ISMAP (Japan)
ISMAP Cloud Infrastructure

ISMAP (Japan) ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement: ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linkerd) + east-west traffic inspection + zero trust network access (ZTNA) + identity-aware proxies + private endpoints (AWS PrivateLink + Azure Private Link + GCP Private Service Connect) + no public IP for sensitive workloads + bastion hosts + jump hosts + VPN/Direct Connect for hybrid + Cloud Network Architecture per JIS X 5051. (2) Container Security: Kubernetes hardening per CIS Kubernetes Benchmark + Pod Security Standards + RBAC + Network Policies + admission controllers (OPA Gatekeeper + Kyverno) + container image scanning (Twistlock + Aqua + Snyk + Anchore) + signed images (Cosign + Notary + Sigstore) + Software Bill of Materials (SBOM) per CycloneDX + SPDX + runtime security (Falco + Sysdig) + container registry security + private registries + image lifecycle. (3) Serverless Security: Function as a Service (FaaS) security + AWS Lambda + Azure Functions + Google Cloud Functions + Knative + cold start security + IAM roles per function + function-to-function authentication + secrets management + dependency scanning + monitoring + observability. (4) Cloud Workload Protection Platform (CWPP): per Gartner CWPP definition + EDR for cloud workloads + behavioural analytics + machine learning + threat hunting + tools (Wiz + Lacework + Prisma Cloud + CrowdStrike Falcon Cloud + Microsoft Defender for Cloud + AWS GuardDuty + GCP Security Command Center). (5) Image and Template Hardening: CIS Hardened Images + STIG Security Technical Implementation Guides + DISA Security Hardening Guides + golden images + immutable infrastructure + regular rebuild + vulnerability scanning + patch management per OS + per platform + JIS X 19790 hardening + JIS X 19592. (6) Cloud Configuration Management: Infrastructure as Code (IaC) + Terraform + AWS CloudFormation + Azure ARM/Bicep + GCP Deployment Manager + Pulumi + Crossplane + version controlled + reviewed + tested + drift detection + Cloud Security Posture Management (CSPM) - Wiz + Prisma Cloud + Lacework + AWS Config + Azure Policy + GCP Security Health Analytics + continuous compliance checks against CIS Benchmarks + ISMAP controls + automated remediation. (7) Multi-Tenancy Isolation: customer isolation + noisy neighbour protection + resource quotas + service-to-service isolation + dedicated vs shared resources + bare-metal vs virtual + customer-specific encryption keys. (8) Cloud Native Security: 12-Factor Apps + SaaS-specific controls + multi-region active-active + disaster recovery + Site Reliability Engineering (SRE). Coordinates with CIS Benchmarks + CIS Hardened Images + STIG + JIS X 19790 + JIS X 5051 + Kubernetes CIS Benchmark + Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) + Container Security Forum + CNCF Cloud Native Computing Foundation. ISMAP Cloud Infrastructure applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.