docs: add certification and audited operations roadmap

This commit is contained in:
thanhnv
2026-07-18 00:22:52 +07:00
parent 2783a21338
commit 36158c5e34
2 changed files with 44 additions and 0 deletions
+43
View File
@@ -0,0 +1,43 @@
# CASAN Certification and Audited-Operations Roadmap
## Claim rule
CASAN must not claim a certification, audit result, compliance attestation, or
government-cloud eligibility until the named certification body, assessor or
procurement process has completed it for the relevant legal entity and service
scope.
## Roadmap
| Stage | Objective | Evidence to prepare | Exit evidence |
|---|---|---|---|
| Paid PoC | Answer security questionnaires consistently | architecture, data flow, inventory, SDLC policy, incident/backup/patch procedures, known limitations | customer PoC acceptance; no certification claim |
| Enterprise pilot | Establish repeatable ISMS-like operations | asset/owner register, risk register, access reviews, vulnerability management, change approvals, restore drills, supplier register | internal control review and remediation log |
| ISO/IEC 27001 readiness | Scope an information-security management system | statement of applicability, policies, risk treatment, training, internal audit, management review | accredited certification audit decision |
| Cloud privacy readiness | Assess cloud PII processing where in scope | processor/subprocessor records, retention/deletion controls, encryption/KMS evidence, privacy impact assessment | applicable ISO/IEC 27017/27018 or equivalent assessment decision |
| AI management readiness | Establish AI management-system controls | AI risk register, human oversight, model/provider evaluation, transparency/accountability evidence | ISO/IEC 42001 scope and audit decision, if pursued |
| Government procurement | Meet exact customer/government service requirements | service-specific security evidence, residency, operational audit evidence | ISMAP or other required procurement assessment, if applicable |
## Operating-process baseline
Before external audit, maintain versioned records for access provisioning,
production changes, release provenance, incident handling, patch/vulnerability
management, vendor review, Evidence Pack retention, backup/restore drills,
availability review and management review. Each record must identify an owner,
date, scope and retained evidence.
## Ownership
| Area | Accountable owner |
|---|---|
| Security management system and risk treatment | Security officer |
| Privacy/APPI record | Privacy/legal owner |
| Release, SLSA/provenance and CI evidence | Engineering/release owner |
| Incident/on-call and DR | Operations owner |
| Vendor/model/provider due diligence | Procurement + security owner |
## Current boundary
The repository contains technical controls and templates; it is not evidence of
an audited operating system. A certification roadmap should be revisited after
each customer deployment because scope, service model and data flows change.
+1
View File
@@ -73,6 +73,7 @@
|---|:--:|---|
| APPI/data-processing documentation | 🟡 template ready | `docs/compliance/APPI_DATA_PROCESSING.md` records the customer/project/model data register, retention, transfer and incident-review evidence. Complete and approve it with the Japanese privacy/legal owner for each production tenant. |
| Japanese SLA/support/escalation | 🟡 draft ready | `docs/jp-poc/07_本番SLA・サポート・エスカレーション案.md` defines severity, ownership and evidence expectations. Finalize service hours, credits, uptime, RPO/RTO and 24x7 coverage only after managed operations/DR are proven. |
| Certification and audited operations roadmap | 🟡 roadmap ready | `docs/compliance/CERTIFICATION_ROADMAP.md` maps PoC → pilot → ISO/cloud privacy/AI management/government procurement evidence. It expressly forbids claims before the relevant accredited audit or procurement process completes. |
---
## Trần điểm & điều kiện lên "Strong (81+)"