ISMAP (Japan)
ISMAP Scope + 2020 Launch + Tri-Ministry Governance

ISMAP (Japan) ISMAP-Scope-2020Launch-MIC-METI-NISC-ISMAP-LIU-Standard-Critical-Tiers-CloudServiceList-Registration: ISMAP Scope + 2020 Launch + MIC/METI/NISC Tri-Ministry Governance + Cloud Service List + 3 Tiers (LIU + Standard + Critical) + ISMAP-LIU Simplified Assurance + Government Procurement Eligibility

Information system Security Management and Assessment Program (ISMAP) Japan - the Japanese government cloud security assessment program launched June 2020 (formal operations began 1 January 2021) + replaces older Common Cloud Procurement Guidelines + similar in concept to US FedRAMP + UK G-Cloud + Australia IRAP. Joint operation by Tri-Ministry governance structure: (1) Ministry of Internal Affairs and Communications (MIC / Soumu-sho) - administrative coordination + government information systems policy; (2) Ministry of Economy Trade and Industry (METI / Keizai Sangyo-sho) - cybersecurity industry policy + standardisation + international cooperation; (3) Cabinet Cybersecurity Center National center of Incident readiness and Strategy for Cybersecurity (NISC / Naikaku Saiba Sekyuriti Senta) - national cybersecurity strategy + incident response coordination. ISMAP Programme Office is operated by Information-technology Promotion Agency (IPA) Japan + IPA Software Engineering Center. Aim: ensure security of cloud services used by Japanese central government + local government + critical infrastructure operators through a standardised assessment program + Cloud Service Provider (CSP) registration on the ISMAP Cloud Service List. Government Procurement: Japanese government procurement of cloud services REQUIRES that the CSP be registered on the ISMAP Cloud Service List + with appropriate tier matching the data classification + similar to US FedRAMP Authorization to Operate (ATO) requirement. Three Assurance Tiers (since 2024 expansion): (1) ISMAP-LIU (Low Impact Use) - launched 2022 - simplified assurance for low-risk SaaS used by government for non-sensitive workflows (e.g. video conferencing + collaboration + simple workflow apps) + reduced control set + abbreviated assessment; (2) ISMAP-Standard - the original ISMAP baseline - comprehensive assurance for typical government cloud use covering normal data classifications + full control set ~1100+ controls inherited from ISO 27001 + ISO 27017 + NIST SP 800-53 + Japanese government cloud requirements; (3) ISMAP-Critical - launched 2024 - enhanced assurance for critical infrastructure cloud services + most sensitive government workloads + additional control enhancements + data residency restrictions + Japanese sovereign cloud requirements + critical infrastructure operator workloads. Cloud Service List (CSL): public registry at ismap.go.jp of all ISMAP-registered CSPs + tier + scope + assessment date + audit report + AWS Japan + Microsoft Azure Japan + Google Cloud Japan + Salesforce + Oracle Japan + IBM Cloud Japan + Fujitsu + NEC + NTT Communications + Yahoo Japan + many JP-based + foreign CSPs registered. Public + freely available via ismap.go.jp. Coordinates with US FedRAMP Low/Moderate/High + UK G-Cloud Digital Marketplace + Australia IRAP Information Security Registered Assessors Program + Singapore Multi-Tier Cloud Security (MTCS) + Korea K-FSI Korea Financial Security Institute Cloud Compliance + Hong Kong FSDM Financial Services Data Management + GCC GCC ESCRA Saudi + China MLPS Multi-Level Protection Scheme + India MeitY Empanelment for Government Departments + ISMS-AC Information Security Management System Accreditation Center + Japan JIS Q 27001 + JIS Q 27017 + JIS Q 27018 + JIS Q 27701. ISMAP Scope + 2020 Launch + Tri-Ministry + Tiers applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.