Fortra's Solutions for Japan Ministry of Defense Information Assurance Standards

Fortra’s integrated data security solutions deliver comprehensive data protection capabilities, continuous security posture assessment, and streamlined risk response, enabling simplified compliance with the Japan Ministry of Defense Information Assurance Standards.

Protecting Sensitive Information and Strengthening Cyber Resilience Across Japan’s Defense Supply Chain

As Japan strengthens cybersecurity across its defense ecosystem, organizations supporting Ministry of Defense (MoD) programs face increasingly rigorous information assurance requirements. The Japan Ministry of Defense Information Assurance Standards (防衛省情報保証基準) establish security measures for organizations handling Protected Information, extending security expectations across the data, systems, personnel, and processes involved in defense procurement.

The standards require organizations to protect the confidentiality, integrity, and availability of Protected Information throughout its lifecycle while maintaining the technical controls and evidence needed to detect security issues, respond effectively, remediate risk, and demonstrate ongoing control effectiveness.

Fortra supports these requirements through an integrated portfolio of data and system security capabilities that help organizations:

  • Identify, classify, and maintain visibility into Protected Information
  • Detect sensitive-data exposure and risky access conditions
  • Monitor and control the use, movement, and transmission of sensitive information
  • Establish secure system configurations and detect unauthorized changes or operational drift
  • Identify and prioritize vulnerabilities and validate remediation
  • Support incident investigation, recovery, security auditing, and evidence collection

Fortra Data Security helps organizations strengthen protection across sensitive data and critical systems, delivering capabilities that provide the visibility, control, and technical evidence needed to reduce risk, improve cyber resilience, and support ongoing compliance with Japan MoD information assurance requirements.

PRODUCT SUMMARY

Fortra Data Security provides a layered framework supporting Japan Ministry of Defense Information Assurance Standards through:

  • Sensitive data discovery and classification
  • System hardening and integrity monitoring
  • Data handling and egress protection
  • Cloud data exposure management
  • Secure email and information exchange
  • Vulnerability assessment and remediation
  • Incident response and recovery validation
  • Continuous compliance and audit-ready reporting

Together, these capabilities help defense organizations and supply-chain partners maintain trusted systems, protect sensitive information, strengthen cyber resilience, and demonstrate ongoing alignment with Japan MoD information assurance requirements.

Chapter 3: Configuration Management

Text

Requirements 3.2(1) - 3.2(4): Baseline Configuration and System Hardening

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

3.2(1)

Baseline Configuration Settings, etc.

Define and obtain approval for baseline configurations that support security policy, protect the system, and restrict component functionality and operation to the minimum necessary. 

  • Fortra Tripwire SCM

  • Fortra VM

  • Baseline policies

  • Configuration assessment results

  • Compliance status

  • Vulnerability findings 

3.2(2) 

Baseline Configuration Settings, etc. 

Configure Protected System components in accordance with the approved baseline configuration. 

Fortra Tripwire SCM 

  • Configuration compliance results

  • Failed policy tests

  • Baseline deviation reports 

3.2(3)(c) 

Configuration Setting Methods 

Disable unsafe or unnecessary functions, including ports, protocols, services, and programs, and prevent their execution. 

Fortra Tripwire SCM 

  • Hardening assessment results

  • Service inventory

  • Listening-port results

  • Software AllowList findings 

3.2(4) 

Review of Configuration Settings 

Periodically, and when configurations are newly implemented or otherwise require review, examine configuration status and confirm that it conforms to the baseline. 

Fortra Tripwire SCM 

  • Configuration assessment reports

  • Baseline compliance status

  • Configuration drift findings 

     

 

Requirements 3.2(5): Software Blacklist and Whitelist Controls

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

3.2(5)(a) 

Creation of Blacklists or Whitelists, etc. 

Create a blacklist or whitelist for individual Protected System components based on the baseline configuration. 

Fortra Tripwire AllowList 

  • Approved software inventory

  • AllowList status

  • Unauthorized software findings 

3.2(5)(b)-(c) 

Creation of Blacklists or Whitelists, etc. 

Prevent blacklisted software from being installed or executed, or permit only whitelisted software to be installed and executed. 

Fortra Tripwire AllowList 

  • Unauthorized software alerts 

  • Operational deviation reports

  • REST API / integration data 

3.2(5)(d) 

Creation of Blacklists or Whitelists, etc. 

Periodically review blacklists or whitelists and update them when Protected System components change. 

Fortra Tripwire AllowList 

  • Current software inventory 

  • AllowList comparison results 

  • Change-driven review evidence 

     

 

Requirements 3.3(1) - 3.3(3): Baseline Change Management and Security Impact

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

3.3(1) 

Changes to Baseline Configuration Settings, etc. 

Update the baseline configuration when vulnerabilities are discovered or remediated, or when required business functionality changes. 

  • Fortra VM

  • Fortra Tripwire SCM 

  • Vulnerability findings

  • Remediation guidance

  • Updated baseline policies

  • Post-change compliance results 

3.3(2) 

Changes to Baseline Configuration Settings, etc. 

Where following the baseline is impossible or significantly unreasonable, implement an approved special configuration. 

Fortra Tripwire SCM 

  • Exception-specific assessment 

  • Configuration status 

  • Deviation evidence 

3.3(3) 

Changes to Baseline Configuration Settings, etc. 

Analyze the security impact before changing a baseline configuration or implementing a special configuration. 

  • Fortra VM

  • Fortra Tripwire FIM/SCM 

  • Vulnerability context 

  • Current configuration state 

  • Change history 

  • Post-change validation 

     

 

Requirements 3.4(1) - 3.4(3): Configuration Inventory, Change Records, and Evidence

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

3.4(1)(a) 

Recording and Retention of Configuration Settings, etc. 

Create a configuration inventory capable of accurately confirming and demonstrating the current configuration state of Protected System components. 

  • Fortra Tripwire

  • Fortra Tripwire AllowList 

  • Configuration state data

  • Software inventory

  • Service/account/port inventory

  • System reports 

3.4(1)(b) 

Creation of an Inventory 

Update the configuration inventory when the current configuration changes, including software installation or updates, and periodically review it for accuracy. 

  • Fortra Tripwire FIM

  • Fortra Tripwire AllowList 

  • Change records 

  • Updated inventory results 

  • Operational deviations

  • Historical reports 

3.4(2) 

Records of Configuration Settings 

Create records documenting baseline configuration decisions and changes and the implementation of component configuration settings. 

Fortra Tripwire FIM/SCM 

  • Change history

  • Configuration assessment reports

  • Baseline compliance evidence 

3.4(3) 

Retention of Inventories, etc. 

Retain configuration inventories and configuration records for the required period, protecting electronic records through encryption. 

Fortra Tripwire

  • Historical configuration records

  • Change evidence

  • Retained audit reports 

     

Chapter 6: Management of Protected Information

Text

Requirement 6.1: Protected Information Classification

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

6.1 

Classification of Information Requiring Protection 

Classify Protected Information so that it can be clearly distinguished from other information and strictly managed. 

Fortra Data Classification 

  • Classification labels and metadata 

  • Classification activity/audit records 

  • Classification reports 

     

 

Requirement 6.2: Protected Information Inventory and Accountability

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

6.2(1) 

Creation and Maintenance of an Inventory of Information Requiring Protection: Creation of an Inventory 

Create an inventory identifying where Protected Information is stored, including Protected Systems and removable media. 

  • Fortra DSPM

  • Fortra Data Classification 

  • Sensitive data inventory 

  • Repository/location visibility 

  • Classification reports 

6.2(2) 

Creation and Maintenance of an Inventory of Information Requiring Protection:  
Updating the Inventory 

Update inventory records when Protected Information is received, created, copied, viewed, removed, transmitted, returned, submitted, or disposed of; system logs may be used as the record. 

  • Fortra Tripwire

  • Fortra DLP 

  • Change history/audit trail

  • DLP activity and incident records

  • User/account attribution 

6.2(3) 

Creation and Maintenance of an Inventory of Information Requiring Protection:  
Managing the Inventory 

Protect inventory records against unauthorized access, alteration, or theft and retain them for the required period. 

Fortra Tripwire 

  • File integrity history 

  • Configuration assessment results 

  • Change alerts and reports 

     

 

Requirement 6.3: Marking of Protected Information

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

6.3(1)(a) 

Marking, etc. of Documents Requiring Protection:  
Marking of Documents Requiring Protection 

Clearly indicate that a document contains Protected Information using an easily recognizable marking. 

Fortra Data Classification

  • Visible classification markings 

  • Classification metadata 

  • Policy/audit records 

6.3(1)(b) 

Marking, etc. of Documents Requiring Protection:  
Marking of Documents Requiring Protection

Clearly identify the portions of a document in which Protected Information is recorded. 

Fortra Data Classification

  • Document markings 

  • Classification evidence 

  • User/policy classification record 

6.3(1)(c) 

Marking, etc. of Documents Requiring Protection:  
Marking of Documents Requiring Protection

Externally indicate that removable media contains Protected Data. 

Fortra Data Classification

  • File classification metadata 

  • DLP device-control events 

  • Policy enforcement records 

     

 

Requirement 6.5: Control of Removable Data

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

6.5(3) 

Restrictions on the Use of Removable Storage Media in Protected Systems 

Prevent the use of personally owned or otherwise unmanaged removable media on Protected Systems. 

Fortra DLP

  • Device-control policy 

  • Blocked-device events 

  • Endpoint activity records 

6.5(4) 

Restrictions on the Use of Removable Storage Media in Protected Systems 

Restrict removable-media use to the minimum number of personnel required for business operations. 

Fortra DLP

  • Device access policy 

  • User/endpoint event records 

  • Policy enforcement logs 

6.5(5) 

Restrictions on the Use of Removable Storage Media in Protected Systems 

Implement technical measures, such as software controls, to ensure copying Protected Data to removable media follows approved use. 

Fortra DLP 

  • USB/removable-media transfer events 

  • Blocked or permitted action records 

  • DLP incident reports 

6.5(6) 

Restrictions on the Use of Removable Storage Media in Protected Systems 

Restrict approved removable media from being connected to information systems other than the Protected System. 

Fortra DLP 

  • Device-control events 

  • Endpoint policy status 

  • Audit/incident records 

     

 

Requirement 6.9: Prevention of Unauthorized Public Disclosure

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

6.9 

Measures for the Public Disclosure of Defense-Related Information 

Verify that information released through websites or other public methods does not contain Protected Information. 

  • Fortra Data Classification

  • Fortra DLP  

  • Classification metadata 

  • DLP policy alerts/incidents 

  • Blocked transfer or upload events 

  • Audit records 

     

Chapter 10: Incident Monitoring and Analysis

Text

Requirement 10.1(1)(c): Incident Monitoring and Analysis

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

10.1(1)(c) 

Response to Information Security Incidents, etc.:  
Development of an Information Security Incident Response Plan: 
Monitoring and Analysis of Incidents, etc. 

Establish procedures for monitoring information security incidents and events, including system monitoring, and for analyzing detected activity. 

  • Fortra Tripwire 

  • Fortra DLP 

  • Fortra DSPM

  • Fortra SEG 

  • Integrity/change alerts 

  • Configuration and operational-state events 

  • DLP incidents 

  • DSPM exposure findings 

  • Email-security events 

     

 

Requirements 10.1(1)(e) and 10.1(2)(b): Incident Evidence Collection and Investigation 

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

10.1(1)(e) 

Response to Information Security Incidents, etc.:  
Development of an Information Security Incident Response Plan: 
Preservation of Evidence and Investigation of the Causes of Incidents, etc. 

Establish procedures for preserving evidence related to an incident and investigating its cause. 

  • Fortra Tripwire 

  • Fortra DLP 

  • Fortra SEG 

  • Historical change records 

  • Integrity/configuration evidence 

  • User/account attribution 

  • DLP incident records 

  • Email-security logs 

10.1(2)(b) 

Response to Information Security Incidents, etc.:  
Development of an Information Security Incident Response Plan: 
Collect and analyze incident information 

Collect and analyze information necessary to understand the details of an incident, including through the use of digital forensic techniques. 

  • Fortra Tripwire

  • Fortra DLP

  • Fortra SEG 

  • System-state and change evidence 

  • Data activity records 

  • Message/email events 

  • Timestamps and attribution 

     

 

Requirement 10.1(2)(c): System Analysis and Security Event Investigation

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

10.1(2)(c) 

Response to Information Security Incidents, etc.:  
Development of an Information Security Incident Response Plan: 
Identify causes of security incidents 

Analyze and examine information systems across the network, including system-log collection and analysis, to identify components, data, accounts and other factors associated with the cause of an incident. 

  • Fortra Tripwire

  • Fortra VM

  • Fortra DLP 

  • Fortra SEG 

  • Change and configuration history

  • Account/software/service/port state

  • Vulnerability findings and affected assets 

  • DLP incidents 

  • Email-security events 

     

 

Requirement 10.1(2)(d): Incident Response and Investigation Records

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

10.1(2)(d) 

Response to Information Security Incidents, etc.:  
Development of an Information Security Incident Response Plan: 
Document and retain incident response records 

Create and retain documentation recording incident-response procedures and results, analysis and root-cause findings, and information obtained during the response. 

  • Fortra Tripwire

  • Fortra VM

  • Fortra DLP

  • Fortra DSPM

  • Fortra SEG 

  • Change/compliance reports 

  • Vulnerability reports 

  • DLP incident records 

  • DSPM findings 

  • SEG security events and reports 

     

Chapter 11: Response Following an Information Security Incident

Text

Requirement 11.1(1): Incident Detection, Response and Investigation

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

11.1(1) 

Response in the Event of an Information Security Incident: 
Actions Upon Discovery or Detection of an Information Security Incident: 
Report, respond, document security incidents. 

Respond appropriately when an incident is discovered or detected and document the response, results, analysis, root-cause findings, and information obtained. 

  • Fortra Tripwire

  • Fortra DLP

  • Fortra SEG

  • Fortra VM 

  • Change and integrity history

  • Configuration/operational-state evidence 

  • DLP incident records 

  • Email-security events 

  • Vulnerability findings 

     

 

Requirement 11.1(2): Vulnerability Detection and Remediation

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

11.1(2) 

Response in the Event of an Information Security Incident: 
Actions Upon Discovery or Detection of an Information Security Incident: 
Report, remediate, document discovered vulnerabilities 

When a Protected System vulnerability is discovered or detected, take appropriate action and document the response and remediation method. 

  • Fortra VM

  • Fortra Tripwire

  • Vulnerability findings 

  • Affected asset inventory 

  • Remediation guidance 

  • Configuration assessment results 

  • Change/integrity records 

     

 

Requirement 11.1(4): Corrective Action and Remediation Tracking

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

11.1(4) 

Response in the Event of an Information Security Incident: 
Actions Upon Discovery or Detection of an Information Security Incident: 
 
Remediate incidents within required timeframes 

Complete required incident or vulnerability remediation within established timeframes; where timely remediation is difficult, establish a corrective action plan and complete the correction within the defined period. 

  • Fortra VM

  • Fortra Tripwire

  • Prioritized vulnerability findings 

  • Remediation status/rescan results 

  • Configuration compliance results 

  • Change history 

  • Post-remediation evidence 

     

 

Requirement 11.1(5): Risk-Based Vulnerability Remediation

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

11.1(5) 

Response in the Event of an Information Security Incident: 
Actions Upon Discovery or Detection of an Information Security Incident: 
Prioritize and remediate critical vulnerabilities 

Use risk-assessment results and public vulnerability information when performing vulnerability remediation, and remediate vulnerabilities with significant security impact as quickly as possible. 

  • Fortra VM

  • Fortra Tripwire

  • CVE/vulnerability intelligence

  • Risk and severity prioritization

  • Affected asset findings

  • Rescan/remediation validation 

  • Configuration assessment and change evidence 

     

Chapter 12: Risk Assesment

Text

Requirement 12.1: Periodic and Event-Driven Risk Assessment

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

12.1 

Risk Assessment: 
Conduct regular information security risk assessments 

Perform risk assessments periodically and whenever significant changes to information security make reassessment necessary. 

  • Fortra Tripwire

  • Fortra VM

  • Fortra DSPM

  • Fortra DLP 

  • Configuration/ 
    compliance results

  • Integrity/change history

  • Vulnerability findings

  • DSPM exposure findings

  • DLP incidents 

     

 

Requirement 12.4: Assessment of Impact, Threats, and Vulnerabilities

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

12.4 

Risk Assessment : 
Assess impacts, threats, and vulnerabilities 

Evaluate the potential damage, threats, and degree of vulnerability associated with unauthorized access, disclosure, use, alteration, or destruction of Protected Information and Protected Systems. 

  • Fortra VM

  • Fortra Tripwire

  • Fortra DSPM

  • Fortra DLP 

  • Risk/severity findings

  • Affected asset inventory

  • Configuration assessment results

  • Unauthorized-change evidence

  • Sensitive-data exposure findings

  • DLP incidents 

     

 

Requirement 12.5: Internal and Third-Party Risk Assessment

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

12.5 

Risk Assessment : 
Assess internal and external risks 

Identify, analyze, and evaluate risks not only within departments handling Protected Information, but also in other internal departments and external organizations where they may affect its protection. 

  • Fortra DSPM

  • Fortra VM

  • Fortra Tripwire

  • Fortra DLP 

  • Cross-repository data findings

  • Exposure/access-risk findings

  • Vulnerability assessment results

  • Configuration/compliance evidence

  • DLP activity and incident records 

     

Chapter 13: Security Audit

Text

Requirements 13.1(1), 13.1(4) and 13.2: Continuous Control Effectiveness and Audit Evidence

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

13.1(1) 

Security Audit:  
Development of a Security Audit Plan, etc.: 
Establish an independent security audit function 

Objectively verify implementation of required security measures and assess whether those measures remain continuously effective. 

  • Fortra Tripwire

  • Fortra VM

  • Fortra DCS

  • Fortra DLP

  • Fortra DSPM

  • Fortra SEG 

  • Configuration/compliance reports

  • Integrity/change history

  • Vulnerability findings

  • Classification evidence

  • DLP/DSPM/SEG reports 

13.1(4) 

Security Audit:  
Development of a Security Audit Plan, etc.: 
Provide necessary information for security audits 

Provide the audit function with information necessary to conduct the security audit and enable its use and analysis. 

Fortra portfolio reporting 

  • Audit-ready reports 

  • Historical event records 

  • Security posture findings 

  • Policy and incident evidence 

13.2 

Security Audit:  
Development of a Security Audit Plan, etc.: 
Security Audit:  
Conducting Security Audits 

Conduct security audits at least annually and when significant information-security changes occur, including evaluation of continuing control effectiveness. 

  • Fortra Tripwire

  • Fortra VM

  • Fortra DCS

  • Fortra DLP

  • Fortra DSPM

  • Fortra SEG 

  • Current vs. historical posture

  • Compliance trends 

  • Vulnerability status 

  • Security-event history 

  • Data-security findings 

     

 

Requirement 13.3(2): Audit Findings and Control Deficiencies

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

13.3(2) 

Security Audit:  
Development of a Security Audit Plan, etc.: 
Reporting of Security Audit Results, etc.: 
Document required security audit results. 

Document problems affecting implementation or continuing effectiveness of security measures, improvement recommendations, and the time required to implement improvements. 

  • Fortra Tripwire

  • Fortra VM 

  • Fortra DSPM

  • Fortra DLP

  • Fortra SEG 

  • Configuration deviations

  • Unauthorized-change findings

  • Prioritized vulnerabilities

  • Data-exposure findings

  • DLP/SEG incidents

  • Remediation evidence 

     

 

Requirement 13.3(3): Corrective Action Validation

Act Section

Requirement

Detail

Fortra Capability

Business Outcome

13.3(3) 

Security Audit:  
Development of a Security Audit Plan, etc.: 
Reporting of Security Audit Results, etc.: 
Implement agreed security audit improvements 

Implement agreed corrective measures within the period established following security-audit findings. 

  • Fortra Tripwire

  • Fortra VM

  • Fortra DLP

  • Fortra DSPM

  • Fortra SEG 

  • Post-remediation configuration results

  • Change history

  • Vulnerability rescan results

  • Updated DSPM findings

  • DLP/SEG policy evidence 

     

Fortra Data Security for Japan MoD Information Assurance Standards

Simplifying regulatory compliance for organizations throughout Japan's defense supply chain.

REQUEST A DEMO