Âé¶¹´«Ã½


      








 














    

Âé¶¹´«Ã½ ??????

Âé¶¹´«Ã½ ?????? ????

Âé¶¹´«Ã½? ??? ?????? ????? ??? ?? ? ???? ??? ????, ?? ???? ??? ??? ????, ???? ?? ?? ???? ???? ?? ??? ??? ?? ?? ? ?? ???? ?????.

?????

???? ?? ?????? ???

AICPA SOC

SOC 1

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ VNDLY

SOC(Service Organization Controls) 1 ?????? ??? ??? ?? ??? ?? ??? ?????. ??? ??? ?? ??? ?? ?? ??? ?? ?? ????.

SOC 1 Type II ???? ISAE(International Standard on Assurance Engagements) 3402(??? ??? ??? ?? ?? ???) ??? ?? ?????.?SOC 1 ???? Âé¶¹´«Ã½ ?????? ???? ??????? ???? ??? ?? ? ?? ???? ????.

AICPA SOC

SOC 2

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY

SOC 2 Type II ?????? ?3?? ??? Âé¶¹´«Ã½ ?? ??? ?? ???? ??? ??? ?????.

SOC 2 ???? ?????????(AICPA) TSC(Trust Services Criteria)? ???? ??, AICPA AT Section 101(?? ??)? ???? ?? ?????.?SOC 2 ???? Âé¶¹´«Ã½ ??????? ??? ?? ???? ???? ?? ???? ???? ??? ?? ? ?? ???? ??? ????. Âé¶¹´«Ã½ ?????? ?? SOC 2 ???? ?? TSC ??(??, ???, ?? ??, ?? ???, ???? ??)? ????. ??, ? ?????? SOC 2+ Additional Subject Matter ????? ??? NIST CSF(Cybersecurity Framework) ? NIST 800-171? ????. ???? ? ?????? Âé¶¹´«Ã½ ??? ???? ???? ?? ?????.

AICPA SOC

SOC 3

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ Strategic Sourcing

AICPA? ?????? ???? ???? ??? ?? ?? ?? ? ???? ??? ?? SOC 3 ?????? ??????.

SOC 3 ???? Âé¶¹´«Ã½ ?? ??? ?? ???? ???? ?3?? ?????. ????? ?? ??? ? ?????? ?? ???? ??, ???, ?? ??, ?? ???, ???? ??? ?? Âé¶¹´«Ã½ ?? ??? ????? ?????.

Âé¶¹´«Ã½ ?????? ??? ?? SOC 3 ???? ?????.

Âé¶¹´«Ã½ Adaptive Planning? ?? SOC 3 ???? ?????.?

Âé¶¹´«Ã½ Peakon Employee Voice? ?? SOC 3 ???? ?????.

Âé¶¹´«Ã½ Strategic Sourcing? ?? SOC 3 ???? ?????.

?? ???

ISO 27001

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ VNDLY, Âé¶¹´«Ã½ Peakon Employee Voice

Âé¶¹´«Ã½? ?? ?? ?? ???(ISMS)? ? ???? ???? ? ?? ?? ?? ?? ??? ??? ?????.?

Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice? ?? Âé¶¹´«Ã½? ?? ISO 27001 ??? ?????.

VNDLY? ?? Âé¶¹´«Ã½? ISO 27001 ??? ?????.

??? ??? ???

ISO 27017

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning

? ??? ???? ??? ????? ? ??? ???? ?? ?? ??? ?? ?? ? ?? ??? ?????.

Âé¶¹´«Ã½ ?????? ?? ? Âé¶¹´«Ã½ Adaptive Planning? ?? Âé¶¹´«Ã½? ?? ISO 27017 ??? ?????.

??? ??? ???

ISO?27018

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning

? ??? ?? ??? ??? ???? ??? ???? ?? ?????.

Âé¶¹´«Ã½ ?????? ?? ? Âé¶¹´«Ã½ Adaptive Planning? ?? Âé¶¹´«Ã½? ?? ISO 27018 ??? ?????.

??? ??? ???

ISO?27701

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning

? ??? ISO/IEC 27001? ????? ???? ?? ???(PIMS) ?? ? ?? ??? ?? ??? ??? ?????.

Âé¶¹´«Ã½ ?????? ?? ? Âé¶¹´«Ã½ Adaptive Planning? ?? Âé¶¹´«Ã½? ?? ISO 27701 ??? ?????.

TRUSTe ?? ???? ??

TRUSTe ?????? ???? ?? ? ??? ???? ??

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing

Âé¶¹´«Ã½? TRUSTe ?????? ???? ?? ? ??? ???? ???? ????? ???? ????.

Âé¶¹´«Ã½? ?? ????? ? SIG ????? ?? ??? ???? ?? ? ??? ???? ????? ??? ?? ??? ?? ? ?? ??, ???? OECD ???? ?? ?????, APEC ???? ?? ?????, ?? ?? ???? ???(GDPR), ?? HIPAA(Health Insurance Portability and Accountability Act), ISO 27001 ?? ?? ?? ??? ?? ??, ? ?? ? ?? ???? ??? ? ??? ???? ??? ??? ? ????.

Âé¶¹´«Ã½? TRUSTe ? ?????.

??? ??? ???

SIG ???

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY

SIG(Standardized Information Gathering) ???? ??? ?? ?? ??? ? ???? ?? ?? ? ??? ??? ???? ? ???? ?? ??? ??? ??? ????.

SIG? ?3? ?? ?? ?? ??? ??? Shared Assessments?? ?????. Âé¶¹´«Ã½? ?? SIG ?? ??? ???? Âé¶¹´«Ã½ ?? ??? ?? ??? ??? ???? ???? ???? ???? ?????. ??? Âé¶¹´«Ã½ Community?? ? ???? ? ????.

nist

NIST CSF? NIST 800-171

?? ??: Âé¶¹´«Ã½ ?????? ??

NIST CSF? ???? ??? ?? ??? ? ????? ??, ??, ??? ??? ?? ??? ?????. NIST ???? ?? ?????? ??? ???? ?? ????? ???? ???? ? ??? ??? ?????. NIST 800-171 ??? ?? ?? ??? ?? ?? ??? ? ???? ??? ?? ?? ?? ??(Controlled Unclassified Information)? ??? ?? ?????.

Âé¶¹´«Ã½? Âé¶¹´«Ã½? SOC 2 ??? NIST CSF, NIST PF ? NIST 800-171 ??? ????, ? ??? ?? ??? Âé¶¹´«Ã½ SOC 2+ ???? ??????.

TRUSTe ?? ???? ??

TrustArc ? ????? ??

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing

Âé¶¹´«Ã½? ????? ??? ???? ????. Âé¶¹´«Ã½? ????? ?? ?3? ?? ???? TRUSTe? ?????.

Âé¶¹´«Ã½? ????? ?? ? ?????.

EU ???? COC

EU ???? ????

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning

EU ???? ????(CCoC)? ???? ??? ???(CSP)? GDPR ?????? ?? ??? ?? ??? ???? ???? ????.

?? ID: 2019LVL02SCOPE001

Âé¶¹´«Ã½ ? ?????.

HIPAA

HIPAA

?? ??: Âé¶¹´«Ã½ ?????? ??

Âé¶¹´«Ã½? Âé¶¹´«Ã½ ?????? ??? ?? HIPAA(Health Insurance Portability and Accountability Act) ?3? ??? ??????. ?? Âé¶¹´«Ã½? HIPAA ?????? ????? ?? ?? ?? ?? ? ?? ??? ??, ???, ??? ??? ??? ??? ???? ??? ?????.

fedramp

FedRAMP Moderate

?? ??: Âé¶¹´«Ã½ ?????? ??

FedRAMP(Federal Risk and Authorization Management Program)? ?? ??? IT ??? ???? ?? ???? ????? ???? ??? ???????. FedRAMP? ???? ??? ?? ? ??? ???? ???? ??? ?????. ?? ??? ? ????? ?? ?? ???? ?????? ??? ???? ?? ???? ??? ??? ? ????.

Âé¶¹´«Ã½? Âé¶¹´«Ã½ Government Cloud? ?? ?? ?? ???? FedRAMP ?? Moderate ??? ??????.

??? ??? ???

G-Cloud

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Peakon Employee Voice

G-Cloud ?????? ?? ??? ???? ?? ??? ??? ? ?????.

G-Cloud? ???? ?? ??? ???? ?? ?? ??? ??? ???? ?? ?? ? ???? ???? ???? ??? ?????. G-Cloud ?????? ?? ??? CSS(Crown Commercial Services)?? ? 1? ???????.

?? ?? ?? ??? CCS ??? ??????? ?? Âé¶¹´«Ã½ ??? ??? ??? ? ????.

Cyber Essentials Plus
cyber essentials plus

Cyber Essentials Plus

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY

Cyber Essentials Plus? ?? ??? ???? ???? ?? ??? ??? ???? ??? ??? ?? ?? ??? ?? ?? ???????.

Cyber Essentials Plus ? ?????.

irap

Australian IRAP

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning

?? ??? ???? ???? ??? ICT ??? ??? ?? ??? ????? ?????. ??? ???? ISM(Information Security Manual) ? PSPF(Protective Security Policy Framework)? ?? ??????. ?? ??? ?? ??(ACSC)? ???? IRAP(Infosec Registered Assessors Program)?? ??? ISM ? PSPF ??? ???? ???? ??? ?? ???? ?????.

Âé¶¹´«Ã½? ?3? ???? ???? Âé¶¹´«Ã½ ???? ??? ???? PROTECTED ???? ISM ? PSPF ??? ???? ?? IRAP ??? ?????.

??? ??? ???

CSA STAR ?? ??

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY

CSA(Cloud Security Alliance) STAR(Security, Trust & Assurance Registry) CAIQ(Consensus Assessments Initiative Questionnaire) ?? ??? ?? ?? ? ??? ?? ?? ??? ?? ?? ?? ??(CSA STAR CAIQ)? ??? ??? ????.

Âé¶¹´«Ã½? 2??? CSA STAR CAIQ ?? ??? ???? ???? Âé¶¹´«Ã½ ?? ??? ?? ??? ??? ?????. Âé¶¹´«Ã½ ??? ? ???? ?? Âé¶¹´«Ã½ ?? ??? ? ???? ??? ? ????.

tisax



TISAX

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing

?????????(VDA)? ???? ?? TISAX(Trusted Information Security Assessment Exchange)? ?????. ? ??? ?? ??? ??? ?? ?? ???? ?? ???? ???? ?? ??? ?????.

??? ?? ??? ? ????.

??? ??? ???

CCCS CSP ITS ??

?? ??: Âé¶¹´«Ã½ ?????? ??

??? ??? ?? ??(CCCS)? ??? ??(GC) ?? ? ??? CSP ??? ??? ????? ???? ??? ???(CSP) ?? ?? ??(ITS) ?? ????? ??????. CCCS? CSP? ???, ???, ??? ITS ??? ?? ??? ??? ?????. ? ????? ?? ???? ? ??? ??? ??? ??? ???? ??/??? ?? ??? ?????? ?????. ?? ?? ??? ??? ???(Treasury Board of Canada Secretariat)?? ???? PB/M/M(Protected B, Medium Integrity, and Medium Availability) ??? ?????.

??? ??? ???

TX-RAMP

?? ??: Âé¶¹´«Ã½ ?????? ??, Âé¶¹´«Ã½ Adaptive Planning, Âé¶¹´«Ã½ Strategic Sourcing, Âé¶¹´«Ã½ Peakon Employee Voice, Âé¶¹´«Ã½ VNDLY

TX-RAMP(Texas Risk and Authorization Management Program)? ??? ? ?? ??? ???? ???? ???? ?? ? ???? ?? ??? ???? DIR ???????. ???? ??? ???? ??? DIR ?????? ???? ???? ??????? ???? ???. TX-RAMP? ?? ?? 475? ??? ???? ???????.

Âé¶¹´«Ã½? TX-RAMP ?? 2 ??? ?????.


??? ??? ????? ???? ?????.