools or commissioning investigations from firms may also be considered1.

Relationship data is exactly what we have been accumulating at TRAFEED for export control. A knowledge graph of more than 200 million records, meaning a database that keeps the connecting edges between people, organisations, papers and patents rather than storing them as separate rows, covering roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, with corporate registries and national control lists layered on top. One caveat I want stated plainly: appearing on such a list is a regulatory designation under a given country's system, not a judgment about the organisation or the researcher listed. Listing status is one verification item among many, and it does not by itself decide whether a transaction or a collaboration can go ahead. That is the premise we operate on. TRAFEED is the world's first AI agent for Japan's security export control field, covering both list controls and catch-all controls, which we confirmed through our own research as of March 2026. In joint validation with Okayama University, using roughly 30,000 records of past screening decisions, AI determination accuracy came out above 95% (our own study). We hold Japanese Patent No. 7862062 and the service is in use at more than 20 organisations.

In the context of risk mitigation, what visibility into relationships buys you is the material for deciding which researcher and which partner institution gets how much access. Connections one or two hops out, which name matching will never show you, become something you compute rather than something you chase. Alongside researcher information, we are extending into shareholder and capital relationship research on partner organisations. Full support for research integrity and research security is an area we are still building, and I am not going to claim it is already implemented. The final determination belongs to the research institution, or in a company's case to its export control officer. What we can take on is limited to assembling the material and leaving it in a form that can explain, later, why a conclusion was reached.

One premise underlies this whole article and deserves stating on its own. The manual is explicit that "in judging whether a counterpart is a trustworthy partner, there must plainly be no discriminatory treatment on grounds of nationality, race, religion, culture or the like"1. Designing access rights is not an exercise in sorting people by attribute. It is an exercise in designing where information and locations sit, according to where the risk is. An operation that confuses the two has left the intent of the regime behind.

What to take away

  • Implementing measures is "necessary," but the content is illustrative and reasonable measures proportionate to the degree of risk are sufficient. There is no obligation to cover all seven
  • The manual gives you one heading-length line per measure. When you put specifics into internal material, keep the primary source and your own practitioner reading visibly separate
  • The DMP and the three management policies sit on the "desirable" side and are absent from the questionnaire, yet they are what makes the measures effective
  • On the Common Standards, agencies and the like "must verify"; other research institutions "may consider verifying with reference to" them. The grades differ
  • TICS is a related initiative the manual mentions. Obtaining it is not asked for
  • Writing the measures down is not the end. Confirming feasibility and following up after the research starts are both part of it

The most common failure I see in this field is not inadequate controls. It is being unable to explain the controls you chose. On what basis did you select this measure? Why was this researcher granted this level of access? Keep that reasoning and a light measure still holds up. Stack up heavy measures with no reasoning behind them and you will have nothing to say when a request for additional measures arrives.

So start by writing the rooms, the apparatus and the data used by the programme onto a single sheet. From there the road is shorter than most people expect. If you are working out the order to tackle this in, talk to our TRAFEED team.

References and primary sources

Footnotes

  1. Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27

  2. National Cyber Office, Cabinet Secretariat, "Common Standards for Cybersecurity Measures for Government Agencies and Related Agencies (FY2025 edition)," adopted by the Cybersecurity Strategic Headquarters on 27 June 2025 https://www.cyber.go.jp/pdf/policy/general/kijyunr7.pdf and "Guidelines for Formulating Countermeasure Standards for Government Agencies and Related Agencies (FY2025 edition)," 1 July 2025 https://www.cyber.go.jp/pdf/policy/general/guider7.pdf

  3. METI, "Technology Information Management Certification System" https://www.meti.go.jp/policy/mono_info_service/mono/technology_management/index.html 2

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles