Files
CASAN/docs/compliance/CERTIFICATION_ROADMAP.md

2.7 KiB

CASAN Certification and Audited-Operations Roadmap

Claim rule

CASAN must not claim a certification, audit result, compliance attestation, or government-cloud eligibility until the named certification body, assessor or procurement process has completed it for the relevant legal entity and service scope.

Roadmap

Stage Objective Evidence to prepare Exit evidence
Paid PoC Answer security questionnaires consistently architecture, data flow, inventory, SDLC policy, incident/backup/patch procedures, known limitations customer PoC acceptance; no certification claim
Enterprise pilot Establish repeatable ISMS-like operations asset/owner register, risk register, access reviews, vulnerability management, change approvals, restore drills, supplier register internal control review and remediation log
ISO/IEC 27001 readiness Scope an information-security management system statement of applicability, policies, risk treatment, training, internal audit, management review accredited certification audit decision
Cloud privacy readiness Assess cloud PII processing where in scope processor/subprocessor records, retention/deletion controls, encryption/KMS evidence, privacy impact assessment applicable ISO/IEC 27017/27018 or equivalent assessment decision
AI management readiness Establish AI management-system controls AI risk register, human oversight, model/provider evaluation, transparency/accountability evidence ISO/IEC 42001 scope and audit decision, if pursued
Government procurement Meet exact customer/government service requirements service-specific security evidence, residency, operational audit evidence ISMAP or other required procurement assessment, if applicable

Operating-process baseline

Before external audit, maintain versioned records for access provisioning, production changes, release provenance, incident handling, patch/vulnerability management, vendor review, Evidence Pack retention, backup/restore drills, availability review and management review. Each record must identify an owner, date, scope and retained evidence.

Ownership

Area Accountable owner
Security management system and risk treatment Security officer
Privacy/APPI record Privacy/legal owner
Release, SLSA/provenance and CI evidence Engineering/release owner
Incident/on-call and DR Operations owner
Vendor/model/provider due diligence Procurement + security owner

Current boundary

The repository contains technical controls and templates; it is not evidence of an audited operating system. A certification roadmap should be revisited after each customer deployment because scope, service model and data flows change.