# CASAN Certification and Audited-Operations Roadmap ## Claim rule CASAN must not claim a certification, audit result, compliance attestation, or government-cloud eligibility until the named certification body, assessor or procurement process has completed it for the relevant legal entity and service scope. ## Roadmap | Stage | Objective | Evidence to prepare | Exit evidence | |---|---|---|---| | Paid PoC | Answer security questionnaires consistently | architecture, data flow, inventory, SDLC policy, incident/backup/patch procedures, known limitations | customer PoC acceptance; no certification claim | | Enterprise pilot | Establish repeatable ISMS-like operations | asset/owner register, risk register, access reviews, vulnerability management, change approvals, restore drills, supplier register | internal control review and remediation log | | ISO/IEC 27001 readiness | Scope an information-security management system | statement of applicability, policies, risk treatment, training, internal audit, management review | accredited certification audit decision | | Cloud privacy readiness | Assess cloud PII processing where in scope | processor/subprocessor records, retention/deletion controls, encryption/KMS evidence, privacy impact assessment | applicable ISO/IEC 27017/27018 or equivalent assessment decision | | AI management readiness | Establish AI management-system controls | AI risk register, human oversight, model/provider evaluation, transparency/accountability evidence | ISO/IEC 42001 scope and audit decision, if pursued | | Government procurement | Meet exact customer/government service requirements | service-specific security evidence, residency, operational audit evidence | ISMAP or other required procurement assessment, if applicable | ## Operating-process baseline Before external audit, maintain versioned records for access provisioning, production changes, release provenance, incident handling, patch/vulnerability management, vendor review, Evidence Pack retention, backup/restore drills, availability review and management review. Each record must identify an owner, date, scope and retained evidence. ## Ownership | Area | Accountable owner | |---|---| | Security management system and risk treatment | Security officer | | Privacy/APPI record | Privacy/legal owner | | Release, SLSA/provenance and CI evidence | Engineering/release owner | | Incident/on-call and DR | Operations owner | | Vendor/model/provider due diligence | Procurement + security owner | ## Current boundary The repository contains technical controls and templates; it is not evidence of an audited operating system. A certification roadmap should be revisited after each customer deployment because scope, service model and data flows change.