ISMAP (Japan)
ISMAP Cloud Operations

ISMAP (Japan) ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA: ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management

ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management + UEBA User and Entity Behaviour Analytics + SOAR Security Orchestration Automation and Response + log centralisation + log retention per ISMAP (typically 1 year minimum + 7 years for ISMAP-Critical) + tamper-evident + WORM storage + clock synchronisation (NTP) + Cloud-native logging (AWS CloudTrail + Azure Monitor + GCP Cloud Logging) + cross-cloud aggregation + alerting + dashboards + Cloud Security Posture Management (CSPM) + Cloud Detection and Response (CDR). (2) Incident Response in Cloud: documented incident response plan + IR team + IR phases (Preparation + Identification + Containment + Eradication + Recovery + Lessons Learned) + tabletop exercises + live exercises + IR playbooks + integration with CSP IR (AWS + Azure + GCP IR) + forensic readiness + chain of custody + threat hunting + Indicator of Compromise (IOC) tracking + Indicator of Attack (IOA) + MITRE ATT&CK framework + retainer for an external incident response provider. (3) NISC Reporting and Government Notification: incident reporting to NISC within prescribed windows + (a) major incident affecting government cloud customer notification within 24 hours of discovery; (b) JPCERT/CC Japan Computer Emergency Response Team Coordination Center coordination; (c) IPA SHIENNETSAB IPA Cybersecurity Service Notification Center; (d) Industry-specific CSIRT (Finance ISAC + Healthcare ISAC + Telecom ISAC + Energy ISAC); (e) Cabinet Office for nationally significant incidents; (f) Government customer agency notification; (g) Industry CSIRT coordination; (h) Personal Information Protection Commission (PIPC) if personal information breach per PIPA 72-hour. (4) Cloud Vulnerability Management: continuous vulnerability scanning + CVE tracking + CVSS scoring + risk-based prioritisation + patch management + vulnerability disclosure program + bug bounty + JVN Japan Vulnerability Notes + IPA Information-technology Promotion Agency advisories + JPCERT alerts + NIST NVD + CISA Known Exploited Vulnerabilities + zero-day handling + responsible disclosure. (5) Penetration Testing: annual penetration testing by qualified ISMAP-approved auditor + scope covering external + internal + web + mobile + API + cloud-specific (multi-tenancy + container escape + serverless) + report submission + remediation tracking + retesting + Red Team exercises for ISMAP-Critical. (6) Cloud Change Management: documented change procedures + Change Advisory Board (CAB) + emergency changes + standard changes + normal changes + risk assessment + testing + back-out plan + post-change review + Configuration Management Database (CMDB) + ITIL 4 + ISO 20000. (7) Service Level Agreement (SLA) Management: documented SLAs + uptime targets (99.9% + 99.95% + 99.99% per tier) + monthly reporting + credits for SLA breach + customer notification + transparency + Government cloud SLA standards. Coordinates with NIST SP 800-61 IR + NIST SP 800-184 Recovery + ISO 27035 Incident + ISO 27040 + JPCERT/CC + IPA + NISC + PIPC + JVN + NIST NVD + CISA KEV + MITRE ATT&CK + STIX/TAXII + Cyber Threat Intelligence (CTI) feeds. ISMAP Cloud Operations applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 154 controls across 59 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 9 controls

  • BSI-14 Vulnerability scanning and management
  • BSI-17 Continuous monitoring strategy
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • BSI-24 Configuration change control
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

API 1164 · 5 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-23 Change management procedures

IEC 62443 · 5 controls

  • IEC62443-13 Network security monitoring
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • IEC62443-23 Change management procedures
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)
  • ASD37-33 Capture network traffic (Limited)

ISO/IEC 30111:2019 · 4 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team
  • 30111-8.1 Post-release monitoring
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • CAT-D3-2 Detective controls
  • CAT-D3-3 Corrective controls
  • CAT-D5-1 Incident planning and strategy
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response
  • IM8-RES.3 Incident Response
  • IM8-SEC.3 Network Security
  • IM8-SEC.4 Vulnerability Management

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls

Bahrain PDPL · 2 controls

FedRAMP High · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling

FedRAMP Moderate · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process

ISO/IEC 27011:2024 · 2 controls

  • 27011-8.4 Logging and monitoring
  • 27011-8.5 Vulnerability and malware management

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

MITRE D3FEND · 2 controls

OWASP ASVS · 2 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CPG-5.A Vulnerability Disclosure Program
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)
  • ICP-24 Macroprudential Surveillance and Insurance Supervision
  • 62351-14 Cyber security event logging
  • 27006-9.4 Surveillance and recertification

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • PSPF24-1 Security Culture, Governance, Risk Management
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 154 it maps to, and the evidence behind each claim, over MCP and REST.