2.7 KiB
CASAN Certification and Audited-Operations Roadmap
Claim rule
CASAN must not claim a certification, audit result, compliance attestation, or government-cloud eligibility until the named certification body, assessor or procurement process has completed it for the relevant legal entity and service scope.
Roadmap
| Stage | Objective | Evidence to prepare | Exit evidence |
|---|---|---|---|
| Paid PoC | Answer security questionnaires consistently | architecture, data flow, inventory, SDLC policy, incident/backup/patch procedures, known limitations | customer PoC acceptance; no certification claim |
| Enterprise pilot | Establish repeatable ISMS-like operations | asset/owner register, risk register, access reviews, vulnerability management, change approvals, restore drills, supplier register | internal control review and remediation log |
| ISO/IEC 27001 readiness | Scope an information-security management system | statement of applicability, policies, risk treatment, training, internal audit, management review | accredited certification audit decision |
| Cloud privacy readiness | Assess cloud PII processing where in scope | processor/subprocessor records, retention/deletion controls, encryption/KMS evidence, privacy impact assessment | applicable ISO/IEC 27017/27018 or equivalent assessment decision |
| AI management readiness | Establish AI management-system controls | AI risk register, human oversight, model/provider evaluation, transparency/accountability evidence | ISO/IEC 42001 scope and audit decision, if pursued |
| Government procurement | Meet exact customer/government service requirements | service-specific security evidence, residency, operational audit evidence | ISMAP or other required procurement assessment, if applicable |
Operating-process baseline
Before external audit, maintain versioned records for access provisioning, production changes, release provenance, incident handling, patch/vulnerability management, vendor review, Evidence Pack retention, backup/restore drills, availability review and management review. Each record must identify an owner, date, scope and retained evidence.
Ownership
| Area | Accountable owner |
|---|---|
| Security management system and risk treatment | Security officer |
| Privacy/APPI record | Privacy/legal owner |
| Release, SLSA/provenance and CI evidence | Engineering/release owner |
| Incident/on-call and DR | Operations owner |
| Vendor/model/provider due diligence | Procurement + security owner |
Current boundary
The repository contains technical controls and templates; it is not evidence of an audited operating system. A certification roadmap should be revisited after each customer deployment because scope, service model and data flows change.