ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities. (1) Cloud Identity Management: centralised identity directory (LDAP + Active Directory + Azure AD + AWS IAM + Google Cloud IAM + Okta + Auth0) + identity lifecycle management (provisioning + role change + termination + just-in-time access) + identity governance + access reviews + access certifications + identity analytics + dormant account detection + orphan account cleanup + RBAC role-based access control + ABAC attribute-based access control + minimum 90-day password rotation for privileged accounts + password complexity per NIST SP 800-63B + JIS X 5051. (2) Multi-Factor Authentication (MFA): MANDATORY for all administrative access + privileged access + customer-facing portals + remote access + based on something-you-have (hardware token + smartphone authenticator + smart card) + something-you-are (biometric) + something-you-know (password) + FIDO2/WebAuthn for phishing-resistant + risk-based authentication + adaptive MFA + compatible with My Number Card (Japanese national ID card with PKI smart card capability). (3) Privileged Access Management (PAM): privileged access workstations (PAW) + just-in-time access + approval workflow + session recording + privileged credential vault (CyberArk + HashiCorp Vault + AWS Secrets Manager + Azure Key Vault) + break-glass procedures + session monitoring + privileged session analytics + zero standing privilege + PEDM Privilege Elevation and Delegation Management. (4) Federation and Single Sign-On (SSO): SAML 2.0 + OAuth 2.0 + OpenID Connect (OIDC) + WS-Federation + federated identity with Japanese government IdP including Government Identity Verification Service + e-Tax Portal + Japan Digital Agency Identity + Cabinet Office identity infrastructure. (5) API Security and Access Tokens: OAuth 2.0 + JWT (JSON Web Tokens) + PASETO (Platform-Agnostic Security Tokens) + API gateway + rate limiting + token introspection + token revocation + scopes + audience + short-lived tokens + refresh token rotation + mutual TLS (mTLS) + API key management + signed requests + OAuth 2.0 PKCE for public clients. (6) My Number Card Integration: Japanese national ID card with PKI smart card + integration for government employee authentication + citizen-facing services + JPKI (Japanese Public Key Infrastructure) + government PKI hierarchy + supports digital signatures + identity verification + e-government services. (7) Government IAM Integration: J-LIS Japan Agency for Local Authority Information Systems + GIDV Government Identity Verification + e-Gov + Digital Agency identity infrastructure. (8) Zero Trust: per US NIST SP 800-207 Zero Trust Architecture + Japanese Digital Agency Zero Trust guidance + identity-aware proxies + microsegmentation + continuous verification + least privilege + assume breach. Coordinates with NIST SP 800-63 Digital Identity + JIS X 5051 + ISO 24760 IAM + FIDO Alliance + OAuth 2.0 + OIDC + SAML 2.0 + JPKI + Japan Digital Agency + Government PKI. ISMAP Identity + Access applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.