Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control. (1) Workforce IAM: (a) Identity Lifecycle Management - joiner-mover-leaver process; (b) Single Sign-On (SSO) + SAML 2.0 + OIDC; (c) Multi-Factor Authentication (MFA) mandatory for all + especially privileged; (d) Role-Based Access Control (RBAC) + Attribute-Based (ABAC); (e) Least Privilege + Need-to-Know; (f) Quarterly Access Recertification; (g) Segregation of Duties; (h) Identity Federation across multi-cloud + hybrid. (2) Privileged Access Management (PAM): (a) Privileged Account Inventory; (b) Vault + Secret Management; (c) Just-In-Time (JIT) provisioning replacing standing privileges; (d) Session Recording + Monitoring; (e) Break-Glass procedures; (f) Privileged Session Management (PSM); (g) Workstation isolation for admins; (h) Dedicated Admin Accounts + Tier 0/1/2 separation; (i) PAM solutions (CyberArk + BeyondTrust + Delinea + Microsoft PAM + cloud-native). (3) Zero Trust Architecture: (a) NIST SP 800-207 Zero Trust Architecture; (b) Never trust always verify; (c) Continuous authentication + authorisation; (d) Microsegmentation; (e) Encrypted East-West traffic; (f) ZTNA Zero Trust Network Access replacing VPN; (g) SASE Secure Access Service Edge; (h) Beyond Corp (Google) + similar architectures; (i) Migration from perimeter-based to identity-based. (4) Banking Customer Authentication - Internet Banking: (a) Japanese Internet Banking Standards (e-banking Authentication Guidelines); (b) Multi-Factor Authentication for transactions; (c) Out-of-Band Authentication (OOBA) - SMS + voice + mobile app; (d) Token-based (hardware + software OTP); (e) Smart card + IC chip (Japan eID + Personal Number Card); (f) Biometric - fingerprint + face + voice + behavioural; (g) FIDO2 WebAuthn + Passkeys (gaining traction in Japanese banks 2024-2025); (h) Risk-Based Authentication (RBA) with device fingerprinting + IP reputation + behavioural analytics; (i) Transaction Risk Analysis (TRA) per SCA Strong Customer Authentication concept (similar to PSD2 in EU). (5) Mobile Banking Authentication: (a) Device binding + attestation; (b) Mobile App MFA - biometric + PIN; (c) FIDO2 in mobile apps; (d) Out-of-band confirmation; (e) Behavioural biometrics; (f) App attestation (SafetyNet + DeviceCheck). (6) ATM + Card Authentication: (a) EMV chip + PIN; (b) Contactless + NFC + tokenisation; (c) 3D Secure 2.0 for online card transactions; (d) Biometric ATM cards (fingerprint); (e) Card-not-present additional authentication. (7) Authorised Push Payment (APP) Fraud Controls: (a) Confirmation of Payee (Japan equivalent emerging); (b) Real-Time Payment Risk Engine; (c) Behavioural analysis + anomaly detection; (d) Customer alerts + holds + step-up authentication; (e) FSA + Japan Bankers Association cooperation; (f) Recovery procedures for APP fraud victims. (8) Service Account + Machine Identity: (a) Service Account inventory + ownership; (b) Certificate-based authentication; (c) Workload Identity (SPIFFE + SPIRE); (d) Cloud-native identity (AWS IAM Roles + Azure Managed Identity + GCP Workload Identity); (e) Key Vault + secrets rotation; (f) Mutual TLS for service-to-service. (9) Customer Identity and Access Management (CIAM): (a) Self-Service Registration + Account Recovery; (b) Progressive Profiling; (c) Consent Management (APPI compliance); (d) Federated Identity (corporate + government); (e) Social Login (limited in Japan + Yahoo Japan + LINE common); (f) Customer Risk Profile + Adaptive MFA. (10) FISC Security Guidelines IAM Specifications: (a) FISC Computer System Security Guidelines for IAM in financial institutions; (b) Specific technical baselines; (c) Internet Banking Customer Authentication baseline; (d) Periodic FISC Working Group updates. (11) APPI Integration: (a) Customer consent for data access; (b) Right to access disclosure (APPI Article 21); (c) Right to human review for automated decisions (APPI Article 21-2); (d) Personal Information Identifier protection. Coordinates with NIST SP 800-63 Digital Identity + NIST SP 800-207 Zero Trust + ISO/IEC 24760 Identity Framework + FIDO Alliance specifications + W3C WebAuthn + OAuth 2.0 + OpenID Connect + SAML 2.0 + Japan Internet Banking Authentication Guidelines + FISC Security Guidelines + APPI + 3D Secure 2.0 + EMVCo + Confirmation of Payee + PSD2 SCA reference + EU eIDAS + Japan Personal Number Card (My Number Card). Japan FSA Cybersecurity IAM applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.