ISMS certification audits in Japan follow the ISO/IEC 27001 standard as interpreted by JIPDEC (Japan Information Processing Development Corporation). The infrastructure-related controls are not technically complex, but they require documentation that many engineering teams have not produced before.

What auditors look for in infrastructure controls

The Annex A controls most relevant to infrastructure are A.11 (physical and environmental security) and A.12 (operations security). For A.11, auditors want evidence that physical access to servers is controlled and logged. For A.12, they want evidence that changes to systems are managed through a defined process, that logs are retained and protected from modification, and that capacity is monitored. These are not difficult requirements to meet, but they require that the evidence exists and is retrievable.

The documentation gap in shared infrastructure

When infrastructure runs on a public cloud provider, the physical security controls (A.11) are covered by the provider's own certifications, typically SOC 2 Type II and ISO 27001. Auditors generally accept this. The operations security controls (A.12) are the harder part, because the audit trail for configuration changes on a public cloud account is only as good as the CloudTrail or equivalent logging you have configured. Many teams discover during their first ISMS audit that their change management logs have gaps.

Building an audit-ready infrastructure baseline

An audit-ready infrastructure baseline has three components: a current-state configuration document, an immutable change log, and a physical access record. On Husk Mesh Vault, the current-state configuration is exportable via the API at any time. The change log is the immutable audit log stream, which records every API call and configuration diff. The physical access record is maintained by the Chiba facility and is available to customers on request.

The quarterly compliance review

The Husk Mesh Vault Compliance Audit Package provides a quarterly review of your audit log stream against the relevant ISMS controls. The output is a structured gap analysis document that identifies controls where evidence is present, controls where evidence is incomplete, and recommended remediation steps. This document is not a substitute for a formal ISMS audit by an accredited certification body, but it significantly reduces the preparation time for that audit.

ISMS certification is achievable for engineering teams of any size. The main requirement is that the evidence exists and is organised before the auditor arrives, not assembled in the week before the audit.