ISMAP (Japan) ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS: ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM
ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) Strictly Confidential + (e) Top Secret per Cabinet Office classification + plus Personal Information per PIPA + My Number Special Personal Information + Specially Designated Secret per Special Secrets Protection Act. Labelling + handling per classification + access controls per classification. (2) Encryption At Rest: AES-256 minimum + AES-128 acceptable for non-sensitive + FIPS 140-3 validated cryptographic modules (or FIPS 140-2 transitioning) + CRYPTREC (Cryptography Research and Evaluation Committee) Japanese government approved algorithms list + JIS X 19768 + key management per ISO 11770 + HSM Hardware Security Module (FIPS 140-3 Level 3) for high-security workloads + customer-managed keys (BYOK Bring Your Own Key + HYOK Hold Your Own Key) for ISMAP-Critical tier + envelope encryption + key rotation per CRYPTREC guidance + key escrow for legal continuity. (3) Encryption In Transit: TLS 1.3 minimum (TLS 1.2 transitional) + cipher suites per CRYPTREC + Perfect Forward Secrecy (PFS) + HSTS + Certificate transparency + EV/OV certificates + mTLS for service-to-service + IPSec for VPN + secure protocols only (no plain FTP + Telnet + SNMPv1/2) + post-quantum cryptography roadmap (NIST PQC standards CRYSTALS-Kyber + CRYSTALS-Dilithium + SPHINCS+ for ISMAP-Critical tier). (4) Data Residency Japan: ISMAP-Standard tier permits data processing in approved data centres + may include Japan-region + select foreign regions per CSP scope; ISMAP-Critical tier REQUIRES data residency in Japan + processing + backup + DR in Japan + no foreign data residency + no foreign government access; Japanese cloud regions (AWS ap-northeast-1 + AWS ap-northeast-3 + Azure Japan East + Japan West + GCP asia-northeast-1 + asia-northeast-2 + Oracle Japan East + Japan Central) + Cabinet Office Japan Government Cloud (Common Government Cloud Platform). (5) Backup: 3-2-1 backup rule (3 copies + 2 different media + 1 offsite) + tested restore procedures + RTO Recovery Time Objective + RPO Recovery Point Objective per service criticality + immutable backups + ransomware-resistant + air-gapped or offline copies + backup encryption + retention per regulatory requirements (My Number retention + PIPA retention + sector-specific). (6) Secure Deletion: per NIST SP 800-88 Media Sanitization + ISO 27040 Storage Security + cryptographic erase + physical destruction + degaussing + Certificate of Destruction + data sanitisation policy + end-of-contract data return/deletion + retention schedules + records destruction logs. (7) Personal Information Protection: per PIPA + My Number Act + Right to Be Forgotten + consent management + DPIA Data Protection Impact Assessment + DPO Data Protection Officer + breach notification per PIPA 72-hour. Coordinates with FIPS 140-3 + NIST SP 800-88 + ISO 27040 + ISO 11770 + CRYPTREC + JIS X 19768 + JIS X 5070 + Japanese government cloud guidelines + Japanese PIPA + My Number Act. ISMAP Data Protection applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 163 controls across 54 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)