公認内部監査人(CIA)tunetterのブログです。 内部監査の試行錯誤を記録していきます。

にほんブログ村 経営ブログ 経営学へ
いま何位?

2010年5月6日木曜日

基準 2.0,2.1

ゴールデンウィークのため中断していましたが、引き続 き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準2.0,2.1です。
Criteria 2.0 
Communications: The entity communicates the defined system availability policies to authorized users.
基準 2.0
伝達:定義されたシステムの可用性方針を承認されたユーザーへ伝達する。

Criteria 2.1 
The entity has prepared an objective description of the system and its boundaries and communicated such description to authorized users.
基準 2.1
システムの目的の説明とその境界と そのような説明を承認されたユーザーへ伝達する用意がある。


Illustrative Controls
For its e-commerce system, the entity has posted a system description on its Web site. [For an example of a system description for an e-commerce system, refer to Appendix A(paragraph .42).]
For its non–e-commerce system, the entity has provided a system description to authorized users. [For an example of a system description for a non–e-commerce based system, refer to Appendix B (paragraph .43).]

統制の実例
商用システムについて、自社のウェブサイトにシステムの説明を掲載する。[Eコマースシステムの説明例は付録A(42 項)を参照]
非商 用システムについてはシステム説明を認められたユーザーに対して供給する。[非商用ベースのシステムの説明例は付録B(43項)を参照]

2010年4月29日木曜日

基準1.3

風邪のため中断していましたが、引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準1.3です。

Criteria 1.3
Responsibility and accountability for the entity’s system availability and related security policies, and changes and updates to those policies, are assigned.
基準 1.3 システムの可用性と関連す るセキュリティポリシーとそれらポリシーへの 変更・更新の責務と説明責任は割り当てられて いる。
Illustrative Controls

Management has assigned responsibilities for the maintenance and enforcement of the entity’s availability policies to the chief information officer (CIO). Others on the  executive committee assist in the review, update, and approval of these policies as outlined in the executive committee handbook.
Ownership and custody of significant information resources (for example, data, programs, and transactions) and responsibility for establishing and maintaining the system availability of and related security over such resources is defined.

統制の実例
経営者は 最高情報責任者(CIO)に可用性のポリシーの保守と執行の責任を割り当てる。他の執行委員会のメンバーはこれらのポリシーの確認、更新、承認補助する行委員会ハンドブックで説明されている。
重要な情報源(例えば、データ、プログラ ム、そして取引)とシステムの可用性の確立と保守、そしてこのようなリーソース全体に関連するセキュリティの所有権と保護が定義されている。

2010年4月23日金曜日

基準1.2

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準1.2です。
Criteria 1.2
The entity’s system availability and related security policies include, but may not be limited to, the following matters:
a. Identification and documentation of the system availability and related security requirements of authorized users.
b. Allowing access, the nature of that access, and who authorizes such access.
c. Preventing unauthorized access.
d. The procedures to add new users, modify the access levels of existing users, and remove users who no longer need access.
e. Assignment of responsibility and accountability for system availability and related security.
f. Assignment of responsibility and accountability for system changes and maintenance.
g. Testing, evaluating, and authorizing system components before implementation.
h. Addressing how complaints and requests relating to system availability and related security issues are resolved.
i. The procedures to handle system availability and related security breaches and other incidents.
j. Provision for allocation for training and other resources to support its system availability and related security policies.
k. Provision for the handling of exceptions and situations not specifically addressed in its system availability and related security policies.
l. Provision for the identification of, and consistency with, applicable laws and regulations, defined commitments, service-level agreements, and other contracts.
m. Recovery and continuity of service in accordance with documented customer commitments or other agreements.
n. Monitoring system capacity to achieve customer commitments or other agreements regarding availability.

基準 1.2
シ ステムの可用性と関連するセキュリティポリシーは以下のことがらを含む。(限定されるわけではない)
a. システムの認証されたユーザーの可用性と関連するセキュリティの要求の認証と考証
b. アクセスの許可、アクセスの性質、そして、誰がそのようなアクセスを承認したか
c. 未承認のアクセスを防ぐ
d. 新規ユーザーを追加する、既存ユーザーのアクセスレベルを変更する、そして、不要となったユーザーを削除する手順
e. システムの可用性と関連するセキュリティについての責任と説明責任の割り当て
f. システムの変更と保守についての責任と説明責任の割り当て
g. 実装前のシステムコンポーネントの試験、評価、そして、承認
h. どのようにシステムの可用性と関係するセキュリティ事項に関連する不平と要望が解決されるかを説明する
i. システムの可用性と関連するセキュリティ侵害と他の事件を取り扱う手順
j. システムの可用性と関連するセキュリティをサポートするためのトレーニングや他のリソース
割 り当ての規定
k. システムの可用性 と関連するセキュリティの例外および特に説明されていない状況を取り扱う規定
l. 適用される法令と規則、定義された約束、サービスレベル合意、そして他の契約規定との一致または整合
m. 文書化された顧客との約束またはその他合意に従ったサービスの復旧と継続
n. 可用性についての顧客との約束やその他合意を達成するための監視システムの能力


Illustrative Controls
The entity’s documented availability and related security policies contain the elements set out in criterion 1.2.

統制の実例
文書化された可用性と関連す るセキュリティポリシーは基準1.2で設定された要素を含む

2010年4月22日木曜日

可用性の原則と基準の表の基準1.0、1.1

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準の表の基準1.0、1.1です。
Availability Principle and Criteria Table
可用性の原則と基準の表
  • .20 The system is available for operation and use as committed or agreed.
  • .20 システムは約束または合意した操作と利用が可能である。
Criteria 1.0
Policies: The entity defines and documents its policies for the availability of its system.

基準 1.0原則:システムの可用性のポリシーは定義されと記述されている。

Criteria 1.1
The entity’s system availability and related security policies are established and periodically reviewed and approved by a designated individual or group.

基準 1.1
システムの可用性と関連するセキュリティポリシーは確立され、定期的に確認され、指名された個人またはグループにより 承認される。

Illustrative Controls
The entity’s documented systems development and acquisition process includes procedures to identify and document authorized users of the system and their availability and related security requirements.
User requirements are documented in service-level agreements or other documents.
Management reviews the entity’s availability and related security policies annually. Proposed changes are submitted as needed for approval by the information technology (IT) standards committee, which includes representation from the customer service department.

統制の実例
ドキュメント化されたシステム 開発と獲得過程は、認証の手順と承認されたユーザーのドキュメントと可用性および関連するセキュリティの要求を含む。
ユーザーの要求はサービスレベル合意や他 のドキュメントに文書化される。
経営者は可用性と関連するセキュリティポリシーを毎年確認する。
変更提案は顧客サービス部署の代表を含む情報技術(IT)標準委員会に よる要承認事項として提出される。

2010年4月21日水曜日

可用性の原則と基準

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は可用性の原則と基準です。

Availability Principle and Criteria
可用性の原則と基準
  • .18 The availability principle refers to the accessibility to the system, products, or services as advertised or committed by contract, service-level, or other agreements. It should be noted that this principle does not, in itself, set a minimum acceptable performance level for system availability. The minimum performance level is established through commitments made or by mutual agreement (contract) between the parties.
  • .18 可用性の原則は、契約やサービスレベル他の合意により宣伝または約束された、システムや製品またはサービスへの到達性に言及する。この原則はそれ自身では システム可用性の最小許容可能なパフォーマンスレベルを設定しないことに注意すべきである。最小許容可能なパフォーマンスレベルは約束作りを通じて、または、当事者間の相互の合意(契約)によって確立されます。
  • .19 Although there is a connection between system availability, system functionality, and system usability, the availability principle does not address system functionality (the specific functions a system performs) and system usability (the ability of users to apply system functions to specific tasks or problems). It does address system availability, which relates to whether the system is accessible for processing, monitoring, and maintenance.
  • .19 システムの可用性とシステムの機能性、そしてシステムの有用性の間に関係があるとしても、可用性の原則はシステムの機能性(システムの特定の機能)とシス テムの有用性(特定のタスクや問題へのシステムの機能に適応するユーザーの能力)を扱わない。システムが処理、監視、そして保守に関連し到達可能であるか 否かはシステムの可用性を説明しない。

2010年4月20日火曜日

基準 4.3

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 4.3です。

Criteria 4.3
Environmental and technological changes are monitored and their effect on system security is assessed on a timely basis.

基準 4.3
環境と技術変更は監視さ れ、それらがシステムセキュリティにおよぼす影響は適時に見積もられる。

Illustrative Controls
Senior management, as part of its annual IT planning process, considers developments in technology and the impact of applicable laws or regulations on the entity’s security policies.
The entity’s IT security group monitors the security impact of emerging technologies.
Users are proactively invited to contribute to initiatives to improve system security through the use of new technologies.

統制の実例
上級管理職は、年度IT計画の 策定プロセスの一部として、開発技術とセキュリティポリシーに適用される法令・規定の影響検討する。
ITセキュリティグループは技術の出現によるセキュリティへの影響を監 視する。
ユーザー は率先的に、新技術の利用を通じてシステムセキュリティの改善を主導し貢献することに招かれる。

2010年4月19日月曜日

基準 4.2

引き続き、Trust Services Principles, Criteria and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and SysTrust®)の勝手訳です。今回は基準 4.2です。

Criteria 4.2
There is a process to identify and address potential impairments to the entity’s ongoing ability to achieve its objectives in accordance with its defined system security policies.
基準 4.2
システムセキュリティポリシーに則り目的を達成するための継続能力に対する潜在的な障害を識別し対処するプロセスがあ る。

Illustrative Controls
Logs are analyzed to identify trends that may have a potential impact on the entity’s ability to achieve its system security objectives.
Monthly IT staff meetings are held to address system security concerns and trends; findings are discussed at quarterly management meetings.

統制の実例
記録はシステムセキュリティ の目的を達成する能力に対する潜在的な衝撃の傾向を識別するために分析される。
月例ITスタッフミーティングはシステムセキュリティ懸念事項と傾向に対処するために開催さ れる。