ISMAP (Japan)
ISMAP Data Protection

ISMAP (Japan) ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS: ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM

ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) Strictly Confidential + (e) Top Secret per Cabinet Office classification + plus Personal Information per PIPA + My Number Special Personal Information + Specially Designated Secret per Special Secrets Protection Act. Labelling + handling per classification + access controls per classification. (2) Encryption At Rest: AES-256 minimum + AES-128 acceptable for non-sensitive + FIPS 140-3 validated cryptographic modules (or FIPS 140-2 transitioning) + CRYPTREC (Cryptography Research and Evaluation Committee) Japanese government approved algorithms list + JIS X 19768 + key management per ISO 11770 + HSM Hardware Security Module (FIPS 140-3 Level 3) for high-security workloads + customer-managed keys (BYOK Bring Your Own Key + HYOK Hold Your Own Key) for ISMAP-Critical tier + envelope encryption + key rotation per CRYPTREC guidance + key escrow for legal continuity. (3) Encryption In Transit: TLS 1.3 minimum (TLS 1.2 transitional) + cipher suites per CRYPTREC + Perfect Forward Secrecy (PFS) + HSTS + Certificate transparency + EV/OV certificates + mTLS for service-to-service + IPSec for VPN + secure protocols only (no plain FTP + Telnet + SNMPv1/2) + post-quantum cryptography roadmap (NIST PQC standards CRYSTALS-Kyber + CRYSTALS-Dilithium + SPHINCS+ for ISMAP-Critical tier). (4) Data Residency Japan: ISMAP-Standard tier permits data processing in approved data centres + may include Japan-region + select foreign regions per CSP scope; ISMAP-Critical tier REQUIRES data residency in Japan + processing + backup + DR in Japan + no foreign data residency + no foreign government access; Japanese cloud regions (AWS ap-northeast-1 + AWS ap-northeast-3 + Azure Japan East + Japan West + GCP asia-northeast-1 + asia-northeast-2 + Oracle Japan East + Japan Central) + Cabinet Office Japan Government Cloud (Common Government Cloud Platform). (5) Backup: 3-2-1 backup rule (3 copies + 2 different media + 1 offsite) + tested restore procedures + RTO Recovery Time Objective + RPO Recovery Point Objective per service criticality + immutable backups + ransomware-resistant + air-gapped or offline copies + backup encryption + retention per regulatory requirements (My Number retention + PIPA retention + sector-specific). (6) Secure Deletion: per NIST SP 800-88 Media Sanitization + ISO 27040 Storage Security + cryptographic erase + physical destruction + degaussing + Certificate of Destruction + data sanitisation policy + end-of-contract data return/deletion + retention schedules + records destruction logs. (7) Personal Information Protection: per PIPA + My Number Act + Right to Be Forgotten + consent management + DPIA Data Protection Impact Assessment + DPO Data Protection Officer + breach notification per PIPA 72-hour. Coordinates with FIPS 140-3 + NIST SP 800-88 + ISO 27040 + ISO 11770 + CRYPTREC + JIS X 19768 + JIS X 5070 + Japanese government cloud guidelines + Japanese PIPA + My Number Act. ISMAP Data Protection applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 163 controls across 54 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • IM8-CLD.2 Cloud Security Controls
  • IM8-DAT.1 Data Classification
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

API 1164 · 4 controls

  • API1164-02 Risk Management Framework
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

FedRAMP Rev 5 · 4 controls

  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

IEC 62443 · 4 controls

  • IEC62443-02 System security categorization
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.3 Cryptography and key management
  • 27011-8.6 Data protection and backup
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

GDPR · 3 controls

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion

MITRE D3FEND · 3 controls

  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development

OWASP ASVS · 3 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

BSI IT-Grundschutz · 2 controls

  • BSI-08 Cryptographic protection of data
  • BSI-15 Security categorization
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-09 Encryption and key management
  • FFIEC-12 Disaster recovery procedures

ISO/IEC 27010:2015 · 2 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-8.2 Membership Termination
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • D.1 Incident Response Planning
  • D.3 Backup and Recovery
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • 4.4.8 Business Continuity and Recovery
  • AL-DPA-14 Direct Marketing
  • DIQ-1 Data Integration and Interoperability
  • QMSR-820.45 Device labelling and packaging controls (§820.45)

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • 60601-1.7.1 Equipment identification and marking
  • 62351-9 Cyber security key management
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • RUSPD-4 Special Categories, Biometric Data
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 163 it maps to, and the evidence behind each claim, over MCP and REST.