ZEROCK

ISMAP Never Says "Keep the Data in Japan": I Searched All 45 Pages of the Control Standard

Published2026-09-06Ryuta Hamamoto

The service passed Japanese government procurement, so the data must be in Japan. Read the actual program documents and that inference falls apart. Across all 45 pages of the ISMAP control standard, the words for "Japan", "outside the country" and "cross-border" never appear once, and the clauses that touch location go no further than notifying customers which countries may hold their data and assessing the risk of foreign law reaching it. Here are the clause numbers.

ISMAP Never Says "Keep the Data in Japan": I Searched All 45 Pages of the Control Standard
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

"The service is registered under ISMAP, so the data is stored inside Japan." I have read that sentence, or something close enough to it, in more cloud selection memos than I can count. The two halves are written as though one causes the other. Very few of the people circulating those memos have checked whether they are connected at all.

It bothered me enough that I downloaded the ISMAP control standard and ran a full-text search on it myself. Forty-five pages. Here is the result before anything else. The Japanese word for Japan, 日本, appears zero times. 国外, meaning outside the country, appears zero times. 越境, cross-border, appears zero times. 国内, meaning domestic or inside the country, turns up three times, and two of those three sit inside a generic list of risk factors that has nothing whatsoever to do with where data lives. The remaining hit is the clause this article is really about.

Which means the inference cannot be built on the control standard. A cloud service that has cleared Japanese government procurement is not, by that fact, a cloud service that keeps your data in Japan. So what does the program require? Let me walk through it with the clause numbers in hand. If you would rather start by mapping where your own organisation currently stands, there is a free AI readiness check.

The words that never show up across 45 pages

ISMAP, the Information system Security Management and Assessment Program (政府情報システムのためのセキュリティ評価制度), rests on a decision taken by the Cybersecurity Strategy Headquarters on 30 January 2020. Its stated purpose is to assess and register cloud services that meet the security requirements the government demands, ahead of time, so that adoption goes smoothly1. Four bodies own the program between them: the national cyber office (国家サイバー統括室), the Digital Agency, the Ministry of Internal Affairs and Communications, and the Ministry of Economy, Trade and Industry. Day-to-day operation is delegated to the Information-technology Promotion Agency, Japan.

One detail worth carrying with you if you quote these documents. The revision of 11 July 2025 replaced the references to the Cabinet Cybersecurity Center (NISC) with the national cyber office that took over from it. Before you cite a clause on the governance of the program, check that you are not copying from a pre-revision copy someone saved two years ago.

Seen from the buyer's side, the program bites through the procurement rules. Government procurement is expected, in principle, to select from the ISMAP cloud service list1. That is why vendors want to be on it, and why customers treat the list as a proxy for trustworthiness. Up to that point the mechanism works well.

The question is what that trust actually covers. What I searched was the requirement itself, the body of controls a service has to satisfy in order to appear on the list, which is the ISMAP control standard2. I extracted the text twice, using two different methods, because a null result is exactly the kind of finding a bad extraction produces. Both runs agreed. Japan, outside the country and cross-border are simply not in those 45 pages. For completeness I also searched 海外, the ordinary word for overseas, and got a single hit. It sits in a passage about a US standards document, describing it as having a long operating record among overseas standards. Nothing to do with where data is placed.

The three hits for 国内 hold up the same way. Two of them appear in a sentence that runs through the external factors an organisation has to consider, "cultural, social, political, legal, regulatory, financial" and so on, "whether international, domestic, regional or local". That is a requirement to survey your operating environment without gaps, not a requirement about siting. Only the third hit deals head-on with which country's law governs the data.

The control standard is a roughly 45-page set of controls assembled on the basis of documents including the Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2023 edition). The absence of a domestic-storage clause is a design decision, not an oversight. What ISMAP assesses is whether a provider's controls are implemented and operating, not geography. But if that is the design, then the real hazard sits on the customer side, where "registered" is quietly being read as "in Japan" by people who have never had cause to check. That is the thing I most want to get across today.

Struggling with AI adoption?

We have prepared materials covering ZEROCK case studies and implementation methods.

What the program asks for is knowledge and assessment, not a location

So what does the control standard say about location? Two clauses, and only two.

The first carries the number 6.1.3.3.PB. The Japanese is the binding text; the rendering here is mine.

The cloud service provider shall notify cloud service customers of the geographic locations of the cloud service provider's organisation, and of the countries in which the cloud service provider may store cloud service customers' data.3

Read the verb. It is "notify". This is not a prohibition on placing data anywhere in particular. Where is the provider's organisation established, and in which countries might the data it holds for you end up. Tell the customer. That is a transparency requirement, nothing more.

Notice as well that the clause says "the countries in which it may store", plural. The drafters assumed from the start that customer data can straddle several jurisdictions. A regime built on the premise that data stays in one place would not phrase it that way.

The second clause is the third hit for 国内 mentioned earlier, and it is numbered 15.1.1.16.B. It sits in chapter 15, which covers supplier relationships.

Assess the risk that, as a result of laws and regulations other than domestic law being applied to information handled on the services the operator provides, information under the control of the cloud service customer is accessed or processed without that customer's intent, select the external contractor on that basis, and where necessary specify the location at which the information handled by the cloud service customer is handled, together with the governing law and jurisdiction stipulated in the contract.4

The awareness is right there in the text. Foreign law can reach in and produce access nobody intended. It is not that the government has failed to notice the problem. The prescription, though, is not "store it in Japan". It is: assess the risk, choose your contractor accordingly, and where necessary pin down the place of handling and the governing law and jurisdiction by contract.

The phrase that catches on me every time is "where necessary". Necessary in whose judgement? The clause does not say. A provider that reasons its way to "not necessary in our case" can go through an audit without ever specifying a location. I do not think that deserves criticism, because it follows naturally from what a baseline standard is. A baseline lays the floor, and how far above the floor you go is left to the contract for each deal. Which means the work of arguing that it is necessary stays with the customer. Reading "it is on the ISMAP list, so we are fine" leaves that work undone by anyone at all.

Put the two clauses side by side and the shape of the requirement comes into focus. Know where your data is. Assess whose law reaches it. Where necessary, fix the place and the law in the contract. What is being asked for is knowledge, assessment and, when warranted, an agreement. It was designed as a governance problem, not a geography problem.

The government does write that servers abroad can be seized, just not inside ISMAP

At this point a fair question arises: does the Japanese government simply not care whether data sits abroad? It cares. The document that says so is not the ISMAP control standard, and that is the whole of the difference.

The Digital Agency's Digital Society Promotion Standard Guideline DS-920, "Guidelines on the Procurement and Use of Generative AI for the Evolution and Innovation of Government Administration" (行政の進化と革新のための生成AIの調達・利活用に係るガイドライン), reached version 2.0 by a decision of the steering committee of the Digital Society Promotion Council on 12 June 2026, and came into force on 1 September 20265. It carries this note.

Where server equipment is installed outside Japan, local laws and regulations apply, and there is a possibility of censorship or seizure by the local government or similar bodies.5

Censorship and seizure, in a normative government document, in plain sight. The note is attached to an item that follows on from the administrative notice of 6 February 2025 issued by the secretariat of the steering committee of the Digital Society Promotion Council, on the use of generative AI such as DeepSeek in government work6. Even where no procurement is involved, the text says, the risks must be properly recognised and judgement exercised with advice sought from the national cyber office. The same point is repeated in the template sections that each ministry and agency uses when drawing up its own internal rules.

So Japan has not dropped this question. It has filed it somewhere else. ISMAP assesses whether the provider's controls are implemented and operating. What to do about servers being abroad is picked up by the user-side guideline and by each ministry's own security policy. As a division of labour it holds together perfectly well.

The awkward part is that the division is invisible from outside government. When a private company picks a cloud service, what it has in hand is the convenient list, and nothing else. DS-920 is not a norm that applies to a private company at all. The layer that was supposed to carry the user-side judgement does not exist in the private sector, and the provider-side assessment result walks off on its own. "A service the government approved" ends up carrying meaning that was never packed into it.

How should a private company fill that gap? My view is that there is no substitute for tracing, once, how far foreign law actually reaches into your own setup. Read the US CLOUD Act, China's National Intelligence Law and Article 48 of the GDPR as texts and it becomes obvious how differently each of them reaches. I went through those clause by clause in which government can reach your data abroad. For the constraint that sits one step earlier, which is where the processing runs rather than where the data rests, there is can you actually run an LLM inside Japan. Think of it as filling in the blank that the standard left open when it wrote "where necessary".

The standard is silent, but the application form is not

Here I want to revise my assessment of the program upwards a little. It is true that the control standard carries no location requirement. But ISMAP does put the question squarely to applicants at the registration stage.

Clause 3.4 of the ISMAP cloud service registration rules lists six categories of information an applicant must supply on top of the statement of assertion. Information on capital relationships and officers. The risk of laws and regulations other than domestic law being applied. Governing law and jurisdiction. Inspection by third parties. Other certifications held. And information on generative AI7. The second and third of those are precisely the subject matter of clause 15.1.1.16.B. What the control standard softened with "where necessary" is set up at the entrance as a mandatory submission.

What makes this useful in practice is how far the information travels. Clause 3.8 of the registration rules provides that the existence of an improvement plan, items (1) to (4) and (6) of clause 3.4, the service name, the scope of the assertion, the controls for the control objectives being implemented, the audit period and subsequent events are disclosed publicly on the list8. The risk of foreign law applying is in that set. So is governing law and jurisdiction. Item (5), other certifications held, is not in the enumeration.

That is worth knowing. "It is on the ISMAP list, therefore the data is in Japan" has nothing behind it. But "for a service on the ISMAP list, I can read what the provider itself has declared about which country's laws reach it" is entirely true. Rather than guessing, go and read the declaration. Since the control standard gives you nothing to stand on, this is a far firmer place to stand.

The mechanics of registration are worth a quick pass too, particularly if you are an overseas vendor considering the route. The applicant prepares the statement of assertion (Form 1) and the management representation letter (Form 2), and undergoes an audit7. The report on the results of the audit must be dated within three months of the last day of the audit period, and the application must be filed within one month of that date. The basic rules define audits as being of two kinds, an assessment of design and an assessment of operating effectiveness1. Applications are made in Japanese, and only the annex to the statement of assertion may be in either Japanese or English. The applicant has to be the party offering the service under its own name, and a certificate of registered matters is required, although that attachment can be omitted where the corporate number is entered on the application form9. These are small procedural points, but missing one of them costs you a cycle, so they are worth writing down.

ISMAP-LIU is not a smaller ISMAP

The other list, ISMAP-LIU, deserves a mention. It covers SaaS used to process operations and information carrying low risk, and it has its own list and its own registration rules110. People describe it to me as the lighter-weight ISMAP. Structurally it is more accurate to treat it as a different thing.

The largest difference is that an assessment on the user side is built into the scheme. Under LIU, government agencies assess the impact level of the operation and of the information handled in accordance with the impact assessment criteria in Appendix 3. Ahead of applying, the applicant has to confirm with the ISMAP operational support agency whether its service falls within the scope of ISMAP-LIU in the first place10. The deliverables differ as well. Form 19 is a report relating to an internal audit, and Form 20 is a notification of the assumed operations and the information to be handled. Working papers from the internal audit have to be retained for at least three years after the audit ends. An internal audit suffices instead of an external one, and in exchange you declare what work the service is expected to be used for and what information will ride on it. That is the design.

For a customer, the practically meaningful step is simply to confirm which of the two lists a service appears on. They travel under the same umbrella name, the ISMAP cloud service list, but the road each one took to get there is different. Designing enterprise AI platforms is what we spend our days on at ZEROCK, and in my experience whether a team makes this one check at the outset changes the precision of every conversation that follows.

Generative AI got decided somewhere other than the control standard

If you want a single illustration of where the centre of gravity of this program sits, the past eighteen months of generative AI policy is the one I would pick.

The registration rules moved first. Item 3.4(6), information on generative AI, was created on 1 April 20259. The ISMAP-LIU registration rules gained the same requirement on the same date, as item 3.4(5). On the LIU side the supplementary provisions include a one-year transitional measure, under which applications filed within a year of entry into force may submit that information in the Form 1 statement of assertion. The impression I take from the sequencing is of a program moving in a hurry.

Vendors have responded unevenly. Tallying the public lists on 6 September 2026, out of the 103 entries on the ISMAP cloud service list, 37 published information on generative AI. The remaining 66 are recorded as 無, meaning none. Among the 37, 23 provide a link to a PDF and 14 direct the reader to the scope of the assertion. On the ISMAP-LIU side, it is 2 out of 4. The list itself was last refreshed on 28 August 2026 according to the portal notices11. What you make of a bit over a third depends on where you sit, but one reading is not available: being on the ISMAP list does not mean the treatment of generative AI has been spelled out.

Through all of that, the control standard did not change once. The judgements about generative AI accumulated in the application items of the registration rules, in program guidance posted on the ISMAP portal, and in DS-920, which is a separate document altogether. The portal carries a note titled "points to bear in mind regarding generative AI services"12. And the revision history of DS-920 version 2.0 records, against clause 6.1.1, that "the description published on the ISMAP portal has been added as a footnote"5. Guidance from the portal was absorbed into a normative document as a footnote.

That footnote, number 23, says this. Where a cloud service provider is supplied with a generative AI model and offers the service on a generative AI development platform to which the provider itself applies security management functions covering the data the model handles, and where that development platform has been included within the scope of the assertion and registered under ISMAP, the security of the data handled by that generative AI service is normally deemed to be in a state satisfying ISMAP's security requirements. In that case there is no need to include each individual generative AI model offered within the scope of the assertion, and the models themselves do not necessarily have to be registered under ISMAP5.

Register the platform and you do not have to register every model running on it. In a world where models are swapped out every few months, a per-model registration requirement would have jammed the program solid. I think it is a realistic piece of drafting. At the same time, the body of DS-920 provides that where a cloud service handling information requiring confidentiality is procured, it should in principle be selected from the ISMAP cloud service list under the ISMAP-in-principle approach and that compliance with the guideline itself is separately required, and it goes out of its way to add that selecting from the list does not remove the need to comply with the guideline5.

Which brings the theme of this article back around. The list is an entrance, not an indulgence. Where the data sits, and the risks specific to generative AI, were both designed to be verified outside the list. The program says so plainly, and yet in the market the word "registered" has taken on weight it was never given. What is out of alignment is not the program. It is how we read it.

So what should you actually check?

Down to practice. When I am evaluating a cloud service or an AI platform, these are the five things I make a point of checking.

  1. Have you actually received the notification under clause 6.1.3.3.PB, meaning the provider's geographic locations and the list of countries in which your data may be stored?
  2. Have you read, yourself, the governing law and jurisdiction published on the list, and the declared risk of laws other than domestic law applying?
  3. Did you ask about storage and processing as separate questions? Storage inside Japan with inference running abroad is a perfectly ordinary architecture.
  4. Is the generative AI information field recorded as none, does it point you to the scope of the assertion, or is there a PDF?
  5. Which list is the service on, the ISMAP cloud service list or the ISMAP-LIU cloud service list?

None of these are questions a provider will resent. Items 1 and 2 concern information the program intends to be disclosed, and item 5 is written on the list itself if you open it. The reason they still get skipped, I think, is that nobody told buyers there was anything here to check.

One last thing on what looks likely to shift. The ISMAP control standard is currently at draft revision stage. The substance is a reflection of the revised international standards, specifically JIS Q 27001:2023, JIS Q 27002:2024 and ISO/IEC 27014:2020, together with a reduction in the number of controls. Public comment opened on 18 September 2025, the draft and accompanying materials were published on 25 December 2025, and reference material was added on 12 May 2026. The cover page of the draft still reads "last revised on ● ● of Reiwa ●", so neither a revision date nor an effective date has been fixed13.

The draft itself runs to 11 pages and does not include the detailed controls that make up chapter 5. Which means, honestly, that what becomes of 6.1.3.3.PB and 15.1.1.16.B cannot be determined from the published material. The direction of travel on control count is clear enough, so how the two location-related clauses are handled is worth following.

That the program does not require domestic storage is not bad news. The bad outcome is believing you are required to do something you are not, and skipping the checks that would actually have told you something. Know where the data is. Assess whose law reaches it. Where necessary, settle it by contract. Those three are all ISMAP ever asked for, and they happen to be a rather good template that a private company can lift straight into its own process. Before you look at whether a service is on the list, try writing those three out in your own organisation's words. If you cannot write them, what you have is not a vendor selection problem. It is a governance problem inside your own building.

If you want to work through your own AI platform, separating storage from processing and pinning down how far foreign law reaches, get in touch.

Footnotes

  1. ISMAP Basic Rules (3 June 2020, last revised 11 July 2025). The purpose of the programme is in 1.2; the underlying decision of the Cybersecurity Strategy Headquarters of 30 January 2020 and the operating structure are in 1.1; the ministries with ownership are in 1.4.4; delegation of administration to the ISMAP operational support agency is in 9.3; the principle that procuring agencies select from the ISMAP cloud service list is in 2.3; the definition of audits as being of two kinds, an assessment of design and an assessment of operating effectiveness, is in 1.4.10; the scope of ISMAP-LIU is in 1.3. The revision history records "11 July 2025, revision of 1.1, 1.4.4 and 1.4.5 in connection with the reorganisation of the Cabinet Cybersecurity Center". Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=20d0a7f22b8ecb50f0bbfd69fe91bff5 2 3 4

  2. ISMAP Control Standard (45 pages in total). The occurrence counts given in the body are figures we measured ourselves by retrieving the PDF and extracting its text (日本 0 hits, 国外 0 hits, 越境 0 hits, 国内 3 hits, 海外 1 hit). The extraction was carried out twice using different methods. The fact that the control standard is built on the Common Standards for Information Security Measures for Government Agencies and Related Agencies (FY2023 edition), and that the single hit for 海外 is a reference to a US standard, are both from the same PDF. Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=9a9431de2bf9fa90f0bbfd69fe91bfa7

  3. ISMAP Control Standard, clause 6.1.3.3.PB. The quotation is a rendering of the original Japanese text. Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=9a9431de2bf9fa90f0bbfd69fe91bfa7

  4. ISMAP Control Standard, clause 15.1.1.16.B. A control placed in chapter 15, which deals with supplier relationships. The quotation is a rendering of the original Japanese text. Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=9a9431de2bf9fa90f0bbfd69fe91bfa7

  5. Digital Society Promotion Standard Guideline DS-920, "Guidelines on the Procurement and Use of Generative AI for the Evolution and Innovation of Government Administration", version 2.0 (decided by the steering committee of the Digital Society Promotion Council on 12 June 2026). The requirement to select in principle from the ISMAP cloud service list while separately complying with the guideline is in 6.1.1②; the treatment where a generative AI development platform has been included within the scope of the assertion is in footnote 23 to the same item; the note on server equipment installed outside Japan and on seeking advice from the national cyber office is in 6.1.1④; entry into force on 1 September 2026 and application of the AI governance framework from 1 July 2026 are in the supplementary provisions; "the description published on the ISMAP portal has been added as a footnote" appears in the revision history for 6.1.1. The quotations are renderings of the original Japanese text. Retrieved 6 September 2026. https://www.digital.go.jp/news/decb64eb-f26e-41cb-8d37-f3dd173108b8 and the PDF at https://www.digital.go.jp/assets/contents/node/information/field_ref_resources/decb64eb-f26e-41cb-8d37-f3dd173108b8/59054b35/20260612_resources_standard_guidelines_guideline_01.pdf 2 3 4 5

  6. "Advisory on the use of generative AI such as DeepSeek in business operations (administrative notice)", 6 February 2025, secretariat of the steering committee of the Digital Society Promotion Council. Retrieved 6 September 2026. https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/d2a5bbd2-ae8f-450c-adaa-33979181d26a/e7bfeba7/20250206_councils_social-promotion-executive_outline_01.pdf

  7. ISMAP Cloud Service Registration Rules. Preparation of the statement of assertion and the management representation letter and undergoing an audit are in 3.1; the six categories of information the applicant must provide (capital relationships and officers, the risk of laws and regulations other than domestic law being applied, governing law and jurisdiction, inspection by third parties, other certifications held, and information on generative AI) are in 3.4; the requirement that the report on the results of the audit be dated within three months of the last day of the audit period is in 3.2; the requirement to apply within one month of that date is in 4.2. Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=a4d0a7f22b8ecb50f0bbfd69fe91bfea 2

  8. ISMAP Cloud Service Registration Rules, clause 3.8. The provision setting the scope of information disclosed publicly on the list, enumerating items (1) to (4) and (6) of clause 3.4; item (5), other certifications held, is not included. Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=a4d0a7f22b8ecb50f0bbfd69fe91bfea

  9. ISMAP Cloud Service Registration Rules, revision history ("1 April 2025, creation of 3.4(6)"), together with 3.9 (application in Japanese, with only the annex to the statement of assertion permitted in either Japanese or English), 3.10, 3.12 and 4.1(1) (certificate of registered matters, the attachment of which may be omitted where the corporate number is entered on the application form). Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=a4d0a7f22b8ecb50f0bbfd69fe91bfea 2

  10. ISMAP-LIU Cloud Service Registration Rules (established 1 November 2022, last revised 9 September 2025). Confirmation of eligibility with the ISMAP operational support agency ahead of application is in 2.2; the mechanism by which government agencies carry out impact assessments in accordance with the impact assessment criteria in Appendix 3 is in 2.4 and 2.5; Form 19 (report relating to an internal audit) and Form 20 (notification of assumed operations and information handled) are in 3.4(6) and (7); retention of internal audit working papers for three years is in 3.5(7); information on generative AI is in 3.4(5) (created 1 April 2025, with a one-year transitional measure in the supplementary provisions). Retrieved 6 September 2026. https://www.ismap.go.jp/csm/sys_attachment.do?sys_id=8cd0a7f22b8ecb50f0bbfd69fe91bf3e 2

  11. ISMAP Cloud Service List and ISMAP-LIU Cloud Service List. The counts given in the body (37 of the 103 ISMAP entries publishing information on generative AI, of which 23 link to a PDF and 14 direct the reader to the scope of the assertion, with 66 recorded as none; 2 of 4 on ISMAP-LIU) are figures we tallied from the public data on 6 September 2026. The update date of the list is based on the portal notices (updated 28 August 2026). Retrieved 6 September 2026. https://www.ismap.go.jp/csm?id=cloud_service_list

  12. ISMAP portal, "Programme guidance: points to bear in mind regarding generative AI services" (article number KB0011070). The page is rendered with JavaScript and its body text could not be retrieved as text, so no verbatim quotation from it is used in this article. The account of generative AI development platforms is sourced to footnote 23 of DS-920 version 2.0. Retrieved 6 September 2026. https://www.ismap.go.jp/csm?id=kb_article_view&sysparm_article=KB0011070

  13. "(Draft) ISMAP Control Standard" and the accompanying reference materials (public comment opened 18 September 2025; national cyber office, Digital Agency, Ministry of Internal Affairs and Communications, Ministry of Economy, Trade and Industry). The fact that the cover of the draft reads "3 June 2020 (last revised on ● ● of Reiwa ●)" with the date left undetermined, that 1.2 records the reflection of JIS Q 27001:2023, JIS Q 27002:2024 and ISO/IEC 27014:2020, and that the reference material states the reduction in the number of controls, are all from those materials. The opening of public comment (18 September 2025), the publication of the draft and accompanying materials (25 December 2025) and the addition of reference material (12 May 2026) are from the notices on the ISMAP portal. The draft itself runs to 11 pages and does not include the detailed controls of chapter 5. Retrieved 6 September 2026. https://public-comment.e-gov.go.jp/pcm/download?seqNo=0000299111

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

Ready to optimize your workflows with AI?

Take our free 3-minute assessment to evaluate your AI readiness across strategy, data, and talent.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Learn More About ZEROCK

Discover the features and case studies for ZEROCK.

Related Articles