ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Information Security Management System Accreditation Center Japan certification + plus ISMAP-specific extensions for cloud. ISMS scope must cover all ISMAP-relevant services + assets + processes. (2) Cloud Security Policy and Strategy: documented cloud-specific security policy approved by senior management + reviewed annually + cascaded to all relevant personnel + covering cloud-specific risks (shared responsibility + multi-tenancy + virtualisation + API + data residency + hyperscaler vs private cloud + hybrid). (3) Cloud Risk Assessment: risk-based approach per ISO/IEC 27005 + JIS Q 27005 + considering cloud-specific threats (insider threat + data leakage + account hijacking + API abuse + multi-tenancy compromise + vendor lock-in + supply chain + denial of service + service outage + ransomware) + assets (data + virtual machines + containers + serverless functions + storage + databases + identities + APIs + customer data + personal information) + vulnerabilities + impact analysis + treatment plan + risk register + heat map + Board-level risk reporting. (4) Shared Responsibility Model: clearly defined responsibilities between CSP and customer (government agency) + per service type (IaaS + PaaS + SaaS) + including responsibility matrix (RACI) for security controls + transparent customer-facing documentation + customer assurance materials. Standard CSP responsibilities: physical infrastructure + hypervisor + storage + network + identity provider infrastructure + customer isolation + service uptime; standard customer responsibilities: data classification + access management + application configuration + customer-managed encryption keys + workload security. (5) Regulatory Compliance: alignment with applicable Japanese laws + Personal Information Protection Act (PIPA) Act on the Protection of Personal Information + Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (My Number Act) + Cybersecurity Basic Act + Act on Prohibition of Unauthorized Computer Access + Act on Protection of Specially Designated Secrets + Telecommunications Business Act + Act on the Protection of Personal Information held by Administrative Organs (where applicable for government data) + sector-specific (FSA Financial Services Agency cloud guidelines + MHLW Health Cloud Guidelines + METI Industrial Cybersecurity) + international (GDPR + ISO 27001 + ISO 27017 + ISO 27018 + ISO 27701 + ISO 22301). (6) Cloud Security Roles and Responsibilities: Chief Information Security Officer (CISO) + Cloud Security Officer (CSO) + Security Operations Center (SOC) + Data Protection Officer (DPO if applicable) + Cloud Architect + Cloud Compliance Officer + Customer Liaison + Audit + clear reporting structure + segregation of duties + dual-control for sensitive operations. Coordinates with ISO 27001 + ISO 27017 + ISO 27018 + ISO 27701 + ISO 22301 + ISMS-AC + JIS Q 27001 + Japanese PIPA + My Number Act + Cybersecurity Basic Act + FSA cloud guidelines + MHLW cloud guidelines. ISMAP Cloud Governance applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.