Japan FSA Cybersecurity Guidelines for Financial Institutions
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
JP FSA Cyber BCM + Resilience
Business Continuity + Cyber Resilience is core per FSA Cybersecurity Guidelines + intersects with FSA Operational Resilience Framework (2023) + BCBS Principles for Operational Resilience (March 2021) + CPMI-IOSCO Guidance on Cyber Resilience for FMIs. (1) Business Impact Analysis (BIA): (a) Critical Functions identification - customer payment + trading + market data + customer service + AML; (b) Recovery Time Objective (RTO) per critical function; (c) Recovery Point Objective (RPO) per critical data; (d) Maximum Tolerable Period of Disruption (MTPD); (e) Resource Requirements; (f) Dependencies (internal + external); (g) Periodic review + after material change. (2) Business Continuity Plan (BCP): (a) Comprehensive BCP covering disruption types; (b) Crisis Management Team; (c) Communications Plan + stakeholders; (d) Alternative work arrangements; (e) Site failover; (f) Critical Function co
- BIA + critical functions + records + annual + after material change
- RTO/RPO + Board approved + records + tested + per function + per data class
- Immutable + air-gapped + records + per backup class + ransomware-resistant
- DR drills + quarterly + annual full + records + lessons learned
- FSA Operational Resilience + Important Business Service + impact tolerance + records
- BIA stale (no annual review)
- RTO/RPO aspirational (not tested)
- Backups not immutable or air-gapped (ransomware vulnerable)
- DR drills partial only (full failover untested)
- Operational Resilience Framework not adopted (siloed BCM)
JP FSA Cyber Exercises + Drills
Cybersecurity exercises + drills are mandated per FSA Cybersecurity Guidelines for Tier 2/3 institutions + coordinated industry-wide via Delta Wall + FISC. (1) Institutional Tabletop Exercises: (a) Annual minimum per FSA expectation; (b) Quarterly for Tier 3 + critical infrastructure; (c) Cross-functional - technical + business + legal + comms + executive + Board; (d) Realistic scenarios with current threat landscape; (e) Decision-making under pressure + ambiguity; (f) After Action Review + improvement actions tracked; (g) Annual Board observation. (2) Scenario Diversity: (a) Ransomware - encryption + extortion + double/triple extortion; (b) Wire Transfer Fraud - BEC + insider + APT; (c) Customer Account Takeover; (d) DDoS attack on customer-facing; (e) Insider Threat - malicious + negligent; (f) Supply Chain Attack (SolarWinds-style); (g) Critical Service Provider Outage; (h) ATM/Card N
- Annual tabletop + cross-functional + records + per exercise + AAR
- Delta Wall + FSA + records + per year + sector lessons learned
- Cyber range + Tier 3 + records + per exercise + Red/Blue/Purple
- Scenario diversity + records + per year + threat coverage matrix
- Improvement actions + tracked + records + per quarter + completion rate
- Tabletop infrequent (every 2-3 years rather than annual)
- Delta Wall participation perfunctory
- Cyber range absent or shared with limited use
- Scenario diversity limited (same scenarios repeated)
- Improvement actions un-tracked (lessons unlearned)
JP FSA Cyber IAM + Customer Auth
Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control. (1) Workforce IAM: (a) Identity Lifecycle Management - joiner-mover-leaver process; (b) Single Sign-On (SSO) + SAML 2.0 + OIDC; (c) Multi-Factor Authentication (MFA) mandatory for all + especially privileged; (d) Role-Based Access Control (RBAC) + Attribute-Based (ABAC); (e) Least Privilege + Need-to-Know; (f) Quarterly Access Recertification; (g) Segregation of Duties; (h) Identity Federation across multi-cloud + hybrid. (2) Privileged Access Management (PAM): (a) Privileged Account Inventory; (b) Vault + Secret Management; (c) Just-In-Time (JIT) provisioning replacing standing privileges; (d) Session Recording + Monitoring; (e) Break-Glass procedures; (f) Privileged Session Ma
- MFA + all users + records + per user + per system + audit trail
- PAM + JIT + session recording + records + per privileged session + audit
- Zero Trust + continuous verification + records + per session + microsegmentation
- Banking customer auth + risk-based + records + per transaction + step-up
- APP fraud controls + records + per detection + customer protection + recovery
- MFA inconsistent (legacy systems excepted)
- PAM standing privileges (no JIT)
- Zero Trust marketing rather than implementation
- Customer authentication single-factor for transactions
- APP fraud controls reactive (no real-time detection)
JP FSA Cyber Incident Response
Incident Response capability is critical per FSA Cybersecurity Guidelines. (1) Incident Response Plan: (a) Documented IR Plan + per FFIEC IT Examination Handbook reference; (b) ISO/IEC 27035 Information Security Incident Management; (c) NIST SP 800-61 Computer Security Incident Handling Guide; (d) Sector-specific - FISC + JFSA reference; (e) Annual review + update; (f) Board approval; (g) Plan accessible to CSIRT + SOC + Senior Management. (2) Incident Classification + Severity: (a) Severity 1 (Critical) - widespread outage + significant customer impact + sensitive data breach; (b) Severity 2 (High) - localised outage + limited customer impact; (c) Severity 3 (Medium) - operational disruption + no customer impact; (d) Severity 4 (Low) - minor issue + procedural; (e) Per-Severity response procedures + escalation. (3) CSIRT Computer Security Incident Response Team: (a) Dedicated CSIRT - Ti
- IR Plan + documented + Board approved + records + annual review + scenarios
- CSIRT + 24x7 + records + per incident + roles + handover
- Tabletop exercises + annual + records + per scenario + after action review
- FSA notification + Article 52-2 + records + per incident + initial + detailed
- Post-incident + RCA + lessons learned + records + per incident + improvement actions
- IR Plan outdated (no annual review)
- CSIRT business-hours coverage only
- Tabletop infrequent (every 2-3 years)
- FSA notification delayed (>30 days)
- Lessons learned siloed (no industry sharing)
JP FSA Cyber Maturity Self-Assessment
The FSA Cybersecurity Maturity Self-Assessment Tool (Saiba Sekyuritii Jiko Hyouka Tool サイバーセキュリティ自己評価ツール) is the centrepiece annual assessment requirement for Japanese financial institutions + first introduced 2017 + significantly enhanced 2022 + sector-specific versions 2024. (1) Self-Assessment Structure: (a) ~150 cybersecurity controls across 6 domains - Governance + Risk Management + Asset Management + Detection + Response + Recovery; (b) Per-Control Maturity Rating (1-5 scale or NIST-style); (c) Evidence requirement per control; (d) Self-Assessment workbook submitted to FSA annually; (e) FSA peer benchmarking + sector-aggregate analysis returned to participating institutions. (2) Maturity Tier Framework: (a) Tier 1 (Basic / Foundational) - all financial institutions including small regional banks + small insurers + small securities firms - basic NIST CSF Identify + Protect + Detect;
- Annual self-assessment + FSA submission + records + per year + audit trail
- Maturity tier + Tier 1/2/3 + records + per institution + progression
- Evidence per control + workbook + records + audit-ready + documents/screenshots/logs
- Gap remediation + tracking + records + per quarter + lessons learned
- Internal audit verification + Three Lines + records + annual + independent
- Self-assessment perfunctory or aspirational (no evidence backing)
- Maturity tier misclassified (under-tiered to avoid scrutiny)
- Evidence weak or generic
- Gap remediation not tracked (annual cycle broken)
- Internal audit not verifying self-assessment
JP FSA Cyber Regulatory Reporting
Regulatory cyber incident notification is mandated by multiple sectoral statutes + FSA Inspection Manual + APPI. (1) Statutory Notification Obligations: (a) Banking Act Article 52-2 + Banking Industry Cybersecurity Notification Order; (b) Insurance Business Act Article 100-2 + Insurance Industry Cybersecurity Notification Order; (c) Financial Instruments and Exchange Act Article 19 + Securities Industry Notification Order; (d) FSA Inspection Manual + Supervisory Guidelines per sector; (e) APPI Article 26 personal data breach notification to PIPC. (2) Material Incident Definition: (a) Customer Impact - service disruption + data breach + financial loss; (b) Operational Impact - significant outage > 4 hours + business critical system; (c) Data Breach - personal information of significant number of customers; (d) Ransomware Detected or Successful; (e) Wire Transfer Fraud + Significant Financ
- Statutory notification + documented + records + per sector + per Article
- 30-day SLA + FSA + records + per incident + initial + detailed + closure
- APPI Article 26 + PIPC + records + per personal data incident + 30-day
- Customer notification + plain language + records + per affected + recommended actions
- Cross-jurisdictional + SEC/GDPR/UK + records + counsel + coordinated timing
- Statutory notification process informal (no per-Article procedure)
- 30-day SLA frequently exceeded
- APPI Article 26 dimension overlooked
- Customer notification template + dense legal
- Cross-jurisdictional uncoordinated (regulatory whipsaw risk)
JP FSA Cyber Risk Management
The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM). (1) NIST CSF 2.0 Alignment - 6 Functions: (a) GOVERN (added in 2.0) - cybersecurity governance + risk management + organizational context + policy; (b) IDENTIFY - asset management + business environment + risk assessment + risk management strategy; (c) PROTECT - identity management + awareness + data security + protective technology; (d) DETECT - anomalies + continuous monitoring + detection processes; (e) RESPOND - response planning + communications + analysis + mitigation; (f) RECOVER - recovery planning + improvements + communications. (2) ISO/IEC 27001 ISMS Integration: (a) Information Security Management System scope including cybersecurity; (b)
- NIST CSF 2.0 + 6 functions + records + per function + maturity scoring
- Risk Appetite + Board + records + annual + KRIs + limit breach escalation
- Risk assessment + inherent + residual + records + per asset + threat modelling
- Treatment decisions + records + per risk + documented + reviewed
- ERM integration + cyber principal + records + Board dashboard + ICAAP where applicable
- NIST CSF 2.0 not mapped (older framework only)
- Risk Appetite absent or not cyber-specific
- Risk assessment compliance-driven (no real threat modelling)
- Treatment decisions implicit (no formal documentation)
- ERM integration absent (cyber siloed)
JP FSA Cyber SOC + Detection
Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling; (b) Hybrid SOC - internal + MSSP Managed Security Service Provider; (c) Outsourced SOC - MSSP managed; (d) MDR Managed Detection and Response - emerging; (e) XDR Extended Detection and Response platforms; (f) Cloud SOC integration; (g) Follow-the-Sun for 24x7 coverage; (h) SOC analyst tiers - L1 triage + L2 investigation + L3 threat hunting + L4 incident response. (2) SIEM Security Information and Event Management: (a) Log aggregation + normalisation + correlation; (b) Major SIEM vendors - Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security + Exabeam + Sumo Logic; (c) Cloud-native SIEM - AWS Security Hub + Google Chronicle + Azure Sentinel; (d) Use Case Library + Detection
- 24x7 SOC + records + per shift + Tier 2/3 + handover + escalation
- SIEM + log coverage + records + per source + retention 1-7 years + use cases
- EDR + 100% endpoints + records + per quarter + behavioural detection
- MITRE ATT and CK + detection coverage + records + per tactic + per technique
- Threat hunting + Tier 3 + records + per hunt + findings + lessons learned
- SOC business-hours only (8x5 not 24x7)
- SIEM log gaps (critical systems not ingested)
- EDR partial coverage (legacy + servers excepted)
- MITRE ATT and CK coverage unknown
- Threat hunting absent or ad-hoc
JP FSA Cyber Scope + Governance
The Japan Financial Services Agency (FSA 金融庁) Cybersecurity Guidelines (Saiba Sekyuritii ni kansuru Gaidorain サイバーセキュリティに関するガイドライン) are the foundational cybersecurity regulatory framework for Japanese financial institutions + first issued July 2015 + revised 2019 + 2022 + sector-specific revisions 2024. (1) Issuing Body: Japan Financial Services Agency (FSA) Supervisory Coordination Division + Securities and Exchange Surveillance Commission (SESC) + IT Division. (2) Statutory Authority: (a) Banking Act Article 52-2 + Insurance Business Act Article 100-2 + Financial Instruments and Exchange Act Article 19; (b) Cybersecurity Basic Act 2014 (Saiba Sekyuritii Kihon Hou サイバーセキュリティ基本法); (c) NISC National Center of Incident Readiness and Strategy for Cybersecurity coordination; (d) FSA Inspection Manual sector-specific cybersecurity provisions. (3) Scope Coverage: applies to (a) Banks - city ba
- Cybersecurity Strategy + Board approved + records + per quarter + Tone-at-Top + signed
- CISO + Board access + records + quarterly reporting + escalation criteria
- Maturity tier self-assessment + Tier 1/2/3 + records + annual + FSA submission
- FISC coordination + industry drills + Delta Wall + records + per engagement
- Sector-specific + Banking Article 52-2 / Insurance Article 100-2 / Securities Article 19 + records
- Cybersecurity Strategy not Board-approved (delegated only)
- CISO without Board access or quarterly reporting
- Maturity tier self-assessment not submitted or perfunctory
- FISC industry drills not participated
- Sector-specific application unclear (treated as generic)
JP FSA Cyber Third Party + Cloud
Third-Party + Outsourcing + Cloud Service Provider cybersecurity is critical per FSA Cybersecurity Guidelines + FISC Cloud Guidelines (FISC Anzen Taisaku Kijun - Cloud Computing Edition). (1) Outsourcing Governance: (a) Outsourcing Policy + Board Approval; (b) Per-Engagement Risk Assessment; (c) Critical vs Non-Critical Classification; (d) Due Diligence proportionate to risk; (e) Contractual obligations + KPIs; (f) Ongoing Monitoring; (g) Periodic Reassessment; (h) Termination + Transition planning. (2) Cloud Service Provider (CSP) Due Diligence: (a) AWS + Microsoft Azure + Google Cloud + Oracle + IBM Cloud + domestic (NTT Cloud + Fujitsu + NEC); (b) Financial Stability + Track Record; (c) Compliance Certifications - ISO 27001 + 27017 + 27018 + 27701 + SOC 2 + ISMAP + FedRAMP equivalent; (d) Data Residency - Japan-only + Asia-Pacific + Global; (e) Encryption + Customer-Managed Keys (CMK)
- Outsourcing governance + per engagement + records + per vendor + critical/non-critical
- Cloud provider DD + ISMAP + records + per CSP + certifications + audit
- Audit right + exercised + records + per annual + onsite or remote
- Concentration risk + multi-cloud strategy + records + per critical + exit plan
- Sub-processor visibility + chain + records + per sub + disclosure + approval
- Outsourcing governance generic (no per-engagement assessment)
- Cloud DD accepts vendor certifications (no audit)
- Audit right contractual but never exercised
- Concentration risk unmonitored (single CSP dependency)
- Sub-processor chain opaque (visibility gaps)
JP FSA Cyber Vulnerability Mgmt
Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing; (c) SAST Static Application Security Testing; (d) IAST Interactive Application Security Testing; (e) SCA Software Composition Analysis - open source dependencies; (f) Container + Cloud Vulnerability Scanning; (g) Network configuration assessment; (h) Continuous + on-demand. (2) Vulnerability Intelligence: (a) National Vulnerability Database (NVD); (b) Japan Vulnerability Notes (JVN) JPCERT/CC; (c) JVN iPedia comprehensive database; (d) Vendor Security Advisories; (e) Threat intelligence integration; (f) Zero-Day intelligence; (g) Exploit availability monitoring (Metasploit + Exploit-DB). (3) Risk-Based Prioritisation: (a) CVSS v3.1 / v
- Vulnerability scanning + continuous + records + per asset + per cycle + risk score
- Patching SLA + per severity + records + audit + dashboard + Board reporting
- Pen testing + annual + records + per scope + findings + remediation
- Red-Team + Tier 3 + records + per annual + Purple Team + scenarios
- SBOM + open source + records + per application + license + vulnerability
- Vulnerability scanning annual only (no continuous)
- Patching SLA missed (critical >7 days)
- Pen testing checkbox (no real attack simulation)
- Red-Team absent for Tier 3
- SBOM not maintained (Log4j-style surprise risk)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Japan FSA Cybersecurity Guidelines for Financial Institutions framework page.