The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM). (1) NIST CSF 2.0 Alignment - 6 Functions: (a) GOVERN (added in 2.0) - cybersecurity governance + risk management + organizational context + policy; (b) IDENTIFY - asset management + business environment + risk assessment + risk management strategy; (c) PROTECT - identity management + awareness + data security + protective technology; (d) DETECT - anomalies + continuous monitoring + detection processes; (e) RESPOND - response planning + communications + analysis + mitigation; (f) RECOVER - recovery planning + improvements + communications. (2) ISO/IEC 27001 ISMS Integration: (a) Information Security Management System scope including cybersecurity; (b) ISO 27001 Annex A controls (now 93 in 2022 revision); (c) Statement of Applicability; (d) Risk Treatment Plan; (e) Internal Audit + Management Review + Continuous Improvement; (f) ISMS Certification through accredited body (gaining traction). (3) FFIEC IT Examination Handbook - 11 Booklets: (a) Information Security; (b) Business Continuity Management; (c) Operations; (d) Architecture, Infrastructure, and Operations; (e) Audit; (f) Development and Acquisition; (g) Management; (h) Outsourcing Technology Services; (i) Retail Payment Systems; (j) Supervision of Technology Service Providers; (k) Wholesale Payment Systems; (l) Used by FSA inspectors as reference. (4) Risk Assessment Methodology: (a) Asset Identification + Crown Jewels (data + systems + processes); (b) Threat Modelling per asset (STRIDE + MITRE ATT and CK + Japanese threat landscape); (c) Vulnerability Assessment + Penetration Testing; (d) Likelihood Estimation (historical + threat intel + indicators); (e) Impact Assessment (financial + operational + reputational + regulatory); (f) Inherent Risk Rating; (g) Control Assessment; (h) Residual Risk Rating; (i) Risk Acceptance or Treatment decision. (5) Risk Appetite + Tolerance: (a) Board-approved Risk Appetite Statement (RAS) including cyber risk dimensions; (b) Risk Tolerance limits per risk type; (c) Key Risk Indicators (KRIs) for cyber + dashboards; (d) Risk Limit Breach escalation; (e) Risk Appetite review annually + on material changes; (f) Risk Capacity vs Appetite. (6) Risk Treatment Options: (a) Accept - within risk appetite + documented decision; (b) Avoid - cease activity + change architecture; (c) Mitigate - implement controls + reduce likelihood/impact; (d) Transfer - cyber insurance + outsourcing risk; (e) Per-Risk treatment decision documented + reviewed. (7) Enterprise Risk Management Integration: (a) Cyber risk as principal risk in ERM taxonomy; (b) Cyber risk reporting in Board ERM dashboard; (c) Cyber risk in Internal Capital Adequacy Assessment Process (ICAAP) where applicable; (d) Operational risk + cyber risk overlap (Basel II/III operational risk); (e) Cyber as systemic risk for D-SIFIs Domestic Systemically Important Financial Institutions. (8) Threat Intelligence-Driven Risk: (a) Threat intelligence sources - FS-ISAC Japan + Japan CSIRT Council + JPCERT/CC + FISC + commercial; (b) Threat-Informed risk assessment; (c) Threat actor capability + intent + targeting analysis; (d) Adversarial emulation in risk testing; (e) Cyber Kill Chain + MITRE ATT and CK frameworks. (9) Risk Quantification + FAIR Methodology: (a) Factor Analysis of Information Risk (FAIR) emerging in Japanese banks; (b) Monte Carlo simulation for tail risk; (c) Annual Loss Expectancy (ALE); (d) Cyber Value at Risk (CyVAR); (e) Capital allocation for cyber risk. (10) Sector-Specific Risk Considerations: (a) Banking - Customer payment + ATM + Internet banking + Card; (b) Insurance - Customer data + Actuarial + Claims; (c) Securities - Trading + Market access + Algorithmic; (d) Asset Management - Custody + Investment management + Settlement; (e) Cryptoasset Exchange - Wallet security + Cold/Hot storage + Smart contract risk + Bridge security. (11) Continuous Improvement: (a) Plan-Do-Check-Act ISMS cycle; (b) Quarterly risk review; (c) Annual risk reassessment + on material change; (d) Lessons learned from incidents + near-misses; (e) Industry benchmarking + peer comparison; (f) Regulatory feedback integration. Coordinates with NIST CSF 2.0 + ISO/IEC 27001/27002/27005 + FFIEC IT Examination Handbook + FAIR Factor Analysis of Information Risk + MITRE ATT and CK + Cyber Kill Chain + Basel II/III Operational Risk + Solvency II for insurers + FSB Financial Stability Board + BCBS Basel Committee + CPMI-IOSCO + G7 Fundamental Elements + APPI + FISC Security Guidelines + sector-specific (Banking/Insurance/Securities/Asset Management). Japan FSA Cybersecurity Risk Management applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.