AuditXYZ

Compliance Framework

Information Security Guidelines for Cloud Service Providers (Japan) (ISG)

Japan's Information Security Guidelines provide cloud security expectations for providers serving Japanese organizations. This guide covers the guidelines, ISMAP certification, and compliance for the Japanese market.

$20,000–$120,0003–9 months2024
Issuing BodyMinistry of Economy, Trade and Industry (METI) / Ministry of Internal Affairs and Communications (MIC)
First Published2014-04-01
Latest Version2024
Typical Cost$20,000–$120,000
Typical Timeline3–9 months
Audit RequiredNo
Audit FrequencyVoluntary compliance. ISMAP (government cloud marketplace) requires annual third-party audit for listed services.
Geographyjapan, asia-pacific

ISG: Japan Information Security Guidelines for Cloud

Japan's Information Security Guidelines for cloud service providers, jointly developed by METI and MIC, establish security expectations for cloud services operating in the Japanese market. These guidelines, supplemented by the ISMAP (Information system Security Management and Assessment Program) for government cloud procurement, form the framework for cloud security assurance in Japan — the world's third-largest cloud market. For cloud providers targeting Japanese enterprise and government customers, understanding the ISG and ISMAP ecosystem is essential.

What the Guidelines Are and Who Issues Them

Japan's cloud security guidelines emerged from a coordinated policy effort between METI (Ministry of Economy, Trade and Industry) and MIC (Ministry of Internal Affairs and Communications). The guidelines address the security responsibilities and expectations for cloud service providers operating in Japan, drawing on international standards — particularly ISO/IEC 27017 (cloud-specific extension of ISO 27001) and ISO/IEC 27018 (privacy protection for public cloud PII processing) — while incorporating Japan-specific regulatory requirements.

The guidelines operate alongside ISMAP (Information system Security Management and Assessment Program), a government-managed program launched in 2020. ISMAP creates a pre-assessed marketplace of cloud services approved for use by Japanese government agencies. Where the ISG provides general market guidance, ISMAP provides the formal certification mechanism that gates access to the Japanese government cloud market.

METI also maintains separate guidelines addressing security management for cloud users (as distinct from cloud providers), creating a comprehensive framework that addresses both sides of the shared responsibility model.

Who Should Follow These Guidelines

Cloud service providers targeting Japanese customers — particularly government agencies and regulated industries including finance, healthcare, and manufacturing — should align with these guidelines. ISMAP certification is effectively required for cloud services used by Japanese government agencies. The Digital Agency (established 2021) manages government cloud procurement and enforces ISMAP requirements across central government.

Japanese enterprises, particularly in manufacturing and financial services, increasingly reference these guidelines when evaluating cloud providers for sensitive workloads. Enterprise procurement security questionnaires in Japan frequently reference ISO 27017 and ISMAP status as key evaluation criteria.

Key Requirements: Security Domains and ISMAP Controls

The ISG addresses cloud-specific security considerations across several domains.

Governance and Accountability requires cloud providers to establish clear governance for information security, including executive accountability, information security policies, and a functioning security management system. Alignment with ISO 27001 is expected as the foundation.

Shared Responsibility Model requires providers to clearly document the division of security responsibilities between the provider and cloud customers, and to communicate these boundaries in service agreements and security documentation.

Data Location Transparency is a distinctly Japanese emphasis: providers must disclose where data is stored, processed, and backed up — including specific countries or regions — and must communicate any changes to data location. Japan's Act on the Protection of Personal Information (APPI) imposes specific requirements on cross-border data transfers that make location transparency legally significant.

Cross-Border Data Transfer Controls address the APPI requirements for transferring personal information outside Japan. Providers must have appropriate mechanisms in place — including customer consent, contractual protections equivalent to Japanese standards, or transfers to countries with equivalent protection levels.

Service Level Management requires documented SLAs with defined availability, performance, and response time commitments, backed by monitoring and reporting mechanisms that give customers visibility into service performance.

Incident Response and Notification requires breach detection capabilities and timely notification procedures. Japan's APPI (as amended in 2022) requires notification of personal information breaches to both the Personal Information Protection Commission (PPC) and affected individuals within 30 days — placing specific timelines on cloud provider incident response and notification procedures.

Supply Chain and Subcontractor Management requires providers to manage information security risks from subcontractors, including data center operators, network providers, and other third parties involved in cloud service delivery.

ISMAP-Specific Controls

ISMAP certification requires compliance with a detailed control set derived from ISO 27001, 27017, and 27018, supplemented by Japanese government-specific requirements. ISMAP-registered auditors assess providers against approximately 1,000 control items organized in categories aligned with the ISO 27000 series. Controls address all aspects of the ISG plus additional requirements around government data handling, incident reporting to government, and Japanese-language communication capabilities.

ISMAP-SaaS (a lighter variant launched in 2021) applies to SaaS services where the cloud infrastructure is provided by a separately ISMAP-assessed provider. This reduces the assessment scope for SaaS vendors building on ISMAP-certified IaaS/PaaS.

The Assessment and ISMAP Registration Process

For ISMAP registration, select a ISMAP-registered audit organization (listed on the ISMAP portal). Engage the auditor for a readiness assessment to identify gaps against the ISMAP control set. Implement required controls — organizations with existing ISO 27001, 27017, and 27018 certifications will find the gap significantly narrower.

The formal assessment involves document review and interviews with the registered auditor. The auditor prepares an assessment report, which the provider submits to the ISMAP management authority (the Digital Agency, Cabinet Secretariat, Ministry of Finance, and Ministry of Defense collectively manage ISMAP). After review, approved services are listed in the ISMAP cloud service list, which government agencies reference for procurement.

ISMAP registration requires annual reassessment by a registered auditor. Services that fail to maintain continuous compliance or undergo reassessment may be removed from the ISMAP list.

Costs and Timeline

ItemEstimated CostTimeline
ISG alignment assessment$5K–$15K1–2 months
ISO 27017/27018 alignment (if not certified)$20K–$60K3–6 months
ISMAP assessment by registered auditor$30K–$60K2–4 months
First-year total (ISMAP)$55K–$120K6–9 months
Annual ISMAP renewal$25K–$50KOngoing

The ISG maps most closely to ISO 27017 (approximately 80% overlap), making ISO 27017 certification the most efficient foundation for both ISG alignment and ISMAP certification. ISO 27001 (approximately 65% overlap) provides the underlying management system. CSA CCM alignment is approximately 55% — organizations using CCM as their cloud security framework can map significant portions of their controls to ISMAP requirements.

Singapore's MTCS serves a comparable purpose in the Singapore market, and organizations pursuing both Asian government markets often develop a unified compliance program around ISO 27001/27017 and CCM as the common foundation, extending to ISMAP and MTCS as country-specific layers.

How Automation Helps

ISMAP's approximately 1,000 control items and annual reassessment cycle create a substantial ongoing compliance operations burden. Automation is essential for maintaining the continuous evidence collection that annual reassessment requires.

LowerPlane supports ISMAP and ISO 27017 compliance as part of its 50+ framework library. Its continuous evidence collection from cloud environments maps to ISMAP control items, maintaining an always-current compliance posture rather than scrambling to prepare evidence at audit time. Starting at $4,000 per year with a free tier, LowerPlane makes annual ISMAP renewal significantly less operationally intensive. AuditXYZ rated LowerPlane 9.4/10 for compliance automation depth.

For cloud configuration security, TigerGate provides continuous posture management that maps to ISO 27017 cloud security controls — directly supporting the infrastructure security elements of ISMAP assessment.

Frequently Asked Questions

Is ISMAP required for all cloud services used by Japanese government? Yes, in practice. The Japanese government's cloud security policy requires that cloud services used by government agencies be listed on the ISMAP cloud service list. While there may be narrow exceptions for specific legacy systems or specialized use cases, new cloud service procurements by central government agencies are expected to use ISMAP-listed services.

Can we use an existing ISO 27001 certification to accelerate ISMAP registration? Yes. ISO 27001 certification is a significant accelerator, as many ISMAP control items align directly with ISO 27001 requirements. However, ISMAP-specific controls beyond ISO 27001 scope — particularly around cross-border data transfer, Japanese incident reporting timelines, and Japanese-language notification capabilities — require dedicated attention.

What is ISMAP-SaaS and is it easier to obtain? ISMAP-SaaS is a variant of ISMAP for SaaS services that run on cloud infrastructure already separately assessed under ISMAP. The SaaS assessment has a narrower scope (approximately 500 control items vs. 1,000+ for the full ISMAP), as infrastructure-level controls are inherited from the underlying IaaS/PaaS provider's ISMAP registration. SaaS vendors should evaluate ISMAP-SaaS if they build on an ISMAP-certified cloud platform.

Does the APPI 2022 amendment affect cloud provider obligations? Yes materially. The 2022 APPI amendment strengthened data breach notification requirements (mandatory notification within 30 days), tightened cross-border transfer rules, and expanded the category of sensitive personal information. Cloud providers handling personal data in Japan must ensure their incident response procedures, breach detection capabilities, and cross-border data transfer mechanisms comply with amended APPI requirements.

Is Japanese-language capability required for ISMAP? ISMAP assessments are conducted in Japanese, and incident notification to Japanese government customers and regulators is expected in Japanese. International cloud providers pursuing ISMAP typically engage Japanese security consultants and build Japanese-language communication capabilities into their incident response procedures.

Request a ISG consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27017High80%
ISO 27001Medium65%
CSA CCMMedium55%

Get matched with a ISG auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.