← Frameworks / Security Framework

FISC Security Guidelines on Computer Systems for Financial Institutions

Japan's de facto mandatory security standard for financial institutions, published by the Center for Financial Industry Information Systems (FISC). Covers technical standards (system design, access control, cryptography, network security), operational standards (IT governance, incident response, outsourcing, SDLC), and facility standards (data center physical security, environmental controls, disaster recovery). Referenced by the FSA and Bank of Japan for supervisory examinations.

Clause Title SP 800-53 Controls
FISC.F1 Data Center Physical Security
FISC.F2 Environmental Controls (Power, HVAC, Fire Suppression)
FISC.F3 Equipment Protection and Maintenance
FISC.F4 Media Handling and Disposal
FISC.F5 Alternative Site and Recovery Facilities
FISC.O1 IT Governance and Risk Management
FISC.O2 System Operation and Monitoring
FISC.O3 Change Management and Configuration Control
FISC.O4 Incident Detection and Response
FISC.O5 Business Continuity and Disaster Recovery
FISC.O6 Outsourcing and Third-Party Management
FISC.O7 System Audit and Compliance
FISC.O8 Human Resources Security and Training
FISC.O9 Information Asset and Data Lifecycle Management
FISC.O10 Software Development Lifecycle
FISC.O11 Log Management and Forensic Readiness
FISC.O12 Vulnerability and Patch Management
FISC.O13 Capacity and Performance Management
FISC.T1 System Planning and Design Requirements
FISC.T2 Access Control and Authentication
FISC.T3 Network Security Architecture
FISC.T4 Cryptographic Controls
FISC.T5 Database and Data Security
FISC.T6 Application Security
FISC.T7 Operating System and Platform Security
FISC.T8 Web and API Security
FISC.T9 Cloud Computing Security
FISC.T10 Mobile and Remote Access Security
FISC.T11 Electronic Payment Systems Security
FISC.T12 Transaction Integrity and Non-repudiation
FISC.T13 System Interconnection Controls
FISC.T14 Virtualisation and Container Security