docs: add certification and audited operations roadmap
This commit is contained in:
@@ -0,0 +1,43 @@
|
|||||||
|
# CASAN Certification and Audited-Operations Roadmap
|
||||||
|
|
||||||
|
## Claim rule
|
||||||
|
|
||||||
|
CASAN must not claim a certification, audit result, compliance attestation, or
|
||||||
|
government-cloud eligibility until the named certification body, assessor or
|
||||||
|
procurement process has completed it for the relevant legal entity and service
|
||||||
|
scope.
|
||||||
|
|
||||||
|
## Roadmap
|
||||||
|
|
||||||
|
| Stage | Objective | Evidence to prepare | Exit evidence |
|
||||||
|
|---|---|---|---|
|
||||||
|
| Paid PoC | Answer security questionnaires consistently | architecture, data flow, inventory, SDLC policy, incident/backup/patch procedures, known limitations | customer PoC acceptance; no certification claim |
|
||||||
|
| Enterprise pilot | Establish repeatable ISMS-like operations | asset/owner register, risk register, access reviews, vulnerability management, change approvals, restore drills, supplier register | internal control review and remediation log |
|
||||||
|
| ISO/IEC 27001 readiness | Scope an information-security management system | statement of applicability, policies, risk treatment, training, internal audit, management review | accredited certification audit decision |
|
||||||
|
| Cloud privacy readiness | Assess cloud PII processing where in scope | processor/subprocessor records, retention/deletion controls, encryption/KMS evidence, privacy impact assessment | applicable ISO/IEC 27017/27018 or equivalent assessment decision |
|
||||||
|
| AI management readiness | Establish AI management-system controls | AI risk register, human oversight, model/provider evaluation, transparency/accountability evidence | ISO/IEC 42001 scope and audit decision, if pursued |
|
||||||
|
| Government procurement | Meet exact customer/government service requirements | service-specific security evidence, residency, operational audit evidence | ISMAP or other required procurement assessment, if applicable |
|
||||||
|
|
||||||
|
## Operating-process baseline
|
||||||
|
|
||||||
|
Before external audit, maintain versioned records for access provisioning,
|
||||||
|
production changes, release provenance, incident handling, patch/vulnerability
|
||||||
|
management, vendor review, Evidence Pack retention, backup/restore drills,
|
||||||
|
availability review and management review. Each record must identify an owner,
|
||||||
|
date, scope and retained evidence.
|
||||||
|
|
||||||
|
## Ownership
|
||||||
|
|
||||||
|
| Area | Accountable owner |
|
||||||
|
|---|---|
|
||||||
|
| Security management system and risk treatment | Security officer |
|
||||||
|
| Privacy/APPI record | Privacy/legal owner |
|
||||||
|
| Release, SLSA/provenance and CI evidence | Engineering/release owner |
|
||||||
|
| Incident/on-call and DR | Operations owner |
|
||||||
|
| Vendor/model/provider due diligence | Procurement + security owner |
|
||||||
|
|
||||||
|
## Current boundary
|
||||||
|
|
||||||
|
The repository contains technical controls and templates; it is not evidence of
|
||||||
|
an audited operating system. A certification roadmap should be revisited after
|
||||||
|
each customer deployment because scope, service model and data flows change.
|
||||||
@@ -73,6 +73,7 @@
|
|||||||
|---|:--:|---|
|
|---|:--:|---|
|
||||||
| APPI/data-processing documentation | 🟡 template ready | `docs/compliance/APPI_DATA_PROCESSING.md` records the customer/project/model data register, retention, transfer and incident-review evidence. Complete and approve it with the Japanese privacy/legal owner for each production tenant. |
|
| APPI/data-processing documentation | 🟡 template ready | `docs/compliance/APPI_DATA_PROCESSING.md` records the customer/project/model data register, retention, transfer and incident-review evidence. Complete and approve it with the Japanese privacy/legal owner for each production tenant. |
|
||||||
| Japanese SLA/support/escalation | 🟡 draft ready | `docs/jp-poc/07_本番SLA・サポート・エスカレーション案.md` defines severity, ownership and evidence expectations. Finalize service hours, credits, uptime, RPO/RTO and 24x7 coverage only after managed operations/DR are proven. |
|
| Japanese SLA/support/escalation | 🟡 draft ready | `docs/jp-poc/07_本番SLA・サポート・エスカレーション案.md` defines severity, ownership and evidence expectations. Finalize service hours, credits, uptime, RPO/RTO and 24x7 coverage only after managed operations/DR are proven. |
|
||||||
|
| Certification and audited operations roadmap | 🟡 roadmap ready | `docs/compliance/CERTIFICATION_ROADMAP.md` maps PoC → pilot → ISO/cloud privacy/AI management/government procurement evidence. It expressly forbids claims before the relevant accredited audit or procurement process completes. |
|
||||||
---
|
---
|
||||||
|
|
||||||
## Trần điểm & điều kiện lên "Strong (81+)"
|
## Trần điểm & điều kiện lên "Strong (81+)"
|
||||||
|
|||||||
Reference in New Issue
Block a user