// Cloud
ISMAP Compliance Software
Japan's government cloud service security assessment program.
Framework at a glance
Short name
ISMAP
Version
2024
Category
Cloud
Controls
44
What ISMAP covers
44 controls across 8 domains — every one tracked, owned and evidenced in Cyber Horizon.
Governance Criteria (ISO/IEC 27014)
4 controls- GOV-1 Direction of Information Security
- GOV-2 Alignment with Business Objectives
- GOV-3 Oversight and Assurance
- GOV-4 Resourcing and Accountability
Management Criteria (ISO/IEC 27001)
8 controls- MGT-1 ISMS Context and Scope
- MGT-2 Leadership and Security Policy
- MGT-3 Information Security Risk Assessment
- MGT-4 Risk Treatment and Statement of Applicability
- MGT-5 Resources, Competence and Awareness
Security Control Baseline: Organisational Measures
10 controls- ORG-1 Information Security Policies
- ORG-2 Roles, Responsibilities and Segregation of Duties
- ORG-3 Supplier and Cloud Service Provider Management
- ORG-4 Asset Management and Acceptable Use
- ORG-5 Information Classification and Handling
Security Control Baseline: People Measures
3 controls- PPL-1 Screening and Terms of Employment
- PPL-2 Security Awareness, Education and Training
- PPL-3 Disciplinary Process and Post-Employment Responsibilities
Security Control Baseline: Physical Measures
2 controls- PHY-1 Physical Security Perimeters and Entry
- PHY-2 Equipment and Environmental Protection
Security Control Baseline: Operational Measures
6 controls- OPS-1 Operating Procedures and Change Management
- OPS-2 Protection Against Malware
- OPS-3 Backup
- OPS-4 Logging and Monitoring
- OPS-5 Vulnerability and Patch Management
Security Control Baseline: Technical Measures
7 controls- TEC-1 Identity and Authentication Management
- TEC-2 Privileged Access Management
- TEC-3 Cryptography and Key Management
- TEC-4 Network Security and Segregation
- TEC-5 Secure Configuration
Cloud Service Controls (ISO/IEC 27017)
4 controls- CLD-1 Segregation in Multi-Tenant Environments
- CLD-2 Virtual Environment Hardening
- CLD-3 Administrator Operations Monitoring
- CLD-4 Return and Removal of Customer Assets
How Cyber Horizon automates ISMAP
Every ISMAP control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISMAP?
Japan's government cloud service security assessment program.
How many controls does ISMAP have?
ISMAP (2024) has 44 controls in Cyber Horizon's catalogue, organised across 8 domains.
How does Cyber Horizon help with ISMAP?
Cyber Horizon maps ISMAP into a shared control library alongside every other framework you run, so evidence collected once counts towards ISMAP and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Cloud frameworks
See ISMAP mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISMAP in Cyber Horizon.