FISC Security Guidelines on Computer Systems for Financial Institutions
Japan's de facto mandatory security standard for financial institutions, published by the Center for Financial Industry Information Systems (FISC). Covers technical standards (system design, access control, cryptography, network security), operational standards (IT governance, incident response, outsourcing, SDLC), and facility standards (data center physical security, environmental controls, disaster recovery). Referenced by the FSA and Bank of Japan for supervisory examinations.
Clauses: 32
Avg Coverage: 82.2%
Publisher: Center for Financial Industry Information Systems (FISC) Version: 11th Edition (2024) | Clause | Title | SP 800-53 Controls |
|---|---|---|
| FISC.F1 | Data Center Physical Security | |
| FISC.F2 | Environmental Controls (Power, HVAC, Fire Suppression) | |
| FISC.F3 | Equipment Protection and Maintenance | |
| FISC.F4 | Media Handling and Disposal | |
| FISC.F5 | Alternative Site and Recovery Facilities | |
| FISC.O1 | IT Governance and Risk Management | |
| FISC.O2 | System Operation and Monitoring | |
| FISC.O3 | Change Management and Configuration Control | |
| FISC.O4 | Incident Detection and Response | |
| FISC.O5 | Business Continuity and Disaster Recovery | |
| FISC.O6 | Outsourcing and Third-Party Management | |
| FISC.O7 | System Audit and Compliance | |
| FISC.O8 | Human Resources Security and Training | |
| FISC.O9 | Information Asset and Data Lifecycle Management | |
| FISC.O10 | Software Development Lifecycle | |
| FISC.O11 | Log Management and Forensic Readiness | |
| FISC.O12 | Vulnerability and Patch Management | |
| FISC.O13 | Capacity and Performance Management | |
| FISC.T1 | System Planning and Design Requirements | |
| FISC.T2 | Access Control and Authentication | |
| FISC.T3 | Network Security Architecture | |
| FISC.T4 | Cryptographic Controls | |
| FISC.T5 | Database and Data Security | |
| FISC.T6 | Application Security | |
| FISC.T7 | Operating System and Platform Security | |
| FISC.T8 | Web and API Security | |
| FISC.T9 | Cloud Computing Security | |
| FISC.T10 | Mobile and Remote Access Security | |
| FISC.T11 | Electronic Payment Systems Security | |
| FISC.T12 | Transaction Integrity and Non-repudiation | |
| FISC.T13 | System Interconnection Controls | |
| FISC.T14 | Virtualisation and Container Security |