Âé¶¹´«Ã½ ??????
Âé¶¹´«Ã½ ?????? ????
Âé¶¹´«Ã½? ??? ?????? ????? ??? ?? ? ???? ??? ????, ?? ???? ??? ??? ????, ???? ?? ?? ???? ???? ?? ??? ??? ?? ?? ? ?? ???? ?????.
???? ?? ?????? ???
SOC 1
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ VNDLY
SOC(Service Organization Controls) 1 ?????? ??? ??? ?? ??? ?? ??? ?????. ??? ??? ?? ??? ?? ?? ??? ?? ?? ????.
SOC 1 Type II ???? ISAE(International Standard on Assurance Engagements) 3402(??? ??? ??? ?? ?? ???) ??? ?? ?????.?SOC 1 ???? Âé¶¹´«Ã½ ?????? ???? ??????? ???? ??? ?? ? ?? ???? ????.
SOC 2
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY
SOC 2 Type II ?????? ?3?? ??? Âé¶¹´«Ã½ ?? ??? ?? ???? ??? ??? ?????.
SOC 2 ???? ?????????(AICPA) TSC(Trust Services Criteria)? ???? ??, AICPA AT Section 101(?? ??)? ???? ?? ?????.?SOC 2 ???? Âé¶¹´«Ã½ ??????? ??? ?? ???? ???? ?? ???? ???? ??? ?? ? ?? ???? ??? ????. Âé¶¹´«Ã½ ?????? ?? SOC 2 ???? ?? TSC ??(??, ???, ?? ??, ?? ???, ???? ??)? ????. ??, ? ?????? SOC 2+ Additional Subject Matter ????? ??? NIST CSF(Cybersecurity Framework) ? NIST 800-171? ????. ???? ? ?????? Âé¶¹´«Ã½ ??? ???? ???? ?? ?????.
SOC 3
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ Strategic Sourcing
AICPA? ?????? ???? ???? ??? ?? ?? ?? ? ???? ??? ?? SOC 3 ?????? ??????.
SOC 3 ???? Âé¶¹´«Ã½ ?? ??? ?? ???? ???? ?3?? ?????. ????? ?? ??? ? ?????? ?? ???? ??, ???, ?? ??, ?? ???, ???? ??? ?? Âé¶¹´«Ã½ ?? ??? ????? ?????.
Âé¶¹´«Ã½ ?????? ??? ?? SOC 3 ???? ?????.
Âé¶¹´«Ã½ Adaptive Planning? ?? SOC 3 ???? ?????.?
Âé¶¹´«Ã½ Peakon Employee Voice? ?? SOC 3 ???? ?????.
Âé¶¹´«Ã½ Strategic Sourcing? ?? SOC 3 ???? ?????.
ISO 27001
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ VNDLY, Âé¶¹´«Ã½ Peakon Employee Voice
Âé¶¹´«Ã½? ?? ?? ?? ???(ISMS)? ? ???? ???? ? ?? ?? ?? ?? ??? ??? ?????.?
Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice? ?? Âé¶¹´«Ã½? ?? ISO 27001 ??? ?????.
VNDLY? ?? Âé¶¹´«Ã½? ISO 27001 ??? ?????.
ISO 27017
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning
? ??? ???? ??? ????? ? ??? ???? ?? ?? ??? ?? ?? ? ?? ??? ?????.
Âé¶¹´«Ã½ ?????? ?? ? Âé¶¹´«Ã½ Adaptive Planning? ?? Âé¶¹´«Ã½? ?? ISO 27017 ??? ?????.
ISO?27018
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning
? ??? ?? ??? ??? ???? ??? ???? ?? ?????.
Âé¶¹´«Ã½ ?????? ?? ? Âé¶¹´«Ã½ Adaptive Planning? ?? Âé¶¹´«Ã½? ?? ISO 27018 ??? ?????.
ISO?27701
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning
? ??? ISO/IEC 27001? ????? ???? ?? ???(PIMS) ?? ? ?? ??? ?? ??? ??? ?????.
Âé¶¹´«Ã½ ?????? ?? ? Âé¶¹´«Ã½ Adaptive Planning? ?? Âé¶¹´«Ã½? ?? ISO 27701 ??? ?????.
TRUSTe ?????? ???? ?? ? ??? ???? ??
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing
Âé¶¹´«Ã½? TRUSTe ?????? ???? ?? ? ??? ???? ???? ????? ???? ????.
Âé¶¹´«Ã½? ?? ????? ? SIG ????? ?? ??? ???? ?? ? ??? ???? ????? ??? ?? ??? ?? ? ?? ??, ???? OECD ???? ?? ?????, APEC ???? ?? ?????, ?? ?? ???? ???(GDPR), ?? HIPAA(Health Insurance Portability and Accountability Act), ISO 27001 ?? ?? ?? ??? ?? ??, ? ?? ? ?? ???? ??? ? ??? ???? ??? ??? ? ????.
Âé¶¹´«Ã½? TRUSTe ? ?????.
SIG ???
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY
SIG(Standardized Information Gathering) ???? ??? ?? ?? ??? ? ???? ?? ?? ? ??? ??? ???? ? ???? ?? ??? ??? ??? ????.
SIG? ?3? ?? ?? ?? ??? ??? Shared Assessments?? ?????. Âé¶¹´«Ã½? ?? SIG ?? ??? ???? Âé¶¹´«Ã½ ?? ??? ?? ??? ??? ???? ???? ???? ???? ?????. ??? Âé¶¹´«Ã½ Community?? ? ???? ? ????.
NIST CSF? NIST 800-171
?? ??: Âé¶¹´«Ã½ ?????? ??
NIST CSF? ???? ??? ?? ??? ? ????? ??, ??, ??? ??? ?? ??? ?????. NIST ???? ?? ?????? ??? ???? ?? ????? ???? ???? ? ??? ??? ?????. NIST 800-171 ??? ?? ?? ??? ?? ?? ??? ? ???? ??? ?? ?? ?? ??(Controlled Unclassified Information)? ??? ?? ?????.
Âé¶¹´«Ã½? Âé¶¹´«Ã½? SOC 2 ??? NIST CSF, NIST PF ? NIST 800-171 ??? ????, ? ??? ?? ??? Âé¶¹´«Ã½ SOC 2+ ???? ??????.
TrustArc ? ????? ??
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing
Âé¶¹´«Ã½? ????? ??? ???? ????. Âé¶¹´«Ã½? ????? ?? ?3? ?? ???? TRUSTe? ?????.
Âé¶¹´«Ã½? ????? ?? ? ?????.
EU ???? ????
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning
EU ???? ????(CCoC)? ???? ??? ???(CSP)? GDPR ?????? ?? ??? ?? ??? ???? ???? ????.
?? ID: 2019LVL02SCOPE001
Âé¶¹´«Ã½ ? ?????.
HIPAA
?? ??: Âé¶¹´«Ã½ ?????? ??
Âé¶¹´«Ã½? Âé¶¹´«Ã½ ?????? ??? ?? HIPAA(Health Insurance Portability and Accountability Act) ?3? ??? ??????. ?? Âé¶¹´«Ã½? HIPAA ?????? ????? ?? ?? ?? ?? ? ?? ??? ??, ???, ??? ??? ??? ??? ???? ??? ?????.
FedRAMP Moderate
?? ??: Âé¶¹´«Ã½ ?????? ??
FedRAMP(Federal Risk and Authorization Management Program)? ?? ??? IT ??? ???? ?? ???? ????? ???? ??? ???????. FedRAMP? ???? ??? ?? ? ??? ???? ???? ??? ?????. ?? ??? ? ????? ?? ?? ???? ?????? ??? ???? ?? ???? ??? ??? ? ????.
Âé¶¹´«Ã½? Âé¶¹´«Ã½ Government Cloud? ?? ?? ?? ???? FedRAMP ?? Moderate ??? ??????.
G-Cloud
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Peakon Employee Voice
G-Cloud ?????? ?? ??? ???? ?? ??? ??? ? ?????.
G-Cloud? ???? ?? ??? ???? ?? ?? ??? ??? ???? ?? ?? ? ???? ???? ???? ??? ?????. G-Cloud ?????? ?? ??? CSS(Crown Commercial Services)?? ? 1? ???????.
?? ?? ?? ??? CCS ??? ??????? ?? Âé¶¹´«Ã½ ??? ??? ??? ? ????.
Cyber Essentials Plus
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY
Cyber Essentials Plus? ?? ??? ???? ???? ?? ??? ??? ???? ??? ??? ?? ?? ??? ?? ?? ???????.
Cyber Essentials Plus ? ?????.
Australian IRAP
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning
?? ??? ???? ???? ??? ICT ??? ??? ?? ??? ????? ?????. ??? ???? ISM(Information Security Manual) ? PSPF(Protective Security Policy Framework)? ?? ??????. ?? ??? ?? ??(ACSC)? ???? IRAP(Infosec Registered Assessors Program)?? ??? ISM ? PSPF ??? ???? ???? ??? ?? ???? ?????.
Âé¶¹´«Ã½? ?3? ???? ???? Âé¶¹´«Ã½ ???? ??? ???? PROTECTED ???? ISM ? PSPF ??? ???? ?? IRAP ??? ?????.
CSA STAR ?? ??
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY
CSA(Cloud Security Alliance) STAR(Security, Trust & Assurance Registry) CAIQ(Consensus Assessments Initiative Questionnaire) ?? ??? ?? ?? ? ??? ?? ?? ??? ?? ?? ?? ??(CSA STAR CAIQ)? ??? ??? ????.
Âé¶¹´«Ã½? 2??? CSA STAR CAIQ ?? ??? ???? ???? Âé¶¹´«Ã½ ?? ??? ?? ??? ??? ?????. Âé¶¹´«Ã½ ??? ? ???? ?? Âé¶¹´«Ã½ ?? ??? ? ???? ??? ? ????.
TISAX
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing
?????????(VDA)? ???? ?? TISAX(Trusted Information Security Assessment Exchange)? ?????. ? ??? ?? ??? ??? ?? ?? ???? ?? ???? ???? ?? ??? ?????.
??? ?? ??? ? ????.
CCCS CSP ITS ??
?? ??: Âé¶¹´«Ã½ ?????? ??
??? ??? ?? ??(CCCS)? ??? ??(GC) ?? ? ??? CSP ??? ??? ????? ???? ??? ???(CSP) ?? ?? ??(ITS) ?? ????? ??????. CCCS? CSP? ???, ???, ??? ITS ??? ?? ??? ??? ?????. ? ????? ?? ???? ? ??? ??? ??? ??? ???? ??/??? ?? ??? ?????? ?????. ?? ?? ??? ??? ???(Treasury Board of Canada Secretariat)?? ???? PB/M/M(Protected B, Medium Integrity, and Medium Availability) ??? ?????.
TX-RAMP
?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY
TX-RAMP(Texas Risk and Authorization Management Program)? ??? ? ?? ??? ???? ???? ???? ?? ? ???? ?? ??? ???? DIR ???????. ???? ??? ???? ??? DIR ?????? ???? ???? ??????? ???? ???. TX-RAMP? ?? ?? 475? ??? ???? ???????.
Âé¶¹´«Ã½? TX-RAMP ?? 2 ??? ?????.
??? ??