Protecting Sensitive Information and Strengthening Cyber Resilience Across Japan’s Defense Supply Chain
As Japan strengthens cybersecurity across its defense ecosystem, organizations supporting Ministry of Defense (MoD) programs face increasingly rigorous information assurance requirements. The Japan Ministry of Defense Information Assurance Standards (防衛省情報保証基準) establish security measures for organizations handling Protected Information, extending security expectations across the data, systems, personnel, and processes involved in defense procurement.
The standards require organizations to protect the confidentiality, integrity, and availability of Protected Information throughout its lifecycle while maintaining the technical controls and evidence needed to detect security issues, respond effectively, remediate risk, and demonstrate ongoing control effectiveness.
Fortra supports these requirements through an integrated portfolio of data and system security capabilities that help organizations:
- Identify, classify, and maintain visibility into Protected Information
- Detect sensitive-data exposure and risky access conditions
- Monitor and control the use, movement, and transmission of sensitive information
- Establish secure system configurations and detect unauthorized changes or operational drift
- Identify and prioritize vulnerabilities and validate remediation
- Support incident investigation, recovery, security auditing, and evidence collection
Fortra Data Security helps organizations strengthen protection across sensitive data and critical systems, delivering capabilities that provide the visibility, control, and technical evidence needed to reduce risk, improve cyber resilience, and support ongoing compliance with Japan MoD information assurance requirements.
Chapter 3: Configuration Management
Requirements 3.2(1) - 3.2(4): Baseline Configuration and System Hardening
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
3.2(1) | Baseline Configuration Settings, etc. | Define and obtain approval for baseline configurations that support security policy, protect the system, and restrict component functionality and operation to the minimum necessary. |
|
|
3.2(2) | Baseline Configuration Settings, etc. | Configure Protected System components in accordance with the approved baseline configuration. | Fortra Tripwire SCM |
|
3.2(3)(c) | Configuration Setting Methods | Disable unsafe or unnecessary functions, including ports, protocols, services, and programs, and prevent their execution. | Fortra Tripwire SCM |
|
3.2(4) | Review of Configuration Settings | Periodically, and when configurations are newly implemented or otherwise require review, examine configuration status and confirm that it conforms to the baseline. | Fortra Tripwire SCM |
|
Requirements 3.2(5): Software Blacklist and Whitelist Controls
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
3.2(5)(a) | Creation of Blacklists or Whitelists, etc. | Create a blacklist or whitelist for individual Protected System components based on the baseline configuration. | Fortra Tripwire AllowList |
|
3.2(5)(b)-(c) | Creation of Blacklists or Whitelists, etc. | Prevent blacklisted software from being installed or executed, or permit only whitelisted software to be installed and executed. | Fortra Tripwire AllowList |
|
3.2(5)(d) | Creation of Blacklists or Whitelists, etc. | Periodically review blacklists or whitelists and update them when Protected System components change. | Fortra Tripwire AllowList |
|
Requirements 3.3(1) - 3.3(3): Baseline Change Management and Security Impact
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
3.3(1) | Changes to Baseline Configuration Settings, etc. | Update the baseline configuration when vulnerabilities are discovered or remediated, or when required business functionality changes. |
|
|
3.3(2) | Changes to Baseline Configuration Settings, etc. | Where following the baseline is impossible or significantly unreasonable, implement an approved special configuration. | Fortra Tripwire SCM |
|
3.3(3) | Changes to Baseline Configuration Settings, etc. | Analyze the security impact before changing a baseline configuration or implementing a special configuration. |
|
|
Requirements 3.4(1) - 3.4(3): Configuration Inventory, Change Records, and Evidence
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
3.4(1)(a) | Recording and Retention of Configuration Settings, etc. | Create a configuration inventory capable of accurately confirming and demonstrating the current configuration state of Protected System components. |
|
|
3.4(1)(b) | Creation of an Inventory | Update the configuration inventory when the current configuration changes, including software installation or updates, and periodically review it for accuracy. |
|
|
3.4(2) | Records of Configuration Settings | Create records documenting baseline configuration decisions and changes and the implementation of component configuration settings. | Fortra Tripwire FIM/SCM |
|
3.4(3) | Retention of Inventories, etc. | Retain configuration inventories and configuration records for the required period, protecting electronic records through encryption. | Fortra Tripwire |
|
Chapter 6: Management of Protected Information
Requirement 6.1: Protected Information Classification
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
6.1 | Classification of Information Requiring Protection | Classify Protected Information so that it can be clearly distinguished from other information and strictly managed. | Fortra Data Classification |
|
Requirement 6.2: Protected Information Inventory and Accountability
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
6.2(1) | Creation and Maintenance of an Inventory of Information Requiring Protection: Creation of an Inventory | Create an inventory identifying where Protected Information is stored, including Protected Systems and removable media. |
|
|
6.2(2) | Creation and Maintenance of an Inventory of Information Requiring Protection: | Update inventory records when Protected Information is received, created, copied, viewed, removed, transmitted, returned, submitted, or disposed of; system logs may be used as the record. |
|
|
6.2(3) | Creation and Maintenance of an Inventory of Information Requiring Protection: | Protect inventory records against unauthorized access, alteration, or theft and retain them for the required period. | Fortra Tripwire |
|
Requirement 6.3: Marking of Protected Information
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
6.3(1)(a) | Marking, etc. of Documents Requiring Protection: | Clearly indicate that a document contains Protected Information using an easily recognizable marking. | Fortra Data Classification |
|
6.3(1)(b) | Marking, etc. of Documents Requiring Protection: | Clearly identify the portions of a document in which Protected Information is recorded. | Fortra Data Classification |
|
6.3(1)(c) | Marking, etc. of Documents Requiring Protection: | Externally indicate that removable media contains Protected Data. | Fortra Data Classification |
|
Requirement 6.5: Control of Removable Data
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
6.5(3) | Restrictions on the Use of Removable Storage Media in Protected Systems | Prevent the use of personally owned or otherwise unmanaged removable media on Protected Systems. | Fortra DLP |
|
6.5(4) | Restrictions on the Use of Removable Storage Media in Protected Systems | Restrict removable-media use to the minimum number of personnel required for business operations. | Fortra DLP |
|
6.5(5) | Restrictions on the Use of Removable Storage Media in Protected Systems | Implement technical measures, such as software controls, to ensure copying Protected Data to removable media follows approved use. | Fortra DLP |
|
6.5(6) | Restrictions on the Use of Removable Storage Media in Protected Systems | Restrict approved removable media from being connected to information systems other than the Protected System. | Fortra DLP |
|
Requirement 6.9: Prevention of Unauthorized Public Disclosure
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
6.9 | Measures for the Public Disclosure of Defense-Related Information | Verify that information released through websites or other public methods does not contain Protected Information. |
|
|
Chapter 10: Incident Monitoring and Analysis
Requirement 10.1(1)(c): Incident Monitoring and Analysis
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
10.1(1)(c) | Response to Information Security Incidents, etc.: | Establish procedures for monitoring information security incidents and events, including system monitoring, and for analyzing detected activity. |
|
|
Requirements 10.1(1)(e) and 10.1(2)(b): Incident Evidence Collection and Investigation
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
10.1(1)(e) | Response to Information Security Incidents, etc.: | Establish procedures for preserving evidence related to an incident and investigating its cause. |
|
|
10.1(2)(b) | Response to Information Security Incidents, etc.: | Collect and analyze information necessary to understand the details of an incident, including through the use of digital forensic techniques. |
|
|
Requirement 10.1(2)(c): System Analysis and Security Event Investigation
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
10.1(2)(c) | Response to Information Security Incidents, etc.: | Analyze and examine information systems across the network, including system-log collection and analysis, to identify components, data, accounts and other factors associated with the cause of an incident. |
|
|
Requirement 10.1(2)(d): Incident Response and Investigation Records
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
10.1(2)(d) | Response to Information Security Incidents, etc.: | Create and retain documentation recording incident-response procedures and results, analysis and root-cause findings, and information obtained during the response. |
|
|
Chapter 11: Response Following an Information Security Incident
Requirement 11.1(1): Incident Detection, Response and Investigation
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
11.1(1) | Response in the Event of an Information Security Incident: | Respond appropriately when an incident is discovered or detected and document the response, results, analysis, root-cause findings, and information obtained. |
|
|
Requirement 11.1(2): Vulnerability Detection and Remediation
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
11.1(2) | Response in the Event of an Information Security Incident: | When a Protected System vulnerability is discovered or detected, take appropriate action and document the response and remediation method. |
|
|
Requirement 11.1(4): Corrective Action and Remediation Tracking
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
11.1(4) | Response in the Event of an Information Security Incident: | Complete required incident or vulnerability remediation within established timeframes; where timely remediation is difficult, establish a corrective action plan and complete the correction within the defined period. |
|
|
Requirement 11.1(5): Risk-Based Vulnerability Remediation
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
11.1(5) | Response in the Event of an Information Security Incident: | Use risk-assessment results and public vulnerability information when performing vulnerability remediation, and remediate vulnerabilities with significant security impact as quickly as possible. |
|
|
Chapter 12: Risk Assesment
Requirement 12.1: Periodic and Event-Driven Risk Assessment
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
12.1 | Risk Assessment: | Perform risk assessments periodically and whenever significant changes to information security make reassessment necessary. |
|
|
Requirement 12.4: Assessment of Impact, Threats, and Vulnerabilities
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
12.4 | Risk Assessment : | Evaluate the potential damage, threats, and degree of vulnerability associated with unauthorized access, disclosure, use, alteration, or destruction of Protected Information and Protected Systems. |
|
|
Requirement 12.5: Internal and Third-Party Risk Assessment
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
12.5 | Risk Assessment : | Identify, analyze, and evaluate risks not only within departments handling Protected Information, but also in other internal departments and external organizations where they may affect its protection. |
|
|
Chapter 13: Security Audit
Requirements 13.1(1), 13.1(4) and 13.2: Continuous Control Effectiveness and Audit Evidence
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
13.1(1) | Security Audit: | Objectively verify implementation of required security measures and assess whether those measures remain continuously effective. |
|
|
13.1(4) | Security Audit: | Provide the audit function with information necessary to conduct the security audit and enable its use and analysis. | Fortra portfolio reporting |
|
13.2 | Security Audit: | Conduct security audits at least annually and when significant information-security changes occur, including evaluation of continuing control effectiveness. |
|
|
Requirement 13.3(2): Audit Findings and Control Deficiencies
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
13.3(2) | Security Audit: | Document problems affecting implementation or continuing effectiveness of security measures, improvement recommendations, and the time required to implement improvements. |
|
|
Requirement 13.3(3): Corrective Action Validation
Act Section | Requirement | Detail | Fortra Capability | Business Outcome |
13.3(3) | Security Audit: | Implement agreed corrective measures within the period established following security-audit findings. |
|
|
Fortra Data Security for Japan MoD Information Assurance Standards
Simplifying regulatory compliance for organizations throughout Japan's defense supply chain.