A Japanese ministry wants to move a records system to the cloud. A SaaS company wants to sell to local governments. A domestic cloud provider wants its storage service on the government's approved list. In each case, the conversation turns quickly to ISMAP, Japan's security assessment program for cloud services used by the government. For providers and organizations designing storage in Japan, ISMAP shapes procurement, controls and documentation.
This article explains what ISMAP is, how the lighter ISMAP-LIU track works, who relies on it and what it means for the storage behind cloud services. It also touches on Japan's personal information law and broader data location considerations. It is part of our data sovereignty series; see also what SecNumCloud requires from storage and BSI C5 and storage for comparable schemes in France and Germany.
ISMAP, the Information system Security Management and Assessment Program, was established in 2020 to ensure the security level of cloud services procured by the Japanese government. Cloud service providers apply for registration, undergo an assessment of their controls by approved auditors and, once registered, appear on the ISMAP cloud service list. Government agencies use that list when procuring cloud services, in line with Japan's cloud-by-default policy for government systems.
The program is run under the national cybersecurity framework, with involvement from NISC, the Digital Agency and other ministries, and an operation support organization manages the registration portal. ISMAP control criteria draw on international information security management standards, adapted with Japanese government security requirements, and cover governance, management controls and detailed technical controls.
Assessing every SaaS product to full ISMAP depth would slow adoption of smaller, lower-risk services. ISMAP-LIU, for low-impact use, provides a streamlined path for SaaS services handling lower-sensitivity information for low-risk business processes. According to the Digital Agency, ISMAP-LIU reduces the scope of annual external audits for certain governance and management controls, while requiring providers to conduct internal audits covering all control objectives within a defined period.
ISMAP registration applies to cloud services, not to individual storage products. But the storage behind a cloud service must support the controls assessed. For providers building services on their own storage, that typically means:
Role-based administration, strong authentication, separation of duties and full logging of administrative actions on the storage platform.
Encryption of data at rest and in transit, with key management processes that the provider controls and can document.
Detailed logs of data access and administrative events, exported to the provider's security monitoring and retained according to policy.
Clear documentation of where data, replicas, backups and metadata are stored. Many Japanese public sector buyers prefer domestic data centers, and providers often commit to keeping data in Japan.
Protection against hardware and site failures, backups and tested recovery procedures. Japan's exposure to earthquakes and other natural disasters makes geographic separation between sites particularly important.
Providers must manage risks from their own suppliers, including storage vendors' support access and software update processes.
Japan's Act on the Protection of Personal Information (APPI) governs personal data handled by businesses, including rules on providing personal data to third parties in foreign countries, with additional transparency requirements introduced in recent amendments. Storing personal data in domestic facilities simplifies compliance, and many organizations choose domestic hosting for sensitive data for reasons of control and public trust as well as law.
| Area | What to verify in the storage platform |
|---|---|
| Access control | Role-based administration, strong authentication, separation of duties |
| Encryption | At rest and in transit, provider-controlled keys |
| Logging | Complete, exportable, protected logs |
| Location | Data, replicas, backups and metadata in documented locations, typically in Japan |
| Resilience | Erasure coding, geographically separated sites, immutable copies |
| Supplier management | Controlled vendor support, transparent update process |
Disaster recovery in Japan deserves particular attention. Sites should be far enough apart to avoid sharing seismic, tsunami and power grid risks, for example in different regions of the country, while keeping data within Japan. Object storage that spans or replicates between distant sites, with erasure coding inside each site, protects data against both local hardware failures and regional disasters. Test recovery between regions, not just within a single facility.
Assessors examine whether controls are designed appropriately and operating as described. For the storage layer of a cloud service, useful preparation includes:
Collecting this evidence continuously, through APIs and automated reports, avoids last-minute effort before each audit.
Beyond central government, Japan's local governments are modernizing their systems and moving toward standardized, cloud-based platforms. Many of them follow national security guidelines and look to ISMAP registration when selecting services. Providers serving this market often need multi-tenant storage that separates each municipality's data, keeps it in Japan and supports long retention for administrative records. Object storage with per-tenant accounts, policies and encryption fits this pattern well.
Scality RING and ARTESCA are software-defined object storage platforms that run on infrastructure chosen and operated by the provider or organization, without dependence on foreign cloud services. They can be deployed across multiple sites in Japan, providing S3-compatible access, erasure coding, compliance-mode object lock, encryption, multi-tenancy, role-based administration and audit logging. Cloud providers and public organizations can use them as the storage layer for services designed to support ISMAP controls and domestic data location commitments. Registration applies to the provider's service as a whole.
Registration is not a one-time event. Annual audits and ongoing changes mean evidence must stay up to date. Review storage access, configurations and recovery tests on a regular schedule so the next audit confirms what is already known.
Public sector systems are frequent ransomware targets. Keep immutable copies with compliance-mode object lock, separate storage credentials from directory accounts and test restores regularly.
ISMAP is Japan's gateway for cloud services in government procurement, with ISMAP-LIU providing a lighter path for low-impact SaaS. Storage is not registered on its own, but it carries many of the controls assessors examine: access control, encryption, logging, data location, resilience and supplier management. Domestic hosting, geographically separated sites and storage that runs fully under the provider's control make those requirements easier to meet.
The Information system Security Management and Assessment Program, Japan's security assessment and registration program for cloud services procured by the government.
A streamlined track for low-impact SaaS services handling lower-sensitivity information, with a reduced external audit scope.
No. ISMAP registration applies to cloud services. The storage platform must support the provider's controls.
Requirements depend on the system and agency, but domestic hosting is widely preferred, and many providers commit to keeping data in Japan.
APPI sets rules on handling personal data, including providing it to third parties abroad. Domestic storage simplifies compliance.