diff --git a/docs/compliance/CERTIFICATION_ROADMAP.md b/docs/compliance/CERTIFICATION_ROADMAP.md new file mode 100644 index 0000000..3c416c2 --- /dev/null +++ b/docs/compliance/CERTIFICATION_ROADMAP.md @@ -0,0 +1,43 @@ +# CASAN Certification and Audited-Operations Roadmap + +## Claim rule + +CASAN must not claim a certification, audit result, compliance attestation, or +government-cloud eligibility until the named certification body, assessor or +procurement process has completed it for the relevant legal entity and service +scope. + +## Roadmap + +| Stage | Objective | Evidence to prepare | Exit evidence | +|---|---|---|---| +| Paid PoC | Answer security questionnaires consistently | architecture, data flow, inventory, SDLC policy, incident/backup/patch procedures, known limitations | customer PoC acceptance; no certification claim | +| Enterprise pilot | Establish repeatable ISMS-like operations | asset/owner register, risk register, access reviews, vulnerability management, change approvals, restore drills, supplier register | internal control review and remediation log | +| ISO/IEC 27001 readiness | Scope an information-security management system | statement of applicability, policies, risk treatment, training, internal audit, management review | accredited certification audit decision | +| Cloud privacy readiness | Assess cloud PII processing where in scope | processor/subprocessor records, retention/deletion controls, encryption/KMS evidence, privacy impact assessment | applicable ISO/IEC 27017/27018 or equivalent assessment decision | +| AI management readiness | Establish AI management-system controls | AI risk register, human oversight, model/provider evaluation, transparency/accountability evidence | ISO/IEC 42001 scope and audit decision, if pursued | +| Government procurement | Meet exact customer/government service requirements | service-specific security evidence, residency, operational audit evidence | ISMAP or other required procurement assessment, if applicable | + +## Operating-process baseline + +Before external audit, maintain versioned records for access provisioning, +production changes, release provenance, incident handling, patch/vulnerability +management, vendor review, Evidence Pack retention, backup/restore drills, +availability review and management review. Each record must identify an owner, +date, scope and retained evidence. + +## Ownership + +| Area | Accountable owner | +|---|---| +| Security management system and risk treatment | Security officer | +| Privacy/APPI record | Privacy/legal owner | +| Release, SLSA/provenance and CI evidence | Engineering/release owner | +| Incident/on-call and DR | Operations owner | +| Vendor/model/provider due diligence | Procurement + security owner | + +## Current boundary + +The repository contains technical controls and templates; it is not evidence of +an audited operating system. A certification roadmap should be revisited after +each customer deployment because scope, service model and data flows change. diff --git a/docs/plans/CASAN_BACKLOG_STATUS.md b/docs/plans/CASAN_BACKLOG_STATUS.md index 17eedfc..34d8038 100644 --- a/docs/plans/CASAN_BACKLOG_STATUS.md +++ b/docs/plans/CASAN_BACKLOG_STATUS.md @@ -73,6 +73,7 @@ |---|:--:|---| | APPI/data-processing documentation | 🟡 template ready | `docs/compliance/APPI_DATA_PROCESSING.md` records the customer/project/model data register, retention, transfer and incident-review evidence. Complete and approve it with the Japanese privacy/legal owner for each production tenant. | | Japanese SLA/support/escalation | 🟡 draft ready | `docs/jp-poc/07_本番SLA・サポート・エスカレーション案.md` defines severity, ownership and evidence expectations. Finalize service hours, credits, uptime, RPO/RTO and 24x7 coverage only after managed operations/DR are proven. | +| Certification and audited operations roadmap | 🟡 roadmap ready | `docs/compliance/CERTIFICATION_ROADMAP.md` maps PoC → pilot → ISO/cloud privacy/AI management/government procurement evidence. It expressly forbids claims before the relevant accredited audit or procurement process completes. | --- ## Trần điểm & điều kiện lên "Strong (81+)"