ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities. (1) Cloud Identity Management: centralised identity directory (LDAP or Active Directory + cloud-provider IAM + identity-as-a-service) + identity lifecycle management (provisioning + role change + termination + just-in-time access) + identity governance + access reviews + access certifications + identity analytics + dormant account detection + orphan account cleanup + RBAC role-based access control + ABAC attribute-based access control + minimum 90-day password rotation for privileged accounts + password complexity per NIST SP 800-63B + JIS X 5051. (2) Multi-Factor Authentication (MFA): MANDATORY for all administrative access + privileged access + customer-facing portals + remote access + based on something-you-have (hardware token + smartphone authenticator + smart card) + something-you-are (biometric) + something-you-know (password) + FIDO2/WebAuthn for phishing-resistant + risk-based authentication + adaptive MFA + compatible with My Number Card (Japanese national ID card with PKI smart card capability). (3) Privileged Access Management (PAM): privileged access workstations (PAW) + just-in-time access + approval workflow + session recording + privileged credential vault + break-glass procedures + session monitoring + privileged session analytics + zero standing privilege + PEDM Privilege Elevation and Delegation Management. (4) Federation and Single Sign-On (SSO): SAML 2.0 + OAuth 2.0 + OpenID Connect (OIDC) + WS-Federation + federated identity with Japanese government IdP including Government Identity Verification Service + e-Tax Portal + Japan Digital Agency Identity + Cabinet Office identity infrastructure. (5) API Security and Access Tokens: OAuth 2.0 + JWT (JSON Web Tokens) + PASETO (Platform-Agnostic Security Tokens) + API gateway + rate limiting + token introspection + token revocation + scopes + audience + short-lived tokens + refresh token rotation + mutual TLS (mTLS) + API key management + signed requests + OAuth 2.0 PKCE for public clients. (6) My Number Card Integration: Japanese national ID card with PKI smart card + integration for government employee authentication + citizen-facing services + JPKI (Japanese Public Key Infrastructure) + government PKI hierarchy + supports digital signatures + identity verification + e-government services. (7) Government IAM Integration: J-LIS Japan Agency for Local Authority Information Systems + GIDV Government Identity Verification + e-Gov + Digital Agency identity infrastructure. (8) Zero Trust: per US NIST SP 800-207 Zero Trust Architecture + Japanese Digital Agency Zero Trust guidance + identity-aware proxies + microsegmentation + continuous verification + least privilege + assume breach. Coordinates with NIST SP 800-63 Digital Identity + JIS X 5051 + ISO 24760 IAM + FIDO Alliance + OAuth 2.0 + OIDC + SAML 2.0 + JPKI + Japan Digital Agency + Government PKI. ISMAP Identity + Access applies.
This control maps to 79 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 79 it maps to, and the evidence behind each claim, over MCP and REST.