ISMAP (Japan)
ISMAP Cloud Infrastructure

ISMAP (Japan) ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement: ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linkerd) + east-west traffic inspection + zero trust network access (ZTNA) + identity-aware proxies + private endpoints (AWS PrivateLink + Azure Private Link + GCP Private Service Connect) + no public IP for sensitive workloads + bastion hosts + jump hosts + VPN/Direct Connect for hybrid + Cloud Network Architecture per JIS X 5051. (2) Container Security: Kubernetes hardening per CIS Kubernetes Benchmark + Pod Security Standards + RBAC + Network Policies + admission controllers (OPA Gatekeeper + Kyverno) + container image scanning + signed images (Cosign + Notary + Sigstore) + Software Bill of Materials (SBOM) per CycloneDX + SPDX + runtime security + container registry security + private registries + image lifecycle. (3) Serverless Security: Function as a Service (FaaS) security + AWS Lambda + Azure Functions + Google Cloud Functions + Knative + cold start security + IAM roles per function + function-to-function authentication + secrets management + dependency scanning + monitoring + observability. (4) Cloud Workload Protection Platform (CWPP): per Gartner CWPP definition + EDR for cloud workloads + behavioural analytics + machine learning + threat hunting + cloud-provider native threat detection services. (5) Image and Template Hardening: CIS Hardened Images + STIG Security Technical Implementation Guides + DISA Security Hardening Guides + golden images + immutable infrastructure + regular rebuild + vulnerability scanning + patch management per OS + per platform + JIS X 19790 hardening + JIS X 19592. (6) Cloud Configuration Management: Infrastructure as Code (IaC) + Terraform + AWS CloudFormation + Azure ARM/Bicep + GCP Deployment Manager + Pulumi + Crossplane + version controlled + reviewed + tested + drift detection + Cloud Security Posture Management (CSPM) + cloud-provider native configuration policy services + continuous compliance checks against CIS Benchmarks + ISMAP controls + automated remediation. (7) Multi-Tenancy Isolation: customer isolation + noisy neighbour protection + resource quotas + service-to-service isolation + dedicated vs shared resources + bare-metal vs virtual + customer-specific encryption keys. (8) Cloud Native Security: 12-Factor Apps + SaaS-specific controls + multi-region active-active + disaster recovery + Site Reliability Engineering (SRE). Coordinates with CIS Benchmarks + CIS Hardened Images + STIG + JIS X 19790 + JIS X 5051 + Kubernetes CIS Benchmark + Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) + Container Security Forum + CNCF Cloud Native Computing Foundation. ISMAP Cloud Infrastructure applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 72 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

API 1164 · 3 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

IEC 62443 · 3 controls

  • IEC62443-13 Network security monitoring
  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems
  • AWWA-3.1 Network Segmentation
  • AWWA-4.3 Configuration Management
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CA-ITSG33-SC-03 Cloud Security
  • CJIS-16 Cloud Computing
  • CJIS-7 Configuration Management
  • CAT-D3-1 Preventative controls
  • CAT-D3-3 Corrective controls
  • FFIEC-06 Network security and segmentation
  • FFIEC-10 Secure configuration standards

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.3 Network Security
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • DIQ-1 Data Integration and Interoperability

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

MITRE D3FEND · 1 control

  • AQAP2110-4 Configuration Management and Change Control
  • OWASPAPI-6 Security Misconfiguration and Secure API Design

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.