← Frameworks / FISC Security Guidelines / Control Mappings

FISC Security Guidelines on Computer Systems for Financial Institutions

Japan's de facto mandatory security standard for financial institutions, published by the Center for Financial Industry Information Systems (FISC). Covers technical standards (system design, access control, cryptography, network security), operational standards (IT governance, incident response, outsourcing, SDLC), and facility standards (data center physical security, environmental controls, disaster recovery). Referenced by the FSA and Bank of Japan for supervisory examinations.

AC Access Control

Control Name FISC Security Guidelines References
AC-01 Policy and Procedures
FISC.T2
AC-02 Account Management
FISC.T2
AC-03 Access Enforcement
FISC.T2FISC.T5FISC.T11
AC-04 Information Flow Enforcement
FISC.T2FISC.T3FISC.T5FISC.T8FISC.T13
AC-05 Separation of Duties
FISC.T2
AC-06 Least Privilege
FISC.T2
AC-07 Unsuccessful Logon Attempts
FISC.T2
AC-08 System Use Notification
FISC.T2
AC-10 Concurrent Session Control
FISC.T2
AC-11 Device Lock
FISC.T2
AC-12 Session Termination
FISC.T2
AC-13 Supervision and Review — Access Control
FISC.T2
AC-16 Security and Privacy Attributes
FISC.O9FISC.T5
AC-17 Remote Access
FISC.T3FISC.T8FISC.T10
AC-18 Wireless Access
FISC.T3FISC.T10
AC-19 Access Control for Mobile Devices
FISC.T10
AC-20 Use of External Systems
FISC.O6FISC.T9FISC.T13
AC-24 Access Control Decisions
FISC.T2

AT Awareness and Training

Control Name FISC Security Guidelines References
AT-01 Policy and Procedures
FISC.O8
AT-02 Literacy Training and Awareness
FISC.O8
AT-03 Role-based Training
FISC.O8
AT-04 Training Records
FISC.O8
AT-06 Training Feedback
FISC.O8

AU Audit and Accountability

Control Name FISC Security Guidelines References
AU-01 Policy and Procedures
FISC.O7FISC.O11
AU-02 Event Logging
FISC.O2FISC.O7FISC.O11FISC.T11
AU-03 Content of Audit Records
FISC.O2FISC.O11
AU-04 Audit Log Storage Capacity
FISC.O11FISC.O13
AU-05 Response to Audit Logging Process Failures
FISC.O11
AU-06 Audit Record Review, Analysis, and Reporting
FISC.O2FISC.O11
AU-07 Audit Record Reduction and Report Generation
FISC.O11
AU-08 Time Stamps
FISC.O11
AU-09 Protection of Audit Information
FISC.O11
AU-10 Non-repudiation
FISC.O11FISC.T11FISC.T12
AU-11 Audit Record Retention
FISC.O7FISC.O11
AU-12 Audit Record Generation
FISC.O2

CA Security Assessment and Authorization

Control Name FISC Security Guidelines References
CA-01 Policy and Procedures
FISC.O7
CA-02 Control Assessments
FISC.O7
CA-03 Information Exchange
FISC.O6FISC.T3FISC.T9FISC.T13
CA-05 Plan of Action and Milestones
FISC.O7
CA-07 Continuous Monitoring
FISC.O2FISC.O7
CA-09 Internal System Connections
FISC.T3FISC.T9FISC.T13

CM Configuration Management

Control Name FISC Security Guidelines References
CM-01 Policy and Procedures
FISC.O3
CM-02 Baseline Configuration
FISC.O3FISC.O13FISC.T7FISC.T14
CM-03 Configuration Change Control
FISC.O3FISC.O12
CM-04 Impact Analyses
FISC.O3
CM-05 Access Restrictions for Change
FISC.O3
CM-06 Configuration Settings
FISC.O3FISC.T7FISC.T14
CM-07 Least Functionality
FISC.T7FISC.T14
CM-08 System Component Inventory
FISC.O9FISC.O13FISC.T7
CM-09 Configuration Management Plan
FISC.O3
CM-12 Information Location
FISC.O9FISC.T5
CM-13 Data Action Mapping
FISC.O9FISC.T5
CM-14 Signed Components
FISC.O3FISC.T6

CP Contingency Planning

Control Name FISC Security Guidelines References
CP-01 Policy and Procedures
FISC.O5
CP-02 Contingency Plan
FISC.O5
CP-03 Contingency Training
FISC.O5
CP-04 Contingency Plan Testing
FISC.O5
CP-05 Contingency Plan Update
FISC.O5
CP-06 Alternate Storage Site
FISC.F5FISC.O5
CP-07 Alternate Processing Site
FISC.F5FISC.O5
CP-08 Telecommunications Services
FISC.F5FISC.O5
CP-09 System Backup
FISC.O5
CP-10 System Recovery and Reconstitution
FISC.O5

IA Identification and Authentication

Control Name FISC Security Guidelines References
IA-01 Policy and Procedures
FISC.T2
IA-02 Identification and Authentication (Organizational Users)
FISC.T2FISC.T10FISC.T11
IA-04 Identifier Management
FISC.T2
IA-05 Authenticator Management
FISC.T2FISC.T10
IA-06 Authentication Feedback
FISC.T2
IA-07 Cryptographic Module Authentication
FISC.T4
IA-08 Identification and Authentication (Non-organizational Users)
FISC.T2
IA-12 Identity Proofing
FISC.T2

IR Incident Response

Control Name FISC Security Guidelines References
IR-01 Policy and Procedures
FISC.O4
IR-02 Incident Response Training
FISC.O4
IR-03 Incident Response Testing
FISC.O4
IR-04 Incident Handling
FISC.O4
IR-05 Incident Monitoring
FISC.O4
IR-06 Incident Reporting
FISC.O4
IR-07 Incident Response Assistance
FISC.O4
IR-08 Incident Response Plan
FISC.O4
IR-09 Information Spillage Response
FISC.O4

MA Maintenance

Control Name FISC Security Guidelines References
MA-01 Policy and Procedures
FISC.F3
MA-02 Controlled Maintenance
FISC.F3FISC.O13
MA-03 Maintenance Tools
FISC.F3
MA-04 Nonlocal Maintenance
FISC.F3
MA-05 Maintenance Personnel
FISC.F3
MA-06 Timely Maintenance
FISC.F3
MA-07 Field Maintenance
FISC.F3

MP Media Protection

Control Name FISC Security Guidelines References
MP-01 Policy and Procedures
FISC.F4FISC.O9FISC.T5
MP-02 Media Access
FISC.F4FISC.T5
MP-03 Media Marking
FISC.F4FISC.O9
MP-04 Media Storage
FISC.F4
MP-05 Media Transport
FISC.F4
MP-06 Media Sanitization
FISC.F4FISC.O9
MP-07 Media Use
FISC.F4
MP-08 Media Downgrading
FISC.F4FISC.O9

PE Physical and Environmental Protection

Control Name FISC Security Guidelines References
PE-01 Policy and Procedures
FISC.F1
PE-02 Physical Access Authorizations
FISC.F1
PE-03 Physical Access Control
FISC.F1
PE-04 Access Control for Transmission
FISC.F1
PE-05 Access Control for Output Devices
FISC.F1
PE-06 Monitoring Physical Access
FISC.F1
PE-07 Visitor Control
FISC.F1
PE-08 Visitor Access Records
FISC.F1
PE-09 Power Equipment and Cabling
FISC.F2
PE-10 Emergency Shutoff
FISC.F2
PE-11 Emergency Power
FISC.F2
PE-12 Emergency Lighting
FISC.F2
PE-13 Fire Protection
FISC.F2
PE-14 Environmental Controls
FISC.F2
PE-15 Water Damage Protection
FISC.F2
PE-16 Delivery and Removal
FISC.F3
PE-17 Alternate Work Site
FISC.F5
PE-18 Location of System Components
FISC.F1
PE-19 Information Leakage
FISC.F1
PE-21 Electromagnetic Pulse Protection
FISC.F2
PE-22 Component Marking
FISC.F1
PE-23 Facility Location
FISC.F5

PL Planning

Control Name FISC Security Guidelines References
PL-01 Policy and Procedures
FISC.O1FISC.T1
PL-02 System Security and Privacy Plans
FISC.T1
PL-06 Security-related Activity Planning
FISC.T1
PL-09 Central Management
FISC.O1FISC.T1
PL-10 Baseline Selection
FISC.T1
PL-11 Baseline Tailoring
FISC.T1

PM Program Management

Control Name FISC Security Guidelines References
PM-01 Information Security Program Plan
FISC.O1
PM-02 Information Security Program Leadership Role
FISC.O1
PM-03 Information Security and Privacy Resources
FISC.O1
PM-04 Plan of Action and Milestones Process
FISC.O1
PM-05 System Inventory
FISC.O1
PM-06 Measures of Performance
FISC.O7
PM-09 Risk Management Strategy
FISC.O1
PM-14 Testing, Training, and Monitoring
FISC.O7
PM-28 Risk Framing
FISC.O1

PS Personnel Security

Control Name FISC Security Guidelines References
PS-01 Policy and Procedures
FISC.O8
PS-02 Position Risk Designation
FISC.O8
PS-03 Personnel Screening
FISC.O8
PS-04 Personnel Termination
FISC.O8
PS-05 Personnel Transfer
FISC.O8
PS-06 Access Agreements
FISC.O8
PS-07 External Personnel Security
FISC.O6FISC.O8
PS-08 Personnel Sanctions
FISC.O8
PS-09 Position Descriptions
FISC.O8

RA Risk Assessment

Control Name FISC Security Guidelines References
RA-01 Policy and Procedures
FISC.O1
RA-02 Security Categorization
FISC.O9
RA-03 Risk Assessment
FISC.O1
RA-05 Vulnerability Monitoring and Scanning
FISC.O12
RA-07 Risk Response
FISC.O1FISC.O12
RA-09 Criticality Analysis
FISC.O1

SA System and Services Acquisition

Control Name FISC Security Guidelines References
SA-02 Allocation of Resources
FISC.T1
SA-03 System Development Life Cycle
FISC.O10FISC.T1FISC.T6
SA-04 Acquisition Process
FISC.O6FISC.O10FISC.T6FISC.T9
SA-08 Security and Privacy Engineering Principles
FISC.O10FISC.O13FISC.T1FISC.T6
SA-09 External System Services
FISC.O6FISC.T9
SA-10 Developer Configuration Management
FISC.O3FISC.O10FISC.T6
SA-11 Developer Testing and Evaluation
FISC.O10FISC.T6
SA-15 Development Process, Standards, and Tools
FISC.O10FISC.T6
SA-16 Developer-provided Training
FISC.O10FISC.T6
SA-17 Developer Security and Privacy Architecture and Design
FISC.O10FISC.T1FISC.T6
SA-20 Customized Development of Critical Components
FISC.O10FISC.T6
SA-21 Developer Screening
FISC.O6FISC.O10
SA-23 Specialization
FISC.O6

SC System and Communications Protection

Control Name FISC Security Guidelines References
SC-02 Separation of System and User Functionality
FISC.T3FISC.T14
SC-03 Security Function Isolation
FISC.T3FISC.T14
SC-04 Information in Shared System Resources
FISC.T5
SC-05 Denial-of-service Protection
FISC.T3
SC-06 Resource Availability
FISC.O13
SC-07 Boundary Protection
FISC.T3FISC.T8FISC.T9FISC.T10FISC.T11FISC.T13
SC-08 Transmission Confidentiality and Integrity
FISC.T4FISC.T8FISC.T10FISC.T11FISC.T12
SC-12 Cryptographic Key Establishment and Management
FISC.T4FISC.T11FISC.T12
SC-13 Cryptographic Protection
FISC.T4FISC.T8FISC.T11FISC.T12
SC-16 Transmission of Security and Privacy Attributes
FISC.T12
SC-17 Public Key Infrastructure Certificates
FISC.T4
SC-18 Mobile Code
FISC.T8
SC-20 Secure Name/Address Resolution Service (Authoritative Source)
FISC.T3
SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
FISC.T3
SC-22 Architecture and Provisioning for Name/Address Resolution Service
FISC.T3
SC-23 Session Authenticity
FISC.T8FISC.T12
SC-24 Fail in Known State
FISC.O5
SC-28 Protection of Information at Rest
FISC.T4FISC.T5
SC-34 Non-modifiable Executable Programs
FISC.T7
SC-39 Process Isolation
FISC.T14
SC-40 Wireless Link Protection
FISC.T4FISC.T10
SC-46 Cross Domain Policy Enforcement
FISC.T3FISC.T13
SC-47 Alternate Communications Paths
FISC.T3FISC.T13
SC-48 Sensor Relocation
FISC.O2

SI System and Information Integrity

Control Name FISC Security Guidelines References
SI-02 Flaw Remediation
FISC.O12FISC.T7
SI-03 Malicious Code Protection
FISC.T7FISC.T14
SI-04 System Monitoring
FISC.O2FISC.O4
SI-05 Security Alerts, Advisories, and Directives
FISC.O2FISC.O12
SI-07 Software, Firmware, and Information Integrity
FISC.T7FISC.T12FISC.T14
SI-10 Information Input Validation
FISC.T5FISC.T6FISC.T8FISC.T12
SI-11 Error Handling
FISC.T8
SI-12 Information Management and Retention
FISC.O9FISC.T5
SI-13 Predictable Failure Prevention
FISC.O2FISC.O13
SI-16 Memory Protection
FISC.T7
SI-17 Fail-safe Procedures
FISC.O5