SAP Concur: ISMAP 2024 Renewal Certificate
The Information systems supporting SAP Concur have been audited and found to comply with the requirements of the Information system Security Management and Assessment Program (ISMAP), which is the Japanese Government’s Security Assessment System for Government Information Systems.Link to certificate page: https://www.ismap.go.jp/csm?id=cloud_service_list Download the Document
01/05/25, 09:47ISMAP Cloud Service List Details - ISMAP Portal
Page 1 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=1cdc60112bb8aa50f0bbfd69fe91bf4c
Cloud service list details
Registration number C24-0085-2
Name of cloud service SAP Concur
The URL of the cloud service's
homepage
Https://www.concur.co.jp/
Name of the cloud service
provider
SAP SE
Corporate number
Location of the cloud service
operator
Dietmar-Hopp-Allee 16, D-69190 Walldorf, Germany.
Date of registration 10/30/2024
Registration expiration date 01/31/2026
Scope of the statement SAP Concur_Scope of statement.pdf
Management measures for
control targets implemented
among the basic statement
requirements
SAP Concur_Management Measures for Control Targets Implemented among the
Basic Statement Requirements.pdf
Audit period 2023/10/01 to 2024/09/30
late event No applicable matters
Availability of an improvement
plan
None
Information on the applicant's
capital relationship and officers
at the time of application
SAP Concur_Information on capital relations and executives, etc.pdf
Information necessary for risk
assessment
SAP Concur_About the provision of information specified in the ISMAP Cloud
Service Registration Rule 3.4(2).pdf
Information on the governing SAP Concur_Information on applicable law and jurisdiction.pdf
*1
*2
※3
※4
Page 1 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=1cdc60112bb8aa50f0bbfd69fe91bf4c
Cloud service list details
Registration number C24-0085-2
Name of cloud service SAP Concur
The URL of the cloud service's
homepage
Https://www.concur.co.jp/
Name of the cloud service
provider
SAP SE
Corporate number
Location of the cloud service
operator
Dietmar-Hopp-Allee 16, D-69190 Walldorf, Germany.
Date of registration 10/30/2024
Registration expiration date 01/31/2026
Scope of the statement SAP Concur_Scope of statement.pdf
Management measures for
control targets implemented
among the basic statement
requirements
SAP Concur_Management Measures for Control Targets Implemented among the
Basic Statement Requirements.pdf
Audit period 2023/10/01 to 2024/09/30
late event No applicable matters
Availability of an improvement
plan
None
Information on the applicant's
capital relationship and officers
at the time of application
SAP Concur_Information on capital relations and executives, etc.pdf
Information necessary for risk
assessment
SAP Concur_About the provision of information specified in the ISMAP Cloud
Service Registration Rule 3.4(2).pdf
Information on the governing SAP Concur_Information on applicable law and jurisdiction.pdf
*1
*2
※3
※4
01/05/25, 09:47ISMAP Cloud Service List Details - ISMAP Portal
Page 2 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=1cdc60112bb8aa50f0bbfd69fe91bf4c
law and jurisdiction stipulated in
the contract
Information on the
implementation status and
acceptance of third-party tests
such as penetration tests and
vulnerability diagnosis
SAP Concur_ISMAP Cloud Service Registration Regulation 3.4(4) Provision of
information.pdf
Special notes on cloud service
registration
Management measures for encryption key management by users (8.1.2.7. PB and
10.1.2.20. PB) is not adopted.
Remarks 2025/04/28 Change the registration expiration date, audit period, information,
etc.
※1 In principle, all management measures as control goals must be implemented, but cloud service providers
are not eligible for management measures as control goals that cannot be reasonably applied in light of the
services they provide. You can do it.
In addition, the management measures as control goals that are excluded are slashed.
※2 If the audit is carried out only based on the maintenance status evaluation, the audit reference date is listed.
※3 If there are minor findings in the management measure standard in the implementation result report, and
an improvement plan indicating that the control related to the findings will be improved within 2 months
from the date of the implementation result report has been submitted by the cloud service provider, " It is
described as "yes".
※4 The information necessary for risk assessment is stipulated in ISMAP Cloud Service Registration Rule 3.4(2),
"Laws and regulations other than domestic laws apply to information handled by cloud services, and
procurement is unintended by procurement ministries, etc. It refers to the information necessary for the
system management committee and the ministry, etc. to conduct a risk assessment regarding the risk of
accessing or processing information managed by the government ministry, etc.
(Note)When utilizing the ISMAP cloud service list, please refer to "Notes on Generated AI Services" for handling
when the registered service includes a generated AI service. In addition, information about the generated AI
will be posted in the "Scope of the statement" or "Special notes related to the registration of cloud services".
Page 2 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=1cdc60112bb8aa50f0bbfd69fe91bf4c
law and jurisdiction stipulated in
the contract
Information on the
implementation status and
acceptance of third-party tests
such as penetration tests and
vulnerability diagnosis
SAP Concur_ISMAP Cloud Service Registration Regulation 3.4(4) Provision of
information.pdf
Special notes on cloud service
registration
Management measures for encryption key management by users (8.1.2.7. PB and
10.1.2.20. PB) is not adopted.
Remarks 2025/04/28 Change the registration expiration date, audit period, information,
etc.
※1 In principle, all management measures as control goals must be implemented, but cloud service providers
are not eligible for management measures as control goals that cannot be reasonably applied in light of the
services they provide. You can do it.
In addition, the management measures as control goals that are excluded are slashed.
※2 If the audit is carried out only based on the maintenance status evaluation, the audit reference date is listed.
※3 If there are minor findings in the management measure standard in the implementation result report, and
an improvement plan indicating that the control related to the findings will be improved within 2 months
from the date of the implementation result report has been submitted by the cloud service provider, " It is
described as "yes".
※4 The information necessary for risk assessment is stipulated in ISMAP Cloud Service Registration Rule 3.4(2),
"Laws and regulations other than domestic laws apply to information handled by cloud services, and
procurement is unintended by procurement ministries, etc. It refers to the information necessary for the
system management committee and the ministry, etc. to conduct a risk assessment regarding the risk of
accessing or processing information managed by the government ministry, etc.
(Note)When utilizing the ISMAP cloud service list, please refer to "Notes on Generated AI Services" for handling
when the registered service includes a generated AI service. In addition, information about the generated AI
will be posted in the "Scope of the statement" or "Special notes related to the registration of cloud services".