引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準3.2(上)です。
Criteria 3.2
Procedures exist to provide for backup, offsite storage, restoration, and disaster recovery consistent with the entity’s defined system availability and related security policies.
基準 3.2
定義されたシステムの可用性と関連するセキュリティポリシーと一致した、バックアップ、オフサイトストレージ、復旧そ して災害復旧手順が存在する。
Illustrative Controls
統制の実例
Management has implemented a comprehensive strategy for backup and restoration based on a review of business requirements. Backup procedures for the entity are documented and include redundant servers, daily incremental backups of each server, and a complete backup of the entire week’s changes on a weekly basis. Daily and
weekly backups are stored offsite in accordance with the entity’s system availability policies.
経営者は、ビジネス要件の評価に基づいて、バッ クアップと復元のための包括的な戦略を実装する。バックアップ手順が記載されて、冗長サーバー、各サー バーの毎日の増分バックアップ、および週単位で1週間の変更の完全なバックアップが含まれる。毎日および毎週のバックアップはエンティティのシステム の可用性ポリシーに応じてオフサイトに格納されます。
Disaster recovery and contingency plans are documented.
災害復旧及び危機管理計画は文書化されてい る。
公認内部監査人(CIA)tunetterのブログです。 内部監査の試行錯誤を記録していきます。
2010年5月17日月曜日
基準3.1(下)
引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準3.1(下)です。
Management maintains measures to protect against environmental factors (for example, fire, flood, dust, power failure, and excessive heat and humidity) based on its risk assessment. The entity’s controlled areas are protected against fire using both smoke detectors and a fire suppression system. Water detectors are installed within
the raised floor areas.
経営はリスクアセスメントに基づき、環境要因(例えば、火災、洪水、ほこり、電源断、過度の暑さと湿度)から保護する手法を維持する。統制された区域は煙探知機と消火システムの両方により火災から保護される。水探知機は上げ床の区域に設置される。
The entity site is protected against a disruption in power supply to the processing environment by both uninterruptible power supplies (UPS) and emergency power supplies (EPS). This equipment is tested semiannually.
現場は処理環境への電源供給断から無停電電源装置(UPS)と緊急電源(EPS)によって保護されている。
Preventive maintenance agreements and scheduled maintenance procedures are in place for key system hardware components.
予防保守合意と計画的保守手続は重要なシステムハードウェアコンポーネントについて存在する。
Vendor warranty specifications are complied with and tested to determine if the system is properly configured.
ベンダーの保証仕様は、システムが適切に 構成されているかどうかを決定するために遵守されテストされる。
Procedures to address minor processing errors, outages, and destruction of records are documented.
マイナーな処理エラーや停電、記録の破壊の処理手順は記録される。
Procedures exist for the identification, documentation, escalation, resolution, and review of problems.
認証、文書化、エスカレーション、決議そして問題の確認の手順が存在する。
Physical and logical security controls are implemented to reduce the opportunity for unauthorized actions that could impair system availability.
システムの可用性を損なう可能性のある不正行為の機会を減らすための物理的・論理的セキュリティ統制が実装される。
Management maintains measures to protect against environmental factors (for example, fire, flood, dust, power failure, and excessive heat and humidity) based on its risk assessment. The entity’s controlled areas are protected against fire using both smoke detectors and a fire suppression system. Water detectors are installed within
the raised floor areas.
経営はリスクアセスメントに基づき、環境要因(例えば、火災、洪水、ほこり、電源断、過度の暑さと湿度)から保護する手法を維持する。統制された区域は煙探知機と消火システムの両方により火災から保護される。水探知機は上げ床の区域に設置される。
The entity site is protected against a disruption in power supply to the processing environment by both uninterruptible power supplies (UPS) and emergency power supplies (EPS). This equipment is tested semiannually.
現場は処理環境への電源供給断から無停電電源装置(UPS)と緊急電源(EPS)によって保護されている。
Preventive maintenance agreements and scheduled maintenance procedures are in place for key system hardware components.
予防保守合意と計画的保守手続は重要なシステムハードウェアコンポーネントについて存在する。
Vendor warranty specifications are complied with and tested to determine if the system is properly configured.
ベンダーの保証仕様は、システムが適切に 構成されているかどうかを決定するために遵守されテストされる。
Procedures to address minor processing errors, outages, and destruction of records are documented.
マイナーな処理エラーや停電、記録の破壊の処理手順は記録される。
Procedures exist for the identification, documentation, escalation, resolution, and review of problems.
認証、文書化、エスカレーション、決議そして問題の確認の手順が存在する。
Physical and logical security controls are implemented to reduce the opportunity for unauthorized actions that could impair system availability.
システムの可用性を損なう可能性のある不正行為の機会を減らすための物理的・論理的セキュリティ統制が実装される。
2010年5月15日土曜日
基準3.0、3.1(上)
引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準3.0、3.1(上)です。
Criteria 3.0
Procedures: The entity uses procedures to achieve its documented system availability objectives in accordance with its defined policies.
基準 3.0
手順:定義されたポリシーに基づいて、文書化されたシステムの可用性の目標を達成するための手順を使用する。
Criteria 3.1
Procedures exist to protect the system against potential risks (for example, environmental risks, natural disasters, labor disputes, and routine operational errors and omissions) that might disrupt system operations and impair system availability.
基準 3.1
システムの操作を混乱させたりシステムの可用性を損なうかもしれない潜在的リスク(例えば、環境リスク、天災、労働争 議、日常の操作ミスや怠慢)からシステムを守る手順が存在する。
Illustrative Controls
統制の実例
A risk assessment is prepared and reviewed on a regular basis or when a significant change occurs in either the internal or external physical environment. Threats such as fire, flood, dust, power failure, excessive heat and humidity, and labor problems have been considered.
リスクアセスメントが準備され定 期的または内部または外部両方の物理環境に重要な変更が発生した際に確認される。火災、洪水、ほこり、電源障害、過度の暑さと湿度、労働問題の脅威が考慮 される。
Criteria 3.0
Procedures: The entity uses procedures to achieve its documented system availability objectives in accordance with its defined policies.
基準 3.0
手順:定義されたポリシーに基づいて、文書化されたシステムの可用性の目標を達成するための手順を使用する。
Criteria 3.1
Procedures exist to protect the system against potential risks (for example, environmental risks, natural disasters, labor disputes, and routine operational errors and omissions) that might disrupt system operations and impair system availability.
基準 3.1
システムの操作を混乱させたりシステムの可用性を損なうかもしれない潜在的リスク(例えば、環境リスク、天災、労働争 議、日常の操作ミスや怠慢)からシステムを守る手順が存在する。
Illustrative Controls
統制の実例
A risk assessment is prepared and reviewed on a regular basis or when a significant change occurs in either the internal or external physical environment. Threats such as fire, flood, dust, power failure, excessive heat and humidity, and labor problems have been considered.
リスクアセスメントが準備され定 期的または内部または外部両方の物理環境に重要な変更が発生した際に確認される。火災、洪水、ほこり、電源障害、過度の暑さと湿度、労働問題の脅威が考慮 される。
2010年5月13日木曜日
基準2.5
引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準2.5です。
Criteria 2.5
Changes that may affect system availability and system security are communicated to management and users who will be affected.
基準 2.5
システムの可用性とシステムセ キュリティに影響する変更は経営者と影響を受けるであろうユーザーに伝達される。
Illustrative Controls
Changes that may affect system availability, customers and users and their security obligations, or the entity’s security commitments are highlighted on the entity’s Web site.
Changes that may affect system availability and related system security are reviewed and approved by affected customers under the provisions of the standard services agreement before implementation of the proposed change.
Planned changes to system components and the scheduling of those changes are reviewed as part of the monthly IT steering committee meetings.
Changes to system components, including those that may affect system security, require the approval of the manager of network operations and/or the security administration team, before implementation.
There is periodic communication of system changes, including changes that affect availability and system security.
Changes that affect system security are incorporated into the entity’s ongoing security awareness program.
統制の実例
システムの可用性や顧客およびユーザーに影響する変更と彼らのセキュリティ義務または企業のセキュリティの約束事項は ウェブサイトで強調される。
システムの可用性と関連するシステムセキュリティに影響するおそれのある変更は影響を受ける顧客によって、提案された変 更の実装前に、標準的なサービス契約の規定のもと確認され承認される。
システムコンポーネントへの計画された変更とそれらの変更のスケジュールは月例IT運営委員 会の中で確認される。
システムセキュリティに影響するものも含めたシステムコンポーネントへの変更は、実装前に、ネットワークオペレーション の管理者と/またはセキュリティ管理チームの承認を求める。
可用性とシステムセキュリティに影響するものを含めたシステム変更の定期的な伝達が存在する。
システムセキュリティに影響する変更は継 続的なセキュリティ注意喚起プログラムに組み込まれる。
Criteria 2.5
Changes that may affect system availability and system security are communicated to management and users who will be affected.
基準 2.5
システムの可用性とシステムセ キュリティに影響する変更は経営者と影響を受けるであろうユーザーに伝達される。
Illustrative Controls
Changes that may affect system availability, customers and users and their security obligations, or the entity’s security commitments are highlighted on the entity’s Web site.
Changes that may affect system availability and related system security are reviewed and approved by affected customers under the provisions of the standard services agreement before implementation of the proposed change.
Planned changes to system components and the scheduling of those changes are reviewed as part of the monthly IT steering committee meetings.
Changes to system components, including those that may affect system security, require the approval of the manager of network operations and/or the security administration team, before implementation.
There is periodic communication of system changes, including changes that affect availability and system security.
Changes that affect system security are incorporated into the entity’s ongoing security awareness program.
統制の実例
システムの可用性や顧客およびユーザーに影響する変更と彼らのセキュリティ義務または企業のセキュリティの約束事項は ウェブサイトで強調される。
システムの可用性と関連するシステムセキュリティに影響するおそれのある変更は影響を受ける顧客によって、提案された変 更の実装前に、標準的なサービス契約の規定のもと確認され承認される。
システムコンポーネントへの計画された変更とそれらの変更のスケジュールは月例IT運営委員 会の中で確認される。
システムセキュリティに影響するものも含めたシステムコンポーネントへの変更は、実装前に、ネットワークオペレーション の管理者と/またはセキュリティ管理チームの承認を求める。
可用性とシステムセキュリティに影響するものを含めたシステム変更の定期的な伝達が存在する。
システムセキュリティに影響する変更は継 続的なセキュリティ注意喚起プログラムに組み込まれる。
2010年5月12日水曜日
基準2.4
引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準2.4です。
Criteria 2.4
The process for informing the entity about system availability issues and breaches of system security and for submitting complaints is communicated to authorized users.
基準 2.4
企業へのシステムの可用性に関することやシステムセキュリティの侵害を知らせるプロセスと苦情の提出プロセスは権限のあ るユーザーに伝達される。
Illustrative Controls
The process for customers and external users to inform the entity of system availability issues, possible security breaches, and other incidents is posted on the entity’s Web site and/or is provided as part of the new user welcome kit.
The entity’s user training program includes modules dealing with the identification and reporting of system availability issues, security breaches, and other incidents.
The entity’s security awareness program includes information concerning the identification of possible security breaches and the process for informing the security administration team.
Documented procedures exist for the identification and escalation of system availability issues, security breaches, and other incidents.
統制の実例
顧客や外部のユーザーへ、システムの可用性関連、潜在的なセキュリティの侵害、その他事故について案内するためのプロ セスはウェブサイトおよび/あるいは新ユーザー受入キットに含まれる。
ユーザー訓練プログラムには、システムの可用性関連の認識と報告、セキュリティの侵害、その 他事故を取り扱うモジュールが含まれる。
セキュリティ意識向上プログラムには、潜在的なセキュリティ侵害の認識とセキュリティ管理チームへの通知プロセスに関し た情報が含まれる。
シ ステムの可用性に関することやセキュリティ侵害、その他事故の認識とエスカレーションの明文化された手続が存在する。
Criteria 2.4
The process for informing the entity about system availability issues and breaches of system security and for submitting complaints is communicated to authorized users.
基準 2.4
企業へのシステムの可用性に関することやシステムセキュリティの侵害を知らせるプロセスと苦情の提出プロセスは権限のあ るユーザーに伝達される。
Illustrative Controls
The process for customers and external users to inform the entity of system availability issues, possible security breaches, and other incidents is posted on the entity’s Web site and/or is provided as part of the new user welcome kit.
The entity’s user training program includes modules dealing with the identification and reporting of system availability issues, security breaches, and other incidents.
The entity’s security awareness program includes information concerning the identification of possible security breaches and the process for informing the security administration team.
Documented procedures exist for the identification and escalation of system availability issues, security breaches, and other incidents.
統制の実例
顧客や外部のユーザーへ、システムの可用性関連、潜在的なセキュリティの侵害、その他事故について案内するためのプロ セスはウェブサイトおよび/あるいは新ユーザー受入キットに含まれる。
ユーザー訓練プログラムには、システムの可用性関連の認識と報告、セキュリティの侵害、その 他事故を取り扱うモジュールが含まれる。
セキュリティ意識向上プログラムには、潜在的なセキュリティ侵害の認識とセキュリティ管理チームへの通知プロセスに関し た情報が含まれる。
シ ステムの可用性に関することやセキュリティ侵害、その他事故の認識とエスカレーションの明文化された手続が存在する。
2010年5月11日火曜日
基準2.3
引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準2.3です。
Criteria 2.3
Responsibility and accountability for the entity’s system availability and related security policies and changes and updates to those policies are communicated to entity personnel responsible for implementing them.
基準 2.3
システムの可用性と関連するセキュリティポリシーの責務と説明責任、そして、それらのポリシーの変更と更新は、それらを 実装する責任のある社員に伝達される。
Illustrative Controls
The network operations team is responsible for implementing the entity’s availability policies under the direction of the chief information officer (CIO). The security administration team is responsible for implementing the related security policies.
The network operations team has custody of and is responsible for the day-to-day maintenance of the entity’s availability policies, and recommends changes to the CIO and the IT steering committee. The security administration team is responsible for the related security policies.
Availability and related security commitments are reviewed with the customer account managers as part of the annual IT planning process.
統制の実例
ネットワークオペレーションチームは最高情報責任者(CIO)の指示のもと、可用性のポリシーの実装に責任を持つ。セ キュリティ管理チームは関連するセキュリティポリシーの実装に責任を持つ。
ネットワークオペレーションチームは可用性ポリシーの日々の保守を監督し責任を持つ。またCIOとIT運営委員会に対して変更を提言する。セキュリティ管理 チームは関連するセキュリティポリシーに責任を持つ。
可用性と関連するセキュリティの約束は顧客アカウント管理者により年次IT計画策定プロセスの一部として確認される。
Criteria 2.3
Responsibility and accountability for the entity’s system availability and related security policies and changes and updates to those policies are communicated to entity personnel responsible for implementing them.
基準 2.3
システムの可用性と関連するセキュリティポリシーの責務と説明責任、そして、それらのポリシーの変更と更新は、それらを 実装する責任のある社員に伝達される。
Illustrative Controls
The network operations team is responsible for implementing the entity’s availability policies under the direction of the chief information officer (CIO). The security administration team is responsible for implementing the related security policies.
The network operations team has custody of and is responsible for the day-to-day maintenance of the entity’s availability policies, and recommends changes to the CIO and the IT steering committee. The security administration team is responsible for the related security policies.
Availability and related security commitments are reviewed with the customer account managers as part of the annual IT planning process.
統制の実例
ネットワークオペレーションチームは最高情報責任者(CIO)の指示のもと、可用性のポリシーの実装に責任を持つ。セ キュリティ管理チームは関連するセキュリティポリシーの実装に責任を持つ。
ネットワークオペレーションチームは可用性ポリシーの日々の保守を監督し責任を持つ。またCIOとIT運営委員会に対して変更を提言する。セキュリティ管理 チームは関連するセキュリティポリシーに責任を持つ。
可用性と関連するセキュリティの約束は顧客アカウント管理者により年次IT計画策定プロセスの一部として確認される。
2010年5月7日金曜日
基準 2.2
引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準 2.2です。
Criteria 2.2
The availability and related security obligations of users and the entity’s availability and related security commitments to users are communicated to authorized users.
基準 2.2
ユーザーの可用性と関連するセキュリティ義務、企業の可用性と関連するセキュリティのユーザーへの約束は承認された ユーザーへ伝達される。
Illustrative Controls
統制の実例
The entity’s system availability and related security commitments and required system availability and related security obligations of its customers and other external users are posted on the entity’s Web site and/or as part of the entity’s standard services agreement. Service-level agreements are reviewed with the customer annually.
企業のシステムの可用性と関連するセキュリ ティの約束と顧客や外部のユーザーに要求されるシステムの可用性と関連するセキュリティ義務は企業のウェブサイトや(or または)標準的なサービス合意に記載される。サービスレベル合意は顧客によって毎年確認される。
For its internal users (employees and contractors), the entity’s policies relating to system availability and security are reviewed with new employees and contractors as part of their orientation, and the key elements of the policies and their impact on the employee are discussed. New employees must sign a statement signifying that they have read, understand, and will follow these policies. Each year, as part of their performance review, employees must reconfirm their understanding of and compliance with the entity’s policies.
Obligations of contractors are detailed in their contract.
インターネットユーザー(従業員と請負者)にとってシステムの可用性とセキュリティに関するポリシーは新規雇用者と請 負者にオリエンテーションの一環として確認される。そしてポリシーの鍵となる要素とそれらの従業員への影響について議論される。新規雇用者はこれらのポリ シーを読み終え、理解し、従うことを確認した声明文に署名する。毎年、パフォーマンスレビューの一部として従業員はポリシーの理解と遵守を再確認する。
請負人の義務は契約に詳述される。
A security awareness program has been implemented to communicate the entity’s IT security policies to employees.
セキュリティ喚起プログラムは従業員への ITセキュリティポリシーの伝達に実装される。
The entity publishes its IT security policies on its corporate intranet.
ITセキュリ ティポリシーは社内のイントラネットに掲出される。
Criteria 2.2
The availability and related security obligations of users and the entity’s availability and related security commitments to users are communicated to authorized users.
基準 2.2
ユーザーの可用性と関連するセキュリティ義務、企業の可用性と関連するセキュリティのユーザーへの約束は承認された ユーザーへ伝達される。
Illustrative Controls
統制の実例
The entity’s system availability and related security commitments and required system availability and related security obligations of its customers and other external users are posted on the entity’s Web site and/or as part of the entity’s standard services agreement. Service-level agreements are reviewed with the customer annually.
企業のシステムの可用性と関連するセキュリ ティの約束と顧客や外部のユーザーに要求されるシステムの可用性と関連するセキュリティ義務は企業のウェブサイトや(or または)標準的なサービス合意に記載される。サービスレベル合意は顧客によって毎年確認される。
For its internal users (employees and contractors), the entity’s policies relating to system availability and security are reviewed with new employees and contractors as part of their orientation, and the key elements of the policies and their impact on the employee are discussed. New employees must sign a statement signifying that they have read, understand, and will follow these policies. Each year, as part of their performance review, employees must reconfirm their understanding of and compliance with the entity’s policies.
Obligations of contractors are detailed in their contract.
インターネットユーザー(従業員と請負者)にとってシステムの可用性とセキュリティに関するポリシーは新規雇用者と請 負者にオリエンテーションの一環として確認される。そしてポリシーの鍵となる要素とそれらの従業員への影響について議論される。新規雇用者はこれらのポリ シーを読み終え、理解し、従うことを確認した声明文に署名する。毎年、パフォーマンスレビューの一部として従業員はポリシーの理解と遵守を再確認する。
請負人の義務は契約に詳述される。
A security awareness program has been implemented to communicate the entity’s IT security policies to employees.
セキュリティ喚起プログラムは従業員への ITセキュリティポリシーの伝達に実装される。
The entity publishes its IT security policies on its corporate intranet.
ITセキュリ ティポリシーは社内のイントラネットに掲出される。
登録:
投稿 (Atom)
