Skip to content

Evidence request lists

ISMAP (Japan)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

ISMAP Assessment + International Coordination

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017
ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency

ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation including BSI Japan + Bureau Veritas Japan + DNV Japan + JIPDEC + JQA Japan Quality Assurance + Kymeta + LRQA + SGS Japan + TUV Rheinland Japan + UL Japan + and others approved by Programme Office. Assessment covers all ISMAP controls + Cloud Service Provider Information Security Management System (CSP ISMS) + cloud-specific controls + customer-facing documentation + technical infrastructure + personnel + processes. Report submitted to Programme Office + CSL listing maintained + remediation tracking + scope changes documented. (2) Annual Review and Continuous Improvement: annual review of ISMAP compliance + risk reassessment + control

Artefacts an auditor will ask for
  • External ISMAP-approved auditor + annual + assessment + records + report + CSL
  • Annual review + continuous improvement + records + roadmap + benchmarking
  • Customer information + transparency + documentation + records + assurance materials
  • International coordination + FedRAMP + IRAP + G-Cloud + MTCS + records + reciprocity
  • Japanese regulatory + PIPA + My Number + Digital Agency + records + audit + compliance
Where this commonly fails
  • ISMAP-approved auditor not engaged (or unqualified)
  • Annual review pro forma (no real improvement)
  • Customer transparency limited (assurance materials gated)
  • International coordination absent (Japan-only view)
  • Japanese regulatory fragmented (PIPA + ISMAP treated separately)

ISMAP Cloud Governance

ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities
ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities

ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Information Security Management System Accreditation Center Japan certification + plus ISMAP-specific extensions for cloud. ISMS scope must cover all ISMAP-relevant services + assets + processes. (2) Cloud Security Policy and Strategy: documented cloud-specific security policy approved by senior management + reviewed annually + cascaded to all relevant personnel + covering cloud-specific risks (shared responsibility + multi-tenancy + virtualisation + API + data residency + hyperscaler vs private cloud + hybrid). (3) Cloud Risk Assessment: risk-based approach per ISO/IEC 27005 + JIS Q 27005 + considering cloud-specific threats (insider t

Artefacts an auditor will ask for
  • ISMS certification + ISO 27001:2022 + ISMS-AC + ISMAP extensions + records
  • Cloud security policy + senior management approval + annual review + records
  • Cloud risk assessment + ISO 27005 + risk register + treatment + heat map + records
  • Shared responsibility matrix + RACI + per service type + customer documentation + records
  • Regulatory compliance mapping + PIPA + My Number + sector-specific + records + audit
Where this commonly fails
  • ISMS certification but no ISMAP-specific extensions
  • Cloud security policy generic (no cloud-specific provisions)
  • Risk assessment qualitative only (no quantitative or treatment plan)
  • Shared responsibility not documented (customer confusion)
  • Regulatory mapping fragmented (PIPA + ISMAP treated separately)

ISMAP Cloud Infrastructure

ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement
ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linkerd) + east-west traffic inspection + zero trust network access (ZTNA) + identity-aware proxies + private endpoints (AWS PrivateLink + Azure Private Link + GCP Private Service Connect) + no public IP for sensitive workloads + bastion hosts + jump hosts + VPN/Direct Connect for hybrid + Cloud Network Architecture per JIS X 5051. (2) Container Security: Kubernetes hardening per CIS Kubernetes Benchmark + Pod Security Standards + RBAC + Network Policies + admission controllers (OPA Gatekeeper + Kyverno) + container image scanning (Twistlock + Aqua + Snyk + Anchore) + signed images (Cosign + Notary + Sigstore) + Software Bill of Material

Artefacts an auditor will ask for
  • VPC segmentation + private endpoints + ZTNA + microsegmentation + records
  • Container security + CIS K8s + Pod Security + image scanning + SBOM + signed images + records
  • Serverless security + FaaS IAM + dependency scanning + monitoring + records
  • CWPP + EDR + behavioural analytics + threat hunting + records + alerting
  • IaC + CSPM + drift detection + automated remediation + continuous compliance + records
Where this commonly fails
  • Flat network architecture (no microsegmentation)
  • Containers run as root (no Pod Security or signed images)
  • Serverless functions over-privileged (broad IAM roles)
  • CWPP absent (no behavioural detection)
  • Infrastructure changes outside IaC (configuration drift)

ISMAP Cloud Operations

ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA
ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management

ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Sumo Logic + Elastic Security + LogRhythm + Chronicle Security) + UEBA User and Entity Behaviour Analytics + SOAR Security Orchestration Automation and Response + log centralisation + log retention per ISMAP (typically 1 year minimum + 7 years for ISMAP-Critical) + tamper-evident + WORM storage + clock synchronisation (NTP) + Cloud-native logging (AWS CloudTrail + Azure Monitor + GCP Cloud Logging) + cross-cloud aggregation + alerting + dashboards + Cloud Security Posture Management (CSPM) + Cloud Detection and Response (CDR). (2) Incident Response in Cloud: documented incident response plan + IR team + IR phases (Preparation + Identi

Artefacts an auditor will ask for
  • 24x7 SOC + SIEM + UEBA + SOAR + log centralisation + retention + records + WORM
  • IR plan + phases + playbooks + forensic readiness + chain of custody + drills + records
  • NISC + JPCERT + PIPC reporting + 24-hour + records + per-incident
  • Vulnerability management + CVE + JVN + IPA + CISA KEV + patch + records
  • Penetration testing + annual + ISMAP auditor + scope + report + retest + records
Where this commonly fails
  • SOC business-hours only (no 24x7 coverage)
  • IR plan paper-only (no drills or playbooks)
  • NISC reporting unaware (24-hour missed)
  • Vulnerability management ad-hoc (no JVN/IPA monitoring)
  • Penetration testing tick-box (no remediation tracking)

ISMAP Data Protection

ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS
ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM

ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) Strictly Confidential + (e) Top Secret per Cabinet Office classification + plus Personal Information per PIPA + My Number Special Personal Information + Specially Designated Secret per Special Secrets Protection Act. Labelling + handling per classification + access controls per classification. (2) Encryption At Rest: AES-256 minimum + AES-128 acceptable for non-sensitive + FIPS 140-3 validated cryptographic modules (or FIPS 140-2 transitioning) + CRYPTREC (Cryptography Research and Evaluation Committee) Japanese government approved algorithms list + JIS X 19768 + key management per ISO 11770 + HSM Hardware Security Module (FIPS 140-3

Artefacts an auditor will ask for
  • Data classification + Japanese gov scheme + PIPA + My Number + records + labels
  • Encryption at rest + AES-256 + FIPS 140-3 + CRYPTREC + HSM + key mgmt + records
  • Encryption in transit + TLS 1.3 + CRYPTREC ciphers + PFS + mTLS + records + audit
  • Data residency Japan + ISMAP-Critical compliance + records + region verification
  • Backup 3-2-1 + immutable + tested restore + secure deletion + records + COD
Where this commonly fails
  • Data classification absent (treating all data uniformly)
  • Encryption modules not FIPS 140-3 validated (commercial libraries)
  • TLS 1.2 or weaker ciphers (no CRYPTREC alignment)
  • ISMAP-Critical workload processed outside Japan (compliance violation)
  • Backups not immutable (vulnerable to ransomware)

ISMAP Identity + Access

ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO
ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM

ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities. (1) Cloud Identity Management: centralised identity directory (LDAP + Active Directory + Azure AD + AWS IAM + Google Cloud IAM + Okta + Auth0) + identity lifecycle management (provisioning + role change + termination + just-in-time access) + identity governance + access reviews + access certifications + identity analytics + dormant account detection + orphan account cleanup + RBAC role-based access control + ABAC attribute-based access control + minimum 90-day password rotation for privileged accounts + password complexity per NIST SP 800-63B + JIS X 5051. (2) Multi-Factor Authentication (MFA): MANDATORY for all administrative access + privileged access + customer-facing portals + remote access + based on something-you-have (hardware token + s

Artefacts an auditor will ask for
  • Cloud IAM + identity lifecycle + access reviews + RBAC + records + analytics
  • MFA mandatory + FIDO2 + My Number Card + records + per-user + per-action
  • PAM + JIT + session recording + credential vault + zero standing + records
  • Federation SSO + SAML/OAuth/OIDC + government IdP + records + audit
  • API security + OAuth 2.0 + JWT/PASETO + mTLS + token lifecycle + records
Where this commonly fails
  • IAM federated to government IdP but no ABAC/RBAC tied to JD Agency role
  • MFA optional or password+SMS only (not phishing-resistant)
  • PAM ad-hoc (no JIT or zero standing)
  • Federation only with single IdP (no government IdP backup)
  • API tokens long-lived (no rotation or scope restriction)

ISMAP Personnel + Resilience + Supply Chain

ISMAP-Personnel-BackgroundChecks-Resilience-BCP-DR-SupplyChain-ThirdParty-Subcontractor-FlowDown
ISMAP Personnel Security + Background Checks + Business Continuity + Disaster Recovery + Resilience + Supply Chain Risk Management + Third Party + Subcontractor Flow-Down + Japanese Sovereignty

ISMAP Personnel + Resilience + Supply Chain controls extend security beyond own perimeter. (1) Personnel Security and Background Checks: per ISMAP requirements + tiered background checks for personnel with access to customer data + (a) Standard CSP employees - identity verification + employment history + reference check + credit check for financial roles; (b) Privileged personnel (administrators + developers with customer data access) - enhanced background check + criminal records check + foreign contacts disclosure + 5-year reinvestigation; (c) ISMAP-Critical tier personnel - Japanese national security check + critical infrastructure background + may require Japanese citizenship; (d) Foreign nationals - separate approval process + monitoring + restricted access + Japanese government clearance for ISMAP-Critical. Personnel training + Non-Disclosure Agreement (NDA) + security awareness an

Artefacts an auditor will ask for
  • Personnel background checks + tiered + ISMAP-Critical Japanese + records + 5-year refresh
  • BCP/DR + ISO 22301 + multi-region + seismic + DR drills + RTO/RPO + records + tabletop
  • Supply chain SCRM + ISO 28000 + supplier tiering + audit + SBOM + records
  • Subcontractor flow-down + ISMAP equivalent + audit rights + customer notice + records
  • CII + Japanese sovereignty + foreign govt protection + records + repatriation plan
Where this commonly fails
  • Background checks generic (no tiered approach for privileged)
  • BCP DR in same earthquake zone (Japan-specific seismic risk)
  • Supply chain SCRM at supplier qualification only (no ongoing)
  • Subcontractor flow-down absent (no ISMAP equivalent imposed)
  • Foreign government access risk unmitigated (CLOUD Act exposure)

ISMAP Scope + 2020 Launch + Tri-Ministry Governance

ISMAP-Scope-2020Launch-MIC-METI-NISC-ISMAP-LIU-Standard-Critical-Tiers-CloudServiceList-Registration
ISMAP Scope + 2020 Launch + MIC/METI/NISC Tri-Ministry Governance + Cloud Service List + 3 Tiers (LIU + Standard + Critical) + ISMAP-LIU Simplified Assurance + Government Procurement Eligibility

Information system Security Management and Assessment Program (ISMAP) Japan - the Japanese government cloud security assessment program launched June 2020 (formal operations began 1 January 2021) + replaces older Common Cloud Procurement Guidelines + similar in concept to US FedRAMP + UK G-Cloud + Australia IRAP. Joint operation by Tri-Ministry governance structure: (1) Ministry of Internal Affairs and Communications (MIC / Soumu-sho) - administrative coordination + government information systems policy; (2) Ministry of Economy Trade and Industry (METI / Keizai Sangyo-sho) - cybersecurity industry policy + standardisation + international cooperation; (3) Cabinet Cybersecurity Center National center of Incident readiness and Strategy for Cybersecurity (NISC / Naikaku Saiba Sekyuriti Senta) - national cybersecurity strategy + incident response coordination. ISMAP Programme Office is operat

Artefacts an auditor will ask for
  • ISMAP CSL registration + tier + scope + records + government client list
  • Tri-Ministry engagement + MIC + METI + NISC + records + correspondence
  • Tier mapping + LIU/Standard/Critical + data classification + records + per workload
  • Annual ISMAP assessment + maintenance + records + audit report + CSL listing
  • Government procurement compliance + records + ATO-equivalent + per-agency contracts
Where this commonly fails
  • Not registered on ISMAP CSL (cannot serve Japanese government)
  • Tri-Ministry coordination weak (only one Ministry engaged)
  • Tier mismatch (LIU registered but Standard data processed)
  • Annual assessment lapsed (CSL listing expired)
  • Procuring agency unaware of ISMAP requirement (compliance gap)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISMAP (Japan) framework page.