Skip to content

Evidence request lists

Japan FSA Cybersecurity Guidelines for Financial Institutions

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

JP FSA Cyber BCM + Resilience

JP-FSA-CYB-Business-Continuity-Cyber-Resilience-RTO-RPO-Backup-Immutable-Air-Gapped-Disaster-Recovery-Ransomware-Resistance
Japan FSA Cybersecurity Business Continuity + Cyber Resilience + RTO + RPO + Backup + Immutable + Air-Gapped + Disaster Recovery + Ransomware Resistance + Operational Resilience + Critical Function Mapping + FSA Operational Resilience Framework

Business Continuity + Cyber Resilience is core per FSA Cybersecurity Guidelines + intersects with FSA Operational Resilience Framework (2023) + BCBS Principles for Operational Resilience (March 2021) + CPMI-IOSCO Guidance on Cyber Resilience for FMIs. (1) Business Impact Analysis (BIA): (a) Critical Functions identification - customer payment + trading + market data + customer service + AML; (b) Recovery Time Objective (RTO) per critical function; (c) Recovery Point Objective (RPO) per critical data; (d) Maximum Tolerable Period of Disruption (MTPD); (e) Resource Requirements; (f) Dependencies (internal + external); (g) Periodic review + after material change. (2) Business Continuity Plan (BCP): (a) Comprehensive BCP covering disruption types; (b) Crisis Management Team; (c) Communications Plan + stakeholders; (d) Alternative work arrangements; (e) Site failover; (f) Critical Function co

Artefacts an auditor will ask for
  • BIA + critical functions + records + annual + after material change
  • RTO/RPO + Board approved + records + tested + per function + per data class
  • Immutable + air-gapped + records + per backup class + ransomware-resistant
  • DR drills + quarterly + annual full + records + lessons learned
  • FSA Operational Resilience + Important Business Service + impact tolerance + records
Where this commonly fails
  • BIA stale (no annual review)
  • RTO/RPO aspirational (not tested)
  • Backups not immutable or air-gapped (ransomware vulnerable)
  • DR drills partial only (full failover untested)
  • Operational Resilience Framework not adopted (siloed BCM)

JP FSA Cyber Exercises + Drills

JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector
Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range

Cybersecurity exercises + drills are mandated per FSA Cybersecurity Guidelines for Tier 2/3 institutions + coordinated industry-wide via Delta Wall + FISC. (1) Institutional Tabletop Exercises: (a) Annual minimum per FSA expectation; (b) Quarterly for Tier 3 + critical infrastructure; (c) Cross-functional - technical + business + legal + comms + executive + Board; (d) Realistic scenarios with current threat landscape; (e) Decision-making under pressure + ambiguity; (f) After Action Review + improvement actions tracked; (g) Annual Board observation. (2) Scenario Diversity: (a) Ransomware - encryption + extortion + double/triple extortion; (b) Wire Transfer Fraud - BEC + insider + APT; (c) Customer Account Takeover; (d) DDoS attack on customer-facing; (e) Insider Threat - malicious + negligent; (f) Supply Chain Attack (SolarWinds-style); (g) Critical Service Provider Outage; (h) ATM/Card N

Artefacts an auditor will ask for
  • Annual tabletop + cross-functional + records + per exercise + AAR
  • Delta Wall + FSA + records + per year + sector lessons learned
  • Cyber range + Tier 3 + records + per exercise + Red/Blue/Purple
  • Scenario diversity + records + per year + threat coverage matrix
  • Improvement actions + tracked + records + per quarter + completion rate
Where this commonly fails
  • Tabletop infrequent (every 2-3 years rather than annual)
  • Delta Wall participation perfunctory
  • Cyber range absent or shared with limited use
  • Scenario diversity limited (same scenarios repeated)
  • Improvement actions un-tracked (lessons unlearned)

JP FSA Cyber IAM + Customer Auth

JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication
Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security

Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control. (1) Workforce IAM: (a) Identity Lifecycle Management - joiner-mover-leaver process; (b) Single Sign-On (SSO) + SAML 2.0 + OIDC; (c) Multi-Factor Authentication (MFA) mandatory for all + especially privileged; (d) Role-Based Access Control (RBAC) + Attribute-Based (ABAC); (e) Least Privilege + Need-to-Know; (f) Quarterly Access Recertification; (g) Segregation of Duties; (h) Identity Federation across multi-cloud + hybrid. (2) Privileged Access Management (PAM): (a) Privileged Account Inventory; (b) Vault + Secret Management; (c) Just-In-Time (JIT) provisioning replacing standing privileges; (d) Session Recording + Monitoring; (e) Break-Glass procedures; (f) Privileged Session Ma

Artefacts an auditor will ask for
  • MFA + all users + records + per user + per system + audit trail
  • PAM + JIT + session recording + records + per privileged session + audit
  • Zero Trust + continuous verification + records + per session + microsegmentation
  • Banking customer auth + risk-based + records + per transaction + step-up
  • APP fraud controls + records + per detection + customer protection + recovery
Where this commonly fails
  • MFA inconsistent (legacy systems excepted)
  • PAM standing privileges (no JIT)
  • Zero Trust marketing rather than implementation
  • Customer authentication single-factor for transactions
  • APP fraud controls reactive (no real-time detection)

JP FSA Cyber Incident Response

JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT
Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned

Incident Response capability is critical per FSA Cybersecurity Guidelines. (1) Incident Response Plan: (a) Documented IR Plan + per FFIEC IT Examination Handbook reference; (b) ISO/IEC 27035 Information Security Incident Management; (c) NIST SP 800-61 Computer Security Incident Handling Guide; (d) Sector-specific - FISC + JFSA reference; (e) Annual review + update; (f) Board approval; (g) Plan accessible to CSIRT + SOC + Senior Management. (2) Incident Classification + Severity: (a) Severity 1 (Critical) - widespread outage + significant customer impact + sensitive data breach; (b) Severity 2 (High) - localised outage + limited customer impact; (c) Severity 3 (Medium) - operational disruption + no customer impact; (d) Severity 4 (Low) - minor issue + procedural; (e) Per-Severity response procedures + escalation. (3) CSIRT Computer Security Incident Response Team: (a) Dedicated CSIRT - Ti

Artefacts an auditor will ask for
  • IR Plan + documented + Board approved + records + annual review + scenarios
  • CSIRT + 24x7 + records + per incident + roles + handover
  • Tabletop exercises + annual + records + per scenario + after action review
  • FSA notification + Article 52-2 + records + per incident + initial + detailed
  • Post-incident + RCA + lessons learned + records + per incident + improvement actions
Where this commonly fails
  • IR Plan outdated (no annual review)
  • CSIRT business-hours coverage only
  • Tabletop infrequent (every 2-3 years)
  • FSA notification delayed (>30 days)
  • Lessons learned siloed (no industry sharing)

JP FSA Cyber Maturity Self-Assessment

JP-FSA-CYB-Cybersecurity-Maturity-Self-Assessment-Tool-Annual-Submission-Risk-Tier-Based-Tier1-Tier2-Tier3
Japan FSA Cybersecurity Maturity Self-Assessment Tool + Annual Submission + Risk-Tier-Based + Tier 1 Foundational + Tier 2 Enhanced + Tier 3 Advanced + FSA Inspection + Plan-Do-Check-Act + Continuous Improvement + Industry Benchmarking

The FSA Cybersecurity Maturity Self-Assessment Tool (Saiba Sekyuritii Jiko Hyouka Tool サイバーセキュリティ自己評価ツール) is the centrepiece annual assessment requirement for Japanese financial institutions + first introduced 2017 + significantly enhanced 2022 + sector-specific versions 2024. (1) Self-Assessment Structure: (a) ~150 cybersecurity controls across 6 domains - Governance + Risk Management + Asset Management + Detection + Response + Recovery; (b) Per-Control Maturity Rating (1-5 scale or NIST-style); (c) Evidence requirement per control; (d) Self-Assessment workbook submitted to FSA annually; (e) FSA peer benchmarking + sector-aggregate analysis returned to participating institutions. (2) Maturity Tier Framework: (a) Tier 1 (Basic / Foundational) - all financial institutions including small regional banks + small insurers + small securities firms - basic NIST CSF Identify + Protect + Detect;

Artefacts an auditor will ask for
  • Annual self-assessment + FSA submission + records + per year + audit trail
  • Maturity tier + Tier 1/2/3 + records + per institution + progression
  • Evidence per control + workbook + records + audit-ready + documents/screenshots/logs
  • Gap remediation + tracking + records + per quarter + lessons learned
  • Internal audit verification + Three Lines + records + annual + independent
Where this commonly fails
  • Self-assessment perfunctory or aspirational (no evidence backing)
  • Maturity tier misclassified (under-tiered to avoid scrutiny)
  • Evidence weak or generic
  • Gap remediation not tracked (annual cycle broken)
  • Internal audit not verifying self-assessment

JP FSA Cyber Regulatory Reporting

JP-FSA-CYB-Incident-Notification-FSA-30-Days-Customer-Disclosure-Banking-Act-Article-52-2-Securities-Article-19-Insurance-Article-100-2
Japan FSA Cyber Incident Notification + 30-Day SLA + Customer Disclosure + Banking Act Article 52-2 + Securities Article 19 + Insurance Article 100-2 + APPI Article 26 Breach + Material Incident Definition + Public Disclosure

Regulatory cyber incident notification is mandated by multiple sectoral statutes + FSA Inspection Manual + APPI. (1) Statutory Notification Obligations: (a) Banking Act Article 52-2 + Banking Industry Cybersecurity Notification Order; (b) Insurance Business Act Article 100-2 + Insurance Industry Cybersecurity Notification Order; (c) Financial Instruments and Exchange Act Article 19 + Securities Industry Notification Order; (d) FSA Inspection Manual + Supervisory Guidelines per sector; (e) APPI Article 26 personal data breach notification to PIPC. (2) Material Incident Definition: (a) Customer Impact - service disruption + data breach + financial loss; (b) Operational Impact - significant outage > 4 hours + business critical system; (c) Data Breach - personal information of significant number of customers; (d) Ransomware Detected or Successful; (e) Wire Transfer Fraud + Significant Financ

Artefacts an auditor will ask for
  • Statutory notification + documented + records + per sector + per Article
  • 30-day SLA + FSA + records + per incident + initial + detailed + closure
  • APPI Article 26 + PIPC + records + per personal data incident + 30-day
  • Customer notification + plain language + records + per affected + recommended actions
  • Cross-jurisdictional + SEC/GDPR/UK + records + counsel + coordinated timing
Where this commonly fails
  • Statutory notification process informal (no per-Article procedure)
  • 30-day SLA frequently exceeded
  • APPI Article 26 dimension overlooked
  • Customer notification template + dense legal
  • Cross-jurisdictional uncoordinated (regulatory whipsaw risk)

JP FSA Cyber Risk Management

JP-FSA-CYB-Risk-Management-NIST-CSF-FFIEC-Aligned-Identify-Protect-Detect-Respond-Recover-Govern-Plan-Do-Check-Act
Japan FSA Cybersecurity Risk Management Framework + NIST CSF 2.0 Aligned + FFIEC Crosswalk + Identify Protect Detect Respond Recover Govern + ISO 27001 ISMS + Plan-Do-Check-Act + Inherent vs Residual Risk + Risk Appetite + Cyber Risk in ERM

The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM). (1) NIST CSF 2.0 Alignment - 6 Functions: (a) GOVERN (added in 2.0) - cybersecurity governance + risk management + organizational context + policy; (b) IDENTIFY - asset management + business environment + risk assessment + risk management strategy; (c) PROTECT - identity management + awareness + data security + protective technology; (d) DETECT - anomalies + continuous monitoring + detection processes; (e) RESPOND - response planning + communications + analysis + mitigation; (f) RECOVER - recovery planning + improvements + communications. (2) ISO/IEC 27001 ISMS Integration: (a) Information Security Management System scope including cybersecurity; (b)

Artefacts an auditor will ask for
  • NIST CSF 2.0 + 6 functions + records + per function + maturity scoring
  • Risk Appetite + Board + records + annual + KRIs + limit breach escalation
  • Risk assessment + inherent + residual + records + per asset + threat modelling
  • Treatment decisions + records + per risk + documented + reviewed
  • ERM integration + cyber principal + records + Board dashboard + ICAAP where applicable
Where this commonly fails
  • NIST CSF 2.0 not mapped (older framework only)
  • Risk Appetite absent or not cyber-specific
  • Risk assessment compliance-driven (no real threat modelling)
  • Treatment decisions implicit (no formal documentation)
  • ERM integration absent (cyber siloed)

JP FSA Cyber SOC + Detection

JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage
Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA

Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling; (b) Hybrid SOC - internal + MSSP Managed Security Service Provider; (c) Outsourced SOC - MSSP managed; (d) MDR Managed Detection and Response - emerging; (e) XDR Extended Detection and Response platforms; (f) Cloud SOC integration; (g) Follow-the-Sun for 24x7 coverage; (h) SOC analyst tiers - L1 triage + L2 investigation + L3 threat hunting + L4 incident response. (2) SIEM Security Information and Event Management: (a) Log aggregation + normalisation + correlation; (b) Major SIEM vendors - Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security + Exabeam + Sumo Logic; (c) Cloud-native SIEM - AWS Security Hub + Google Chronicle + Azure Sentinel; (d) Use Case Library + Detection

Artefacts an auditor will ask for
  • 24x7 SOC + records + per shift + Tier 2/3 + handover + escalation
  • SIEM + log coverage + records + per source + retention 1-7 years + use cases
  • EDR + 100% endpoints + records + per quarter + behavioural detection
  • MITRE ATT and CK + detection coverage + records + per tactic + per technique
  • Threat hunting + Tier 3 + records + per hunt + findings + lessons learned
Where this commonly fails
  • SOC business-hours only (8x5 not 24x7)
  • SIEM log gaps (critical systems not ingested)
  • EDR partial coverage (legacy + servers excepted)
  • MITRE ATT and CK coverage unknown
  • Threat hunting absent or ad-hoc

JP FSA Cyber Scope + Governance

JP-FSA-CYB-Scope-Guidelines-Cyber-Security-Financial-Institutions-2015-2019-2022-2024-Banking-Insurance-Securities-FISC
Japan FSA Cybersecurity Guidelines Scope + Cyber Security Reinforcement at Financial Institutions + 2015 + 2019 + 2022 + 2024 Updates + Banking + Insurance + Securities + Funds + Sector-Specific + FISC Coordination + Board and Senior Management Oversight + Three Lines of Defense

The Japan Financial Services Agency (FSA 金融庁) Cybersecurity Guidelines (Saiba Sekyuritii ni kansuru Gaidorain サイバーセキュリティに関するガイドライン) are the foundational cybersecurity regulatory framework for Japanese financial institutions + first issued July 2015 + revised 2019 + 2022 + sector-specific revisions 2024. (1) Issuing Body: Japan Financial Services Agency (FSA) Supervisory Coordination Division + Securities and Exchange Surveillance Commission (SESC) + IT Division. (2) Statutory Authority: (a) Banking Act Article 52-2 + Insurance Business Act Article 100-2 + Financial Instruments and Exchange Act Article 19; (b) Cybersecurity Basic Act 2014 (Saiba Sekyuritii Kihon Hou サイバーセキュリティ基本法); (c) NISC National Center of Incident Readiness and Strategy for Cybersecurity coordination; (d) FSA Inspection Manual sector-specific cybersecurity provisions. (3) Scope Coverage: applies to (a) Banks - city ba

Artefacts an auditor will ask for
  • Cybersecurity Strategy + Board approved + records + per quarter + Tone-at-Top + signed
  • CISO + Board access + records + quarterly reporting + escalation criteria
  • Maturity tier self-assessment + Tier 1/2/3 + records + annual + FSA submission
  • FISC coordination + industry drills + Delta Wall + records + per engagement
  • Sector-specific + Banking Article 52-2 / Insurance Article 100-2 / Securities Article 19 + records
Where this commonly fails
  • Cybersecurity Strategy not Board-approved (delegated only)
  • CISO without Board access or quarterly reporting
  • Maturity tier self-assessment not submitted or perfunctory
  • FISC industry drills not participated
  • Sector-specific application unclear (treated as generic)

JP FSA Cyber Third Party + Cloud

JP-FSA-CYB-Third-Party-Outsourcing-Cyber-Risk-Cloud-Service-Provider-Due-Diligence-Audit-Right-Sub-Processor-Visibility-Concentration-Risk
Japan FSA Cybersecurity Third Party + Outsourcing Cyber Risk + Cloud Service Provider Due Diligence + Audit Right + Sub-Processor Visibility + Concentration Risk + Data Sovereignty + ISMAP Certification + FISC Cloud Guidelines

Third-Party + Outsourcing + Cloud Service Provider cybersecurity is critical per FSA Cybersecurity Guidelines + FISC Cloud Guidelines (FISC Anzen Taisaku Kijun - Cloud Computing Edition). (1) Outsourcing Governance: (a) Outsourcing Policy + Board Approval; (b) Per-Engagement Risk Assessment; (c) Critical vs Non-Critical Classification; (d) Due Diligence proportionate to risk; (e) Contractual obligations + KPIs; (f) Ongoing Monitoring; (g) Periodic Reassessment; (h) Termination + Transition planning. (2) Cloud Service Provider (CSP) Due Diligence: (a) AWS + Microsoft Azure + Google Cloud + Oracle + IBM Cloud + domestic (NTT Cloud + Fujitsu + NEC); (b) Financial Stability + Track Record; (c) Compliance Certifications - ISO 27001 + 27017 + 27018 + 27701 + SOC 2 + ISMAP + FedRAMP equivalent; (d) Data Residency - Japan-only + Asia-Pacific + Global; (e) Encryption + Customer-Managed Keys (CMK)

Artefacts an auditor will ask for
  • Outsourcing governance + per engagement + records + per vendor + critical/non-critical
  • Cloud provider DD + ISMAP + records + per CSP + certifications + audit
  • Audit right + exercised + records + per annual + onsite or remote
  • Concentration risk + multi-cloud strategy + records + per critical + exit plan
  • Sub-processor visibility + chain + records + per sub + disclosure + approval
Where this commonly fails
  • Outsourcing governance generic (no per-engagement assessment)
  • Cloud DD accepts vendor certifications (no audit)
  • Audit right contractual but never exercised
  • Concentration risk unmonitored (single CSP dependency)
  • Sub-processor chain opaque (visibility gaps)

JP FSA Cyber Vulnerability Mgmt

JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team
Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response

Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing; (c) SAST Static Application Security Testing; (d) IAST Interactive Application Security Testing; (e) SCA Software Composition Analysis - open source dependencies; (f) Container + Cloud Vulnerability Scanning; (g) Network configuration assessment; (h) Continuous + on-demand. (2) Vulnerability Intelligence: (a) National Vulnerability Database (NVD); (b) Japan Vulnerability Notes (JVN) JPCERT/CC; (c) JVN iPedia comprehensive database; (d) Vendor Security Advisories; (e) Threat intelligence integration; (f) Zero-Day intelligence; (g) Exploit availability monitoring (Metasploit + Exploit-DB). (3) Risk-Based Prioritisation: (a) CVSS v3.1 / v

Artefacts an auditor will ask for
  • Vulnerability scanning + continuous + records + per asset + per cycle + risk score
  • Patching SLA + per severity + records + audit + dashboard + Board reporting
  • Pen testing + annual + records + per scope + findings + remediation
  • Red-Team + Tier 3 + records + per annual + Purple Team + scenarios
  • SBOM + open source + records + per application + license + vulnerability
Where this commonly fails
  • Vulnerability scanning annual only (no continuous)
  • Patching SLA missed (critical >7 days)
  • Pen testing checkbox (no real attack simulation)
  • Red-Team absent for Tier 3
  • SBOM not maintained (Log4j-style surprise risk)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Japan FSA Cybersecurity Guidelines for Financial Institutions framework page.