Scality Blog | Object storage, AI data infrastructure & cyber resilience

ISMAP and Cloud Storage in Japan: What It Means

Written by Joshua Silvia | Oct 5, 2026, 8:47:39 PM

A Japanese ministry wants to move a records system to the cloud. A SaaS company wants to sell to local governments. A domestic cloud provider wants its storage service on the government's approved list. In each case, the conversation turns quickly to ISMAP, Japan's security assessment program for cloud services used by the government. For providers and organizations designing storage in Japan, ISMAP shapes procurement, controls and documentation.

This article explains what ISMAP is, how the lighter ISMAP-LIU track works, who relies on it and what it means for the storage behind cloud services. It also touches on Japan's personal information law and broader data location considerations. It is part of our data sovereignty series; see also what SecNumCloud requires from storage and BSI C5 and storage for comparable schemes in France and Germany.

What ISMAP is

ISMAP, the Information system Security Management and Assessment Program, was established in 2020 to ensure the security level of cloud services procured by the Japanese government. Cloud service providers apply for registration, undergo an assessment of their controls by approved auditors and, once registered, appear on the ISMAP cloud service list. Government agencies use that list when procuring cloud services, in line with Japan's cloud-by-default policy for government systems.

The program is run under the national cybersecurity framework, with involvement from NISC, the Digital Agency and other ministries, and an operation support organization manages the registration portal. ISMAP control criteria draw on international information security management standards, adapted with Japanese government security requirements, and cover governance, management controls and detailed technical controls.

ISMAP-LIU for low-impact SaaS

Assessing every SaaS product to full ISMAP depth would slow adoption of smaller, lower-risk services. ISMAP-LIU, for low-impact use, provides a streamlined path for SaaS services handling lower-sensitivity information for low-risk business processes. According to the Digital Agency, ISMAP-LIU reduces the scope of annual external audits for certain governance and management controls, while requiring providers to conduct internal audits covering all control objectives within a defined period.

Who relies on ISMAP

  • Central government agencies, which use registered services when procuring cloud.
  • Local governments and public bodies, many of which reference ISMAP in their own procurement.
  • Regulated industries and enterprises, which increasingly use ISMAP registration as a signal of trustworthy cloud services.
  • Cloud and SaaS providers, for whom registration is often a prerequisite for public sector business.

What ISMAP means for storage

ISMAP registration applies to cloud services, not to individual storage products. But the storage behind a cloud service must support the controls assessed. For providers building services on their own storage, that typically means:

Access control and administration

Role-based administration, strong authentication, separation of duties and full logging of administrative actions on the storage platform.

Encryption and key management

Encryption of data at rest and in transit, with key management processes that the provider controls and can document.

Logging and monitoring

Detailed logs of data access and administrative events, exported to the provider's security monitoring and retained according to policy.

Data location transparency

Clear documentation of where data, replicas, backups and metadata are stored. Many Japanese public sector buyers prefer domestic data centers, and providers often commit to keeping data in Japan.

Resilience and recovery

Protection against hardware and site failures, backups and tested recovery procedures. Japan's exposure to earthquakes and other natural disasters makes geographic separation between sites particularly important.

Supplier management

Providers must manage risks from their own suppliers, including storage vendors' support access and software update processes.

Personal information and data location

Japan's Act on the Protection of Personal Information (APPI) governs personal data handled by businesses, including rules on providing personal data to third parties in foreign countries, with additional transparency requirements introduced in recent amendments. Storing personal data in domestic facilities simplifies compliance, and many organizations choose domestic hosting for sensitive data for reasons of control and public trust as well as law.

A storage checklist for ISMAP-oriented services

AreaWhat to verify in the storage platform
Access controlRole-based administration, strong authentication, separation of duties
EncryptionAt rest and in transit, provider-controlled keys
LoggingComplete, exportable, protected logs
LocationData, replicas, backups and metadata in documented locations, typically in Japan
ResilienceErasure coding, geographically separated sites, immutable copies
Supplier managementControlled vendor support, transparent update process

Designing for earthquakes and regional risks

Disaster recovery in Japan deserves particular attention. Sites should be far enough apart to avoid sharing seismic, tsunami and power grid risks, for example in different regions of the country, while keeping data within Japan. Object storage that spans or replicates between distant sites, with erasure coding inside each site, protects data against both local hardware failures and regional disasters. Test recovery between regions, not just within a single facility.

Preparing for an ISMAP assessment: the storage team's part

Assessors examine whether controls are designed appropriately and operating as described. For the storage layer of a cloud service, useful preparation includes:

  • Architecture documentation showing sites, data flows, tenant separation and management interfaces.
  • Access lists and reviews for storage administrators, with evidence of periodic review and removal of unneeded access.
  • Configuration evidence for encryption, key management, replication and immutability.
  • Log samples and retention settings demonstrating that administrative and access events are captured, protected and monitored.
  • Change management records for storage upgrades and configuration changes.
  • Recovery test results, including tests between geographically separated sites.
  • Vendor management records describing how the storage vendor provides support and updates.

Collecting this evidence continuously, through APIs and automated reports, avoids last-minute effort before each audit.

Serving local governments and the wider public sector

Beyond central government, Japan's local governments are modernizing their systems and moving toward standardized, cloud-based platforms. Many of them follow national security guidelines and look to ISMAP registration when selecting services. Providers serving this market often need multi-tenant storage that separates each municipality's data, keeps it in Japan and supports long retention for administrative records. Object storage with per-tenant accounts, policies and encryption fits this pattern well.

Common gaps

  • Shared administrator accounts that prevent individual accountability.
  • Incomplete logging of administrative actions on storage.
  • Disaster recovery sites too close together to survive a regional event.
  • Unclear documentation of where replicas, backups and metadata are stored.
  • Vendor support access that is not controlled or logged.

How Scality fits

Scality RING and ARTESCA are software-defined object storage platforms that run on infrastructure chosen and operated by the provider or organization, without dependence on foreign cloud services. They can be deployed across multiple sites in Japan, providing S3-compatible access, erasure coding, compliance-mode object lock, encryption, multi-tenancy, role-based administration and audit logging. Cloud providers and public organizations can use them as the storage layer for services designed to support ISMAP controls and domestic data location commitments. Registration applies to the provider's service as a whole.

Questions to ask a storage vendor

  • Can the platform run fully on our infrastructure in Japan, with no mandatory external services?
  • How are tenants separated, and how can we demonstrate isolation to assessors?
  • What encryption and key management options are available?
  • Which logs are produced, and how are they exported to our monitoring?
  • How is support delivered, and can remote access be controlled and logged?
  • How does the platform replicate or distribute data between distant sites?

Keeping the evidence current

Registration is not a one-time event. Annual audits and ongoing changes mean evidence must stay up to date. Review storage access, configurations and recovery tests on a regular schedule so the next audit confirms what is already known.

Ransomware resilience

Public sector systems are frequent ransomware targets. Keep immutable copies with compliance-mode object lock, separate storage credentials from directory accounts and test restores regularly.

Putting it together

ISMAP is Japan's gateway for cloud services in government procurement, with ISMAP-LIU providing a lighter path for low-impact SaaS. Storage is not registered on its own, but it carries many of the controls assessors examine: access control, encryption, logging, data location, resilience and supplier management. Domestic hosting, geographically separated sites and storage that runs fully under the provider's control make those requirements easier to meet.

Frequently asked questions

What is ISMAP?

The Information system Security Management and Assessment Program, Japan's security assessment and registration program for cloud services procured by the government.

What is ISMAP-LIU?

A streamlined track for low-impact SaaS services handling lower-sensitivity information, with a reduced external audit scope.

Does storage need ISMAP registration?

No. ISMAP registration applies to cloud services. The storage platform must support the provider's controls.

Must government data in Japan stay in Japan?

Requirements depend on the system and agency, but domestic hosting is widely preferred, and many providers commit to keeping data in Japan.

How does APPI affect cloud storage?

APPI sets rules on handling personal data, including providing it to third parties abroad. Domestic storage simplifies compliance.

Further reading

Related reading