Leveraging Databricks to Support FISC Security Guidelines
Captured source
source ↗Leveraging Databricks to Support FISC Security Guidelines | Databricks Blog Skip to main content
Summary
The Databricks Platform with Unity Catalog helps Japanese financial institutions implement technical controls that align with the FISC Security Guidelines.
Centralized governance, fine‑grained permissions, encryption, and audit logging make it easier to design, implement, and evidence FISC‑aligned controls on Databricks.
A FISC Customer Capabilities Mapping Matrix links guideline units to Databricks features and customer responsibilities, enabling teams to plan and document controls under the shared responsibility model.
The FISC Security Guidelines on Computer Systems for Banking and Related Financial Institutions are key to how Japanese financial institutions are expected to manage and secure their IT environments. For many organizations, the challenge is translating those expectations into concrete, auditable controls on modern data and AI platforms. The Databricks Platform can be configured to support identity management, network isolation, encryption, data access, and auditing. Through centralized governance, detailed permissions, and data lineage, teams can enforce controls such as segregation of duties and cybersecurity measures, and integrate with external backup and recovery solutions to protect vital financial information. Databricks also provides a FISC Customer Capabilities Mapping Matrix that links guideline units to specific Databricks Data Intelligence Platform capabilities and customer responsibilities. This enables IT, security, and compliance teams to design, implement, and test controls that align directly with FISC, while clearly understanding how Databricks, the cloud provider, and the customer share responsibilities. The following sections describe how Databricks and Unity Catalog support FISC‑aligned architectures and how to apply the mapping matrix in practice. Understanding FISC and Its Impact On Financial Institutions For banks, securities firms, and other financial institutions in Japan, the FISC Security Guidelines serve as a common benchmark for regulators, auditors, and internal risk teams when evaluating technology risk. Rather than prescribing specific products, the guidelines define principles and control objectives that institutions are expected to implement and evidence across their environments. In practice, FISC touches a broad set of disciplines, which include but are not limited to: Access management and segregation of duties: Ensuring that privileged access is tightly controlled, roles are clearly separated, and changes to production systems are appropriately governed. Change management and system development: Requiring documented, tested, and approved changes, with traceability from requirements through deployment. Data backup, recovery, and continuity: Demonstrating that critical data and services can be restored within defined recovery time and recovery point objectives. System and operations monitoring: Monitoring systems, networks, and applications for performance, availability, and security signals, and responding to incidents in a timely way. Audit trails and record‑keeping: Maintaining logs and records that show who did what, when, and in which systems, so that activities can be reconstructed and reviewed. Outsourcing, cloud services, and vendor management: Treating cloud and other third‑party service providers as extensions of the institution’s own environment, with structured due diligence, contractual safeguards, and ongoing oversight of security and control effectiveness.
A FISC‑aligned architecture on Databricks addresses both Databricks Data Intelligence Platform‑level controls and customer‑specific requirements. How Databricks and Unity Catalog Support FISC Compliance The Databricks Platform, featuring Unity Catalog , can be used as a governance and security layer across clouds for both data and AI workloads. It can be used to implement technical controls related to FISC expectations in a few key areas: Access control and segregation of duties: Centralized RBAC/ABAC and fine-grained permissions on catalogs, schemas, tables, and AI assets support least privilege and clear separation between admin, developer, and business roles. Auditability and lineage: Comprehensive audit logs and end‑to‑end lineage make it easier to evidence who accessed what, when, and through which pipelines or models, directly supporting FISC requirements for monitoring and record‑keeping. Encryption and key management: Databricks encrypts Customer Content under its control in transit and at rest and supports customer‑managed keys (CMKs) for eligible services. Customers remain responsible for enabling encryption and configuring CMKs in their own cloud storage (e.g., Amazon S3, Azure Blob Storage, or Google Cloud Storage (GCS)), aligning with FISC expectations for protecting sensitive financial data in storage environments. Network isolation and authentication: Private networking options, IP restrictions, egress controls, strong authentication via SSO and MFA help reduce exposure to cyberattacks and demonstrate that access to regulated systems is tightly controlled. Enhanced Security Monitoring and Compliance Security Profile For regulated and high-risk workloads, Databricks offers two optional add-on features: Enhanced Security Monitoring (ESM) and the Compliance Security Profile (CSP), which strengthen the default platform controls. ESM runs clusters on hardened OS images and deploys additional security agents for antivirus and malware detection, file-integrity monitoring, sending security events to your log destination, such as a SIEM, alongside standard Databricks audit logs. Further, Databricks regularly scans representative host images for known vulnerabilities and shares vulnerability reports with workspace administrators as new images are released. CSP includes all ESM capabilities and enforces stricter configuration baselines, including automatic cluster updates with configurable maintenance windows and, on supported platforms, specific instance-type and encryption requirements. Together, ESM and CSP allow customers to designate hardened runtime environments for sensitive financial data workloads, helping demonstrate to auditors that compute environments meet the higher operational security expectations embedded in the FISC guidelines. Customers can enable ESM and CSP on selected workspaces and clusters based on their regulatory, risk,...
Excerpt shown — open the source for the full document.
Notability
notability 3.0/10Corporate compliance blog, not AI research.