ISMAP (Japan)
ISMAP Identity + Access

ISMAP (Japan) ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO: ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM

ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities. (1) Cloud Identity Management: centralised identity directory (LDAP or Active Directory + cloud-provider IAM + identity-as-a-service) + identity lifecycle management (provisioning + role change + termination + just-in-time access) + identity governance + access reviews + access certifications + identity analytics + dormant account detection + orphan account cleanup + RBAC role-based access control + ABAC attribute-based access control + minimum 90-day password rotation for privileged accounts + password complexity per NIST SP 800-63B + JIS X 5051. (2) Multi-Factor Authentication (MFA): MANDATORY for all administrative access + privileged access + customer-facing portals + remote access + based on something-you-have (hardware token + smartphone authenticator + smart card) + something-you-are (biometric) + something-you-know (password) + FIDO2/WebAuthn for phishing-resistant + risk-based authentication + adaptive MFA + compatible with My Number Card (Japanese national ID card with PKI smart card capability). (3) Privileged Access Management (PAM): privileged access workstations (PAW) + just-in-time access + approval workflow + session recording + privileged credential vault + break-glass procedures + session monitoring + privileged session analytics + zero standing privilege + PEDM Privilege Elevation and Delegation Management. (4) Federation and Single Sign-On (SSO): SAML 2.0 + OAuth 2.0 + OpenID Connect (OIDC) + WS-Federation + federated identity with Japanese government IdP including Government Identity Verification Service + e-Tax Portal + Japan Digital Agency Identity + Cabinet Office identity infrastructure. (5) API Security and Access Tokens: OAuth 2.0 + JWT (JSON Web Tokens) + PASETO (Platform-Agnostic Security Tokens) + API gateway + rate limiting + token introspection + token revocation + scopes + audience + short-lived tokens + refresh token rotation + mutual TLS (mTLS) + API key management + signed requests + OAuth 2.0 PKCE for public clients. (6) My Number Card Integration: Japanese national ID card with PKI smart card + integration for government employee authentication + citizen-facing services + JPKI (Japanese Public Key Infrastructure) + government PKI hierarchy + supports digital signatures + identity verification + e-government services. (7) Government IAM Integration: J-LIS Japan Agency for Local Authority Information Systems + GIDV Government Identity Verification + e-Gov + Digital Agency identity infrastructure. (8) Zero Trust: per US NIST SP 800-207 Zero Trust Architecture + Japanese Digital Agency Zero Trust guidance + identity-aware proxies + microsegmentation + continuous verification + least privilege + assume breach. Coordinates with NIST SP 800-63 Digital Identity + JIS X 5051 + ISO 24760 IAM + FIDO Alliance + OAuth 2.0 + OIDC + SAML 2.0 + JPKI + Japan Digital Agency + Government PKI. ISMAP Identity + Access applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 79 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.3 Account Management

OWASP Top 10:2025 · 4 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

BSI IT-Grundschutz · 3 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

OWASP ASVS · 2 controls

  • AMLCTF-35 Identity Verification Standard
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27010:2015 · 1 control

  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

MITRE D3FEND · 1 control

MiFID II / MiFIR · 1 control

  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 79 it maps to, and the evidence behind each claim, over MCP and REST.