ISMAP Personnel + Resilience + Supply Chain controls extend security beyond own perimeter. (1) Personnel Security and Background Checks: per ISMAP requirements + tiered background checks for personnel with access to customer data + (a) Standard CSP employees - identity verification + employment history + reference check + credit check for financial roles; (b) Privileged personnel (administrators + developers with customer data access) - enhanced background check + criminal records check + foreign contacts disclosure + 5-year reinvestigation; (c) ISMAP-Critical tier personnel - Japanese national security check + critical infrastructure background + may require Japanese citizenship; (d) Foreign nationals - separate approval process + monitoring + restricted access + Japanese government clearance for ISMAP-Critical. Personnel training + Non-Disclosure Agreement (NDA) + security awareness annual training + role-based training + post-employment confidentiality + termination procedures (immediate access revocation + return of materials + exit interview + post-employment NDA reminder). (2) Business Continuity and Disaster Recovery: BCP per ISO 22301 BCMS + JIS Q 22301 + Business Impact Analysis (BIA) + RTO/RPO/MTPD per service + DR site geographic separation (different earthquake zone for Japan + different power grid + different communication backbone) + active-active or active-passive architecture + DR drills + tabletop + functional + full-scale + cross-regional cloud failover + ISMAP-Critical requires Japanese sovereign cloud DR + earthquake/tsunami resilience (Japan-specific seismic considerations + Tier IV data centre standards + Uptime Institute Tier IV + ANSI/TIA-942 Rated 4) + multi-region redundancy (typically AWS ap-northeast-1 Tokyo + ap-northeast-3 Osaka or equivalent Azure + GCP). (3) Supply Chain Risk Management: per ISO 28000 Supply Chain Security + NIST SP 800-161 SCRM + supplier due diligence + supplier security assessment + tiered classification (critical + significant + moderate + low) + ongoing monitoring + cyber security assessment + financial health + ESG/sustainability + concentration risk + geopolitical risk + Foreign Investment Promotion and Protection of National Security Act (FIPS Act) review for critical suppliers + Tier 2 and Tier 3 visibility + Software Bill of Materials (SBOM) + hardware component traceability + third party security assurance + ISMAP CSP supplier audit rights + termination contingency + exit strategy + repatriation. (4) Third Party and Subcontractor Flow-Down: ISMAP requirements MUST flow down to subcontractors handling Customer data + including (a) ISMAP equivalent controls; (b) audit rights for Programme Office and ISMAP auditor; (c) NISC reporting obligations; (d) data residency in Japan if subcontractor processes ISMAP-Critical data; (e) termination + return/deletion of data; (f) prior notification to customer of subcontractor changes; (g) Customer right to object to subcontractor; (h) Subcontractor list maintained and disclosed. (5) Critical Service Continuity: Critical Infrastructure Operator (CII) classification + Japanese Critical Infrastructure Protection (CIP) Plan + Cabinet Office Critical Infrastructure Cyber Defense + IPA Critical Infrastructure SHIENRETSU + sector-specific (Power + Gas + Water + Telecom + Finance + Healthcare + Transport + Government Information Systems). (6) Japanese Sovereignty Considerations: Japanese government cloud + Japan-only data residency for ISMAP-Critical + Japanese personnel for critical operations + Japan-based legal entity + Japanese legal jurisdiction + protection from foreign government access (US CLOUD Act + China Cybersecurity Law + Russia Federal Law on Personal Data Localisation + EU GDPR cross-border access). Coordinates with ISO 22301 BCMS + ISO 28000 SCS + NIST SP 800-161 SCRM + JIS Q 22301 + JIS Q 28000 + Japan FIPS Act + CII Plan + IPA SHIENRETSU + Uptime Institute Tier IV + ANSI/TIA-942. ISMAP Personnel + Resilience + Supply Chain applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.