The FISC Security Guidelines on Computer Systems for Banking and Related Financial Institutions are key to how Japanese financial institutions are expected to manage and secure their IT environments. For many organizations, the challenge is translating those expectations into concrete, auditable controls on modern data and AI platforms.
The Databricks Platform can be configured to support identity management, network isolation, encryption, data access, and auditing. Through centralized governance, detailed permissions, and data lineage, teams can enforce controls such as segregation of duties and cybersecurity measures, and integrate with external backup and recovery solutions to protect vital financial information.
Databricks also provides a FISC Customer Capabilities Mapping Matrix that links guideline units to specific Databricks Data Intelligence Platform capabilities and customer responsibilities. This enables IT, security, and compliance teams to design, implement, and test controls that align directly with FISC, while clearly understanding how Databricks, the cloud provider, and the customer share responsibilities.
The following sections describe how Databricks and Unity Catalog support FISC‑aligned architectures and how to apply the mapping matrix in practice.
Understanding FISC and Its Impact On Financial Institutions
For banks, securities firms, and other financial institutions in Japan, the FISC Security Guidelines serve as a common benchmark for regulators, auditors, and internal risk teams when evaluating technology risk. Rather than prescribing specific products, the guidelines define principles and control objectives that institutions are expected to implement and evidence across their environments.
In practice, FISC touches a broad set of disciplines, which include but are not limited to:
- Access management and segregation of duties: Ensuring that privileged access is tightly controlled, roles are clearly separated, and changes to production systems are appropriately governed.
- Change management and system development: Requiring documented, tested, and approved changes, with traceability from requirements through deployment.
- Data backup, recovery, and continuity: Demonstrating that critical data and services can be restored within defined recovery time and recovery point objectives.
- System and operations monitoring: Monitoring systems, networks, and applications for performance, availability, and security signals, and responding to incidents in a timely way.
- Audit trails and record‑keeping: Maintaining logs and records that show who did what, when, and in which systems, so that activities can be reconstructed and reviewed.
- Outsourcing, cloud services, and vendor management: Treating cloud and other third‑party service providers as extensions of the institution’s own environment, with structured due diligence, contractual safeguards, and ongoing oversight of security and control effectiveness.
A FISC‑aligned architecture on Databricks addresses both Databricks Data Intelligence Platform‑level controls and customer‑specific requirements.
How Databricks and Unity Catalog Support FISC Compliance
The Databricks Platform, featuring Unity Catalog, can be used as a governance and security layer across clouds for both data and AI workloads. It can be used to implement technical controls related to FISC expectations in a few key areas:
- Access control and segregation of duties: Centralized RBAC/ABAC and fine-grained permissions on catalogs, schemas, tables, and AI assets support least privilege and clear separation between admin, developer, and business roles.
- Auditability and lineage: Comprehensive audit logs and end‑to‑end lineage make it easier to evidence who accessed what, when, and through which pipelines or models, directly supporting FISC requirements for monitoring and record‑keeping.
- Encryption and key management: Databricks encrypts Customer Content under its control in transit and at rest and supports customer‑managed keys (CMKs) for eligible services. Customers remain responsible for enabling encryption and configuring CMKs in their own cloud storage (e.g., Amazon S3, Azure Blob Storage, or Google Cloud Storage (GCS)), aligning with FISC expectations for protecting sensitive financial data in storage environments.
- Network isolation and authentication: Private networking options, IP restrictions, egress controls, strong authentication via SSO and MFA help reduce exposure to cyberattacks and demonstrate that access to regulated systems is tightly controlled.
- Enhanced Security Monitoring and Compliance Security Profile
- For regulated and high-risk workloads, Databricks offers two optional add-on features: Enhanced Security Monitoring (ESM) and the Compliance Security Profile (CSP), which strengthen the default platform controls. ESM runs clusters on hardened OS images and deploys additional security agents for antivirus and malware detection, file-integrity monitoring, sending security events to your log destination, such as a SIEM, alongside standard Databricks audit logs. Further, Databricks regularly scans representative host images for known vulnerabilities and shares vulnerability reports with workspace administrators as new images are released.
- CSP includes all ESM capabilities and enforces stricter configuration baselines, including automatic cluster updates with configurable maintenance windows and, on supported platforms, specific instance-type and encryption requirements.
- Together, ESM and CSP allow customers to designate hardened runtime environments for sensitive financial data workloads, helping demonstrate to auditors that compute environments meet the higher operational security expectations embedded in the FISC guidelines. Customers can enable ESM and CSP on selected workspaces and clusters based on their regulatory, risk, and monitoring requirements.
Using these capabilities, institutions can configure the platform to implement technical controls aligned with FISC expectations. To help teams apply these capabilities directly to specific guideline units, Databricks provides a mapping matrix that connects FISC requirements to Databricks features and shared responsibilities.
Mapping FISC Requirements to Databricks Capabilities
The FISC Customer Capabilities Mapping Matrix links each guideline unit to specific Databricks features. Your IT, security, legal, and compliance teams can use the matrix to:
- Identify which Databricks capabilities support each FISC control objective
- Understand where customer configuration, process, or evidence is required
- Design, implement, and test controls in a way that is directly traceable back to FISC
At a high level, the matrix distinguishes between:
- Databricks Platform Controls: including encryption, hardened runtimes, audit logging, and governance features that Databricks operates and continuously validates.
- Customer Responsibilities: including defining policies, configuring IAM, integrating logs with SIEM tools, and maintaining internal procedures and evidence.
By reviewing each applicable guideline unit alongside the corresponding Databricks capabilities and notes, customer teams can build a FISC-aligned control framework that fits within their organizational risk management program to align with their operating model.
Security and the Shared Responsibility Model
Databricks operates under a shared responsibility model. Databricks and the cloud provider are responsible for securing the platform and underlying infrastructure. At the same time, customers are responsible for configuring and operating Databricks for their own data, workloads, and regulatory obligations.
On the Databricks side, responsibilities include:
- Hardening and operating the Databricks service and control plane
- Providing core security and governance controls, such as RBAC/ABAC, encryption, audit logging, and private networking options
- Maintaining independent certifications and attestations that demonstrate the design and effectiveness of those controls
On the customer side, responsibilities include:
- Classifying data and defining risk‑appropriate controls
- Configuring identity and access controls (for example, SSO, MFA, SCIM groups, Unity Catalog permissions)
- Enabling and integrating logging, monitoring, and alerting with SIEM and GRC tools
- Designing and operating backup, disaster recovery, and operational processes that meet FISC and internal policy requirements
Where applicable, the Databricks FISC Customer Capabilities Mapping Matrix outlines customer‑configurable controls for each guideline unit. The Databricks Data Intelligence Platform security model describes the underlying platform controls that support those capabilities. Using the matrix as a guide, customers can document FISC‑aligned controls, demonstrate how shared responsibilities are addressed end‑to‑end, and demonstrate how Databricks fits into their broader security and compliance architecture.
Extending FISC Controls to AI and Machine Learning Workloads
As financial institutions increasingly deploy AI and machine learning models for credit scoring, fraud detection, and other regulated use cases, FISC-aligned controls must extend beyond data pipelines into model governance and inference environments. Databricks supports this through Unity Catalog's Model Registry, which provides end-to-end model lineage linking training data, code versions, and evaluation metrics to every registered model version, as well as version-controlled promotion workflows and audit-log entries for every model read, write, or stage transition.
For institutions that want a structured framework for AI-specific risks, the Databricks AI Security Framework Agentic AI Extension whitepaper (DASF 3.0 Google sheet, Excel) maps 97 AI-specific risks to 73 controls across AI system components, covering areas such as AI agents security, model governance, training data integrity, and inference security, and can be incorporated into your vendor due diligence, outsourcing oversight, and internal AI risk assessment processes. When AI workloads process regulated data, enabling the Compliance Security Profile (CSP) ensures that the underlying compute environment meets the same hardened baseline required for other sensitive financial data workloads.
Using the Mapping Matrix: Important Considerations
Note: This blog and control mapping guidance are intended as an educational resource only and may contain inaccuracies or omissions. We reserve the right to update these materials at any time without prior notice. Readers are advised to consult appropriate technical and legal experts for proper control implementation and regulatory compliance.
Next Steps for FISC Compliance with Databricks
To move forward, consider the following actions:
- Assess Your Current Posture with the Security Analysis Tool
- Before remediating controls, run the Databricks Security Analysis Tool (SAT) to evaluate your workspace configuration against security best practices and flag gaps, such as public network access, missing logging, or admin accounts lacking MFA. SAT output serves as a practical prioritization guide and audit evidence. Note that SAT is provided as-is, without official support or SLAs.
- Adopt Databricks Capabilities Mapping:
- Review the FISC–Databricks Customer Capabilities Mapping Matrix with your audit and security teams to identify control gaps and plan remediation.
- Review Databricks Security and Compliance Materials:
- Visit the Databricks Security and Trust Center at databricks.com/trust for more information on ISO 27001, SOC 1, and SOC 2 Type II, etc. certification and reports
- Use Unity Catalog for centralized governance:
- Use Unity Catalog to enforce fine-grained access controls, manage permissions, and track lineage for sensitive financial data across clouds.
- Collaborate across teams and with Databricks teams:
- Work with your internal security, compliance, and legal teams and, where appropriate, your Databricks representatives, to inquire about FISC-aligned architecture on the Databricks Data Intelligence Platform.
These steps can help you operationalize Databricks capabilities in support of your FISC compliance objectives.