Reading the Matrix · A-11
Reading the Matrix in the APJ Context
Most security frameworks were written by Americans, for American enterprises, under American regulatory assumptions. The NIST CSF was developed by NIST, a US agency. The CIS Controls came out of the SANS Institute. ATT&CK is a MITRE project. Even the Cyber Defense Matrix, though it maps well to any environment, was first presented at RSA Conference in San Francisco.
This doesn’t make these frameworks wrong for APJ. It means applying them in APJ requires translation work that the frameworks themselves don’t provide. Regulatory requirements differ. Organizational structures differ. The threat landscape has regional characteristics. The vendor market looks different. The talent pool is constrained in specific ways that aren’t universal.
This article does that translation work for the CDM in four major APJ markets: Japan, Singapore, Australia, and South Korea. It’s longer than most articles in this series because the regional specificity is the point.
Japan
The regulatory layer
Japanese financial institutions operate under a layered regulatory structure that doesn’t have a direct Western equivalent.
The Financial Services Agency (FSA / 金融庁) sets supervisory expectations through its Guidelines for Supervision (監督指針) and cybersecurity-specific guidance. The FSA’s cybersecurity assessment framework, introduced in 2018 and updated subsequently, requires major financial institutions to conduct annual self-assessments using a structured format. The assessment covers governance, risk management, and technical controls across a scope that maps reasonably well to CDM cells, though the FSA framework uses its own taxonomy.
FISC (Financial Industry Information Systems / 金融情報システムセンター) publishes the most operationally specific guidance for Japanese FSI: the Security Guidelines on Computer Systems for Financial Institutions (金融機関等コンピュータシステムの安全対策基準). The 14th edition, published in 2023, covers endpoint security, network security, application development security, access management, incident response, and business continuity. FISC is not legally binding in the same way that FSA supervision is, but adherence to FISC guidelines is widely treated as the practical standard for what “reasonable security” means in Japanese financial services. Deviating from FISC without documented justification creates examination risk.
NISC (National center of Incident readiness and Strategy for Cybersecurity / 内閣サイバーセキュリティセンター) publishes guidance for government agencies and critical infrastructure operators. For commercial enterprises, NISC guidance is relevant context rather than binding requirement, but it shapes regulatory expectations in sectors classified as critical infrastructure.
Mapping FISC to CDM
FISC Chapter structure maps to CDM cells with reasonable precision:
FISC Chapter 1-2 (Computer Facility Management, System Operation Management) maps primarily to Devices/Identify and Devices/Protect. Physical security controls for data centers and server rooms, hardware asset management, operational procedures for system changes. These chapters are detailed and prescriptive; compliance is typically high because the requirements are concrete.
FISC Chapter 3 (Network Management) maps to Networks/Identify and Networks/Protect. Network architecture documentation, perimeter security, remote access controls, wireless security. FISC is thorough here; the Japanese FSI network perimeter has historically been well-defended. The relative weakness is Networks/Detect: FISC requires logging and monitoring but is less prescriptive about what detection capability should look like.
FISC Chapter 4 (Application System Development Management) maps to Applications/Identify and Applications/Protect. Secure development lifecycle, vulnerability testing requirements, change management. FISC coverage of application security has strengthened in recent editions, partly in response to incidents involving web application attacks on Japanese financial institutions.
FISC Chapter 5 (Access Management) maps across the Users and Devices rows in Protect. Authentication requirements, privileged access management, access review processes. FISC’s authentication requirements have been updated to reflect MFA expectations, though implementation varies across institutions.
FISC Chapter 6 (Incident Response and Business Continuity) maps to Detect, Respond, and Recover across all rows. This is where FISC is thinnest relative to the CDM. The framework requires incident response plans and business continuity plans, but the prescriptive detail for detection capability, response playbooks, and recovery testing is less developed than the protective controls in earlier chapters.
The CDM scorecard exercise (Article 6) is particularly valuable for Japanese financial institutions precisely because FISC coverage is uneven across the matrix. A FISC compliance assessment that produces a high overall score can hide significant gaps in Detect and Respond cells.
Structural characteristics of Japanese enterprise security
A few patterns that recur across large Japanese enterprises and that affect how the CDM applies:
Organizational separation between IT and security is pronounced. The security function in many Japanese enterprises operates as an advisory and oversight function rather than an operational one. IT operations owns most of the Identify and Protect cells; security provides guidance and monitors compliance. This creates the handoff problems described in Article 5, often in acute form.
Vendor concentration is high. NTT Data, Fujitsu, NEC, Hitachi, and a small number of other system integrators handle a large proportion of enterprise IT in Japan. Security products are frequently procured through these SIs rather than directly from security vendors. The CDM is useful for evaluating what capability the SI-delivered solution actually provides, independent of the SI’s positioning.
Legacy infrastructure is extensive. Japanese enterprises, particularly in financial services, manufacturing, and public sector, carry significant mainframe and legacy application portfolios. Some of these systems predate modern security tooling by decades. CDM cells in the Applications row are often partially or entirely empty for legacy systems because the systems don’t support the instrumentation that modern security tools require.
The talent market is tight in specific ways. Japan has a general IT talent shortage that is well-documented. In security specifically, the shortage is acute at the analyst level (Detect and Respond functions) and less severe at the compliance and audit level. This maps directly to the CDM’s People/Tech continuum: the functions that most need people (Detect and Respond) are the ones where Japanese enterprises are most understaffed. Managed security services and MSSPs fill some of this gap, but the quality of MSSP detection and response capability varies significantly.
METI’s cybersecurity initiatives are worth noting for non-FSI Japanese enterprises. The Cyber Security Management Guidelines (サイバーセキュリティ経営ガイドライン), published by METI and IPA, provide a CDM-compatible organizing structure for enterprise security governance without the FSI-specific requirements of FISC. The 2023 revision increased emphasis on supply chain security and incident response, both of which map to specific CDM cells.
Singapore
The regulatory layer
Singapore’s Monetary Authority of Singapore (MAS) publishes the most comprehensive financial sector cybersecurity framework in Southeast Asia. MAS Notice MAS-TM-G1 (Technology Risk Management Guidelines, revised 2021) and the accompanying Notice MAS 655 (Cybersecurity) for banks set specific requirements with measurable thresholds.
MAS TRM is notable for its specificity: it includes requirements for system availability, recovery time objectives, penetration testing frequency, and cyber incident reporting timelines that are more concrete than most regulatory frameworks. The 4-hour notification requirement for significant cyber incidents (under MAS Notice 655, Section 13.1) is among the most demanding in the region.
The Cyber Security Agency of Singapore (CSA) publishes the Singapore Cyber Landscape report annually and maintains the Cybersecurity Code of Practice for Critical Information Infrastructure owners. The CCoP maps to CDM cells but uses its own structure.
CDM application in Singapore
The Singapore environment is useful to contrast with Japan in a few ways.
The talent pool is more internationally diverse, English is the business language, and the regulatory framework is written in a style closer to international best practice than the FISC model. Singapore enterprises tend to have earlier adoption of cloud services and a higher proportion of security tooling procured directly from international vendors rather than through domestic SIs.
The CDM’s Detect and Respond cells tend to be more developed in Singapore FSI than in comparable Japanese institutions, partly because MAS has been more prescriptive about incident detection and notification requirements and partly because the talent market supports it.
The regional headquarters dynamic is significant: many global financial institutions run their APAC security operations from Singapore. This creates CDM coverage map complexity: which cells are covered by the global security operations center, which are covered by the regional team, and which are gaps in the handoff between them? Article 5’s handoff analysis applies here with a cross-border dimension.
MAS’s Adversary Attack Simulation (AAS) framework, introduced in the TRM 2021 revision, requires significant financial institutions to conduct advanced threat simulation exercises. This maps directly to the assessment framework in Article 8: MAS is essentially requiring red team-level testing for major institutions, with a threat-intelligence-driven scope. The CDM provides the architectural context for scoping those exercises.
Australia
The regulatory layer
APRA (Australian Prudential Regulation Authority) CPS 234 (Information Security), which took effect in July 2019, is the primary binding cybersecurity requirement for APRA-regulated entities: banks, insurers, and superannuation funds. CPS 234 requires entities to maintain information security capability commensurate with the size and extent of threats, notify APRA of material information security incidents within 72 hours, and test the effectiveness of controls annually.
The Australian Cyber Security Centre (ACSC) publishes the Essential Eight Maturity Model, which is the most widely referenced security baseline for Australian government agencies and is increasingly adopted in the private sector. The Essential Eight covers: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
Essential Eight through CDM
The Essential Eight maps to CDM cells in a distribution that reveals its design intent:
Application control (Devices/Protect), patch applications (Applications/Protect), Office macro settings (Applications/Protect), user application hardening (Devices/Protect and Applications/Protect), restrict administrative privileges (Users/Protect and Devices/Protect), patch operating systems (Devices/Protect), MFA (Users/Protect), regular backups (Data/Recover).
Seven of eight controls are Protect column controls. One is Recover. None are explicitly Detect or Respond. The Essential Eight is a prevention-focused framework, well-calibrated for its original purpose (reducing the most common attack vectors against Australian government agencies) and limited for organizations that need a comprehensive program view.
The ACSC publishes the Essential Eight Maturity Model with four levels (0-3). Australian organizations that have maturity-assessed themselves against the Essential Eight have often done so without examining whether the Detect and Respond columns have any coverage at all. The CDM makes that gap explicit: a Maturity Level 3 Essential Eight organization can still have empty Detect and Respond cells.
APRA CPS 234 is broader than the Essential Eight and explicitly requires detection capability and incident response. CPS 234’s “information security testing” requirement, which mandates annual testing of controls by suitably qualified personnel, maps to the assessment framework in Article 8.
The Australian context
Australian enterprises in financial services and critical infrastructure have a relatively mature security baseline by regional standards. APRA CPS 234 compliance has driven investment in governance, risk, and the Protect column. The talent market is English-language and internationally connected, supporting access to security tooling and expertise that’s harder to source in some other APJ markets.
The specific challenge for Australian organizations is geographic: distributed operations across large distances, reliance on offshore managed services for some security functions, and a significant proportion of enterprises in sectors (mining, agriculture, energy) that combine IT and OT in ways that the CDM’s standard asset classes don’t fully capture. The OT extension to the CDM (using Devices and Networks rows to model OT infrastructure separately from IT infrastructure) is particularly relevant for the Australian resources and energy sectors.
South Korea
The regulatory layer
South Korea has a distinctive regulatory structure: the Information and Communications Network Act (정보통신망법) and the Personal Information Protection Act (개인정보 보호법, PIPA) are the primary frameworks for most enterprises. Financial institutions operate under additional FSC/FSS (Financial Services Commission / Financial Supervisory Service) guidance.
The Korea Internet & Security Agency (KISA) maintains the ISMS-P (Information Security Management System - Personal Information) certification, which is mandatory for certain categories of companies by law (ISPs, hospitals above certain size thresholds, companies handling significant personal data volumes). ISMS-P is a comprehensive certification covering governance, risk management, and technical controls.
CDM application in South Korea
Korean enterprises, particularly in technology and financial services, tend to have higher security maturity in the Devices and Networks rows than in Data and Users rows. This reflects both the regulatory emphasis on personal data protection (which drives Data/Protect investment) and the historically strong IT infrastructure capability in Korean enterprises.
The chaebol structure of major Korean enterprises creates a specific CDM challenge: large conglomerates with diverse subsidiaries across different industries maintain varying security maturity across the group. A holding company security team covering automotive, financial services, and consumer electronics subsidiaries is managing three different CDM maps with different regulatory requirements, different threat profiles, and different operational constraints.
ISMS-P certification requirements map to CDM cells in a pattern similar to FISC: strong coverage in Identify and Protect, less prescriptive on Detect and Respond. The CDM gap analysis for ISMS-P certified organizations reliably surfaces detection and response maturity as the area most requiring attention.
APJ-wide observations
A few patterns that hold across the region:
Detect and Respond maturity consistently lags Identify and Protect. This is a global pattern, but it’s more pronounced in APJ than in North America or Europe, partly because regulatory frameworks in the region have historically emphasized preventive controls and partly because the analyst talent market is tighter. The CDM makes this visible in a way that enables a specific conversation with leadership: we are spending most of our security budget on the left side of the matrix and very little on the right side, and here is what that means for our ability to detect and respond to an incident.
Managed security services are more prevalent than in-house SOC capability. For mid-market organizations across APJ, MSSPs provide a significant portion of Detect and Respond capability. The quality of that capability varies considerably. Using the CDM to evaluate MSSP contracts is straightforward: what cells does the service cover, what’s the People/Tech ratio the MSSP provides in those cells, and what are the handoff procedures when the MSSP hands an incident back to your team?
Supply chain and third-party risk is acutely relevant. APJ supply chains for technology products, industrial equipment, and software are complex and internationally distributed. The vendor asset ring from Article 2 is particularly important in APJ contexts. The SolarWinds and similar supply chain incidents have elevated this on regulatory agendas: MAS, FSA, and APRA have all strengthened supply chain security requirements in recent regulatory updates.
The CDM is most useful in this region as a common language. In environments where security conversations happen across organizational silos with different vocabulary, where regulatory requirements use different terminology than vendor products, and where security decisions need to be communicated to both technical teams and executive leadership, the CDM’s simple 5x5 structure provides a shared reference point that cuts across these divides.
That’s not a small thing. A significant portion of security program failure in APJ enterprises comes not from technical gaps but from communication failures: between security and IT, between security and the business, between the CISO and the board. The CDM doesn’t fix organizational communication problems, but it gives people a picture to point at.
Next: Companion Piece — CDM and Post-Quantum Cryptography: Where Cryptographic Risk Lives in the Matrix