ISMAP (Japan)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
ISMAP Assessment + International Coordination
ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation including BSI Japan + Bureau Veritas Japan + DNV Japan + JIPDEC + JQA Japan Quality Assurance + Kymeta + LRQA + SGS Japan + TUV Rheinland Japan + UL Japan + and others approved by Programme Office. Assessment covers all ISMAP controls + Cloud Service Provider Information Security Management System (CSP ISMS) + cloud-specific controls + customer-facing documentation + technical infrastructure + personnel + processes. Report submitted to Programme Office + CSL listing maintained + remediation tracking + scope changes documented. (2) Annual Review and Continuous Improvement: annual review of ISMAP compliance + risk reassessment + control
- External ISMAP-approved auditor + annual + assessment + records + report + CSL
- Annual review + continuous improvement + records + roadmap + benchmarking
- Customer information + transparency + documentation + records + assurance materials
- International coordination + FedRAMP + IRAP + G-Cloud + MTCS + records + reciprocity
- Japanese regulatory + PIPA + My Number + Digital Agency + records + audit + compliance
- ISMAP-approved auditor not engaged (or unqualified)
- Annual review pro forma (no real improvement)
- Customer transparency limited (assurance materials gated)
- International coordination absent (Japan-only view)
- Japanese regulatory fragmented (PIPA + ISMAP treated separately)
ISMAP Cloud Governance
ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Information Security Management System Accreditation Center Japan certification + plus ISMAP-specific extensions for cloud. ISMS scope must cover all ISMAP-relevant services + assets + processes. (2) Cloud Security Policy and Strategy: documented cloud-specific security policy approved by senior management + reviewed annually + cascaded to all relevant personnel + covering cloud-specific risks (shared responsibility + multi-tenancy + virtualisation + API + data residency + hyperscaler vs private cloud + hybrid). (3) Cloud Risk Assessment: risk-based approach per ISO/IEC 27005 + JIS Q 27005 + considering cloud-specific threats (insider t
- ISMS certification + ISO 27001:2022 + ISMS-AC + ISMAP extensions + records
- Cloud security policy + senior management approval + annual review + records
- Cloud risk assessment + ISO 27005 + risk register + treatment + heat map + records
- Shared responsibility matrix + RACI + per service type + customer documentation + records
- Regulatory compliance mapping + PIPA + My Number + sector-specific + records + audit
- ISMS certification but no ISMAP-specific extensions
- Cloud security policy generic (no cloud-specific provisions)
- Risk assessment qualitative only (no quantitative or treatment plan)
- Shared responsibility not documented (customer confusion)
- Regulatory mapping fragmented (PIPA + ISMAP treated separately)
ISMAP Cloud Infrastructure
ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linkerd) + east-west traffic inspection + zero trust network access (ZTNA) + identity-aware proxies + private endpoints (AWS PrivateLink + Azure Private Link + GCP Private Service Connect) + no public IP for sensitive workloads + bastion hosts + jump hosts + VPN/Direct Connect for hybrid + Cloud Network Architecture per JIS X 5051. (2) Container Security: Kubernetes hardening per CIS Kubernetes Benchmark + Pod Security Standards + RBAC + Network Policies + admission controllers (OPA Gatekeeper + Kyverno) + container image scanning (Twistlock + Aqua + Snyk + Anchore) + signed images (Cosign + Notary + Sigstore) + Software Bill of Material
- VPC segmentation + private endpoints + ZTNA + microsegmentation + records
- Container security + CIS K8s + Pod Security + image scanning + SBOM + signed images + records
- Serverless security + FaaS IAM + dependency scanning + monitoring + records
- CWPP + EDR + behavioural analytics + threat hunting + records + alerting
- IaC + CSPM + drift detection + automated remediation + continuous compliance + records
- Flat network architecture (no microsegmentation)
- Containers run as root (no Pod Security or signed images)
- Serverless functions over-privileged (broad IAM roles)
- CWPP absent (no behavioural detection)
- Infrastructure changes outside IaC (configuration drift)
ISMAP Cloud Operations
ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Sumo Logic + Elastic Security + LogRhythm + Chronicle Security) + UEBA User and Entity Behaviour Analytics + SOAR Security Orchestration Automation and Response + log centralisation + log retention per ISMAP (typically 1 year minimum + 7 years for ISMAP-Critical) + tamper-evident + WORM storage + clock synchronisation (NTP) + Cloud-native logging (AWS CloudTrail + Azure Monitor + GCP Cloud Logging) + cross-cloud aggregation + alerting + dashboards + Cloud Security Posture Management (CSPM) + Cloud Detection and Response (CDR). (2) Incident Response in Cloud: documented incident response plan + IR team + IR phases (Preparation + Identi
- 24x7 SOC + SIEM + UEBA + SOAR + log centralisation + retention + records + WORM
- IR plan + phases + playbooks + forensic readiness + chain of custody + drills + records
- NISC + JPCERT + PIPC reporting + 24-hour + records + per-incident
- Vulnerability management + CVE + JVN + IPA + CISA KEV + patch + records
- Penetration testing + annual + ISMAP auditor + scope + report + retest + records
- SOC business-hours only (no 24x7 coverage)
- IR plan paper-only (no drills or playbooks)
- NISC reporting unaware (24-hour missed)
- Vulnerability management ad-hoc (no JVN/IPA monitoring)
- Penetration testing tick-box (no remediation tracking)
ISMAP Data Protection
ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) Strictly Confidential + (e) Top Secret per Cabinet Office classification + plus Personal Information per PIPA + My Number Special Personal Information + Specially Designated Secret per Special Secrets Protection Act. Labelling + handling per classification + access controls per classification. (2) Encryption At Rest: AES-256 minimum + AES-128 acceptable for non-sensitive + FIPS 140-3 validated cryptographic modules (or FIPS 140-2 transitioning) + CRYPTREC (Cryptography Research and Evaluation Committee) Japanese government approved algorithms list + JIS X 19768 + key management per ISO 11770 + HSM Hardware Security Module (FIPS 140-3
- Data classification + Japanese gov scheme + PIPA + My Number + records + labels
- Encryption at rest + AES-256 + FIPS 140-3 + CRYPTREC + HSM + key mgmt + records
- Encryption in transit + TLS 1.3 + CRYPTREC ciphers + PFS + mTLS + records + audit
- Data residency Japan + ISMAP-Critical compliance + records + region verification
- Backup 3-2-1 + immutable + tested restore + secure deletion + records + COD
- Data classification absent (treating all data uniformly)
- Encryption modules not FIPS 140-3 validated (commercial libraries)
- TLS 1.2 or weaker ciphers (no CRYPTREC alignment)
- ISMAP-Critical workload processed outside Japan (compliance violation)
- Backups not immutable (vulnerable to ransomware)
ISMAP Identity + Access
ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities. (1) Cloud Identity Management: centralised identity directory (LDAP + Active Directory + Azure AD + AWS IAM + Google Cloud IAM + Okta + Auth0) + identity lifecycle management (provisioning + role change + termination + just-in-time access) + identity governance + access reviews + access certifications + identity analytics + dormant account detection + orphan account cleanup + RBAC role-based access control + ABAC attribute-based access control + minimum 90-day password rotation for privileged accounts + password complexity per NIST SP 800-63B + JIS X 5051. (2) Multi-Factor Authentication (MFA): MANDATORY for all administrative access + privileged access + customer-facing portals + remote access + based on something-you-have (hardware token + s
- Cloud IAM + identity lifecycle + access reviews + RBAC + records + analytics
- MFA mandatory + FIDO2 + My Number Card + records + per-user + per-action
- PAM + JIT + session recording + credential vault + zero standing + records
- Federation SSO + SAML/OAuth/OIDC + government IdP + records + audit
- API security + OAuth 2.0 + JWT/PASETO + mTLS + token lifecycle + records
- IAM federated to government IdP but no ABAC/RBAC tied to JD Agency role
- MFA optional or password+SMS only (not phishing-resistant)
- PAM ad-hoc (no JIT or zero standing)
- Federation only with single IdP (no government IdP backup)
- API tokens long-lived (no rotation or scope restriction)
ISMAP Personnel + Resilience + Supply Chain
ISMAP Personnel + Resilience + Supply Chain controls extend security beyond own perimeter. (1) Personnel Security and Background Checks: per ISMAP requirements + tiered background checks for personnel with access to customer data + (a) Standard CSP employees - identity verification + employment history + reference check + credit check for financial roles; (b) Privileged personnel (administrators + developers with customer data access) - enhanced background check + criminal records check + foreign contacts disclosure + 5-year reinvestigation; (c) ISMAP-Critical tier personnel - Japanese national security check + critical infrastructure background + may require Japanese citizenship; (d) Foreign nationals - separate approval process + monitoring + restricted access + Japanese government clearance for ISMAP-Critical. Personnel training + Non-Disclosure Agreement (NDA) + security awareness an
- Personnel background checks + tiered + ISMAP-Critical Japanese + records + 5-year refresh
- BCP/DR + ISO 22301 + multi-region + seismic + DR drills + RTO/RPO + records + tabletop
- Supply chain SCRM + ISO 28000 + supplier tiering + audit + SBOM + records
- Subcontractor flow-down + ISMAP equivalent + audit rights + customer notice + records
- CII + Japanese sovereignty + foreign govt protection + records + repatriation plan
- Background checks generic (no tiered approach for privileged)
- BCP DR in same earthquake zone (Japan-specific seismic risk)
- Supply chain SCRM at supplier qualification only (no ongoing)
- Subcontractor flow-down absent (no ISMAP equivalent imposed)
- Foreign government access risk unmitigated (CLOUD Act exposure)
ISMAP Scope + 2020 Launch + Tri-Ministry Governance
Information system Security Management and Assessment Program (ISMAP) Japan - the Japanese government cloud security assessment program launched June 2020 (formal operations began 1 January 2021) + replaces older Common Cloud Procurement Guidelines + similar in concept to US FedRAMP + UK G-Cloud + Australia IRAP. Joint operation by Tri-Ministry governance structure: (1) Ministry of Internal Affairs and Communications (MIC / Soumu-sho) - administrative coordination + government information systems policy; (2) Ministry of Economy Trade and Industry (METI / Keizai Sangyo-sho) - cybersecurity industry policy + standardisation + international cooperation; (3) Cabinet Cybersecurity Center National center of Incident readiness and Strategy for Cybersecurity (NISC / Naikaku Saiba Sekyuriti Senta) - national cybersecurity strategy + incident response coordination. ISMAP Programme Office is operat
- ISMAP CSL registration + tier + scope + records + government client list
- Tri-Ministry engagement + MIC + METI + NISC + records + correspondence
- Tier mapping + LIU/Standard/Critical + data classification + records + per workload
- Annual ISMAP assessment + maintenance + records + audit report + CSL listing
- Government procurement compliance + records + ATO-equivalent + per-agency contracts
- Not registered on ISMAP CSL (cannot serve Japanese government)
- Tri-Ministry coordination weak (only one Ministry engaged)
- Tier mismatch (LIU registered but Standard data processed)
- Annual assessment lapsed (CSL listing expired)
- Procuring agency unaware of ISMAP requirement (compliance gap)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISMAP (Japan) framework page.