ISMAP (Japan) ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities: ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities
ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Information Security Management System Accreditation Center Japan certification + plus ISMAP-specific extensions for cloud. ISMS scope must cover all ISMAP-relevant services + assets + processes. (2) Cloud Security Policy and Strategy: documented cloud-specific security policy approved by senior management + reviewed annually + cascaded to all relevant personnel + covering cloud-specific risks (shared responsibility + multi-tenancy + virtualisation + API + data residency + hyperscaler vs private cloud + hybrid). (3) Cloud Risk Assessment: risk-based approach per ISO/IEC 27005 + JIS Q 27005 + considering cloud-specific threats (insider threat + data leakage + account hijacking + API abuse + multi-tenancy compromise + vendor lock-in + supply chain + denial of service + service outage + ransomware) + assets (data + virtual machines + containers + serverless functions + storage + databases + identities + APIs + customer data + personal information) + vulnerabilities + impact analysis + treatment plan + risk register + heat map + Board-level risk reporting. (4) Shared Responsibility Model: clearly defined responsibilities between CSP and customer (government agency) + per service type (IaaS + PaaS + SaaS) + including responsibility matrix (RACI) for security controls + transparent customer-facing documentation + customer assurance materials. Standard CSP responsibilities: physical infrastructure + hypervisor + storage + network + identity provider infrastructure + customer isolation + service uptime; standard customer responsibilities: data classification + access management + application configuration + customer-managed encryption keys + workload security. (5) Regulatory Compliance: alignment with applicable Japanese laws + Personal Information Protection Act (PIPA) Act on the Protection of Personal Information + Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (My Number Act) + Cybersecurity Basic Act + Act on Prohibition of Unauthorized Computer Access + Act on Protection of Specially Designated Secrets + Telecommunications Business Act + Act on the Protection of Personal Information held by Administrative Organs (where applicable for government data) + sector-specific (FSA Financial Services Agency cloud guidelines + MHLW Health Cloud Guidelines + METI Industrial Cybersecurity) + international (GDPR + ISO 27001 + ISO 27017 + ISO 27018 + ISO 27701 + ISO 22301). (6) Cloud Security Roles and Responsibilities: Chief Information Security Officer (CISO) + Cloud Security Officer (CSO) + Security Operations Center (SOC) + Data Protection Officer (DPO if applicable) + Cloud Architect + Cloud Compliance Officer + Customer Liaison + Audit + clear reporting structure + segregation of duties + dual-control for sensitive operations. Coordinates with ISO 27001 + ISO 27017 + ISO 27018 + ISO 27701 + ISO 22301 + ISMS-AC + JIS Q 27001 + Japanese PIPA + My Number Act + Cybersecurity Basic Act + FSA cloud guidelines + MHLW cloud guidelines. ISMAP Cloud Governance applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 202 controls across 91 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33