ð SOC2 èªèšŒç¶æ³
â çŸåšã®èªå®ã¹ããŒã¿ã¹
ð èªå®ã®è©³çް:
- SOC2 ã¿ã€ã 2ïŒéçšæå¹æ§ïŒ
- ã¢ã¯ãã£ãã§ææ°
- Q3 2024
- æå¹æé: Q3 2025
- ç¬ç«ãã第äžè ã®å ¬èªäŒèšå£«ïŒCPAïŒäºåæ
ð¯ ä¿¡é ŒãµãŒãã¹åºæº
- â ã»ãã¥ãªãã£: äžæ£ã¢ã¯ã»ã¹ããã®ã·ã¹ãã ä¿è·
- â 空ãç¶æ³: éçšããã³äœ¿çšã®ããã®ã·ã¹ãã ã®ã¢ã¯ã»ã·ããªãã£
- â åŠçã®å®å šæ§ å®å šãã€æ£ç¢ºãªåŠç
- â æ©å¯ä¿æ: æå®æ©å¯æ å ±ä¿è·
- â ãã©ã€ãã·ãŒ: å人æ å ±ã®åéããã³åŠç
ð SOC2 Type 2 ã®æå³
SOC2 Type 2 ã¯ãSaaS ã»ãã¥ãªãã£èªèšŒã®ãŽãŒã«ãã¹ã¿ã³ããŒãã§ãããããªã·ãŒææžã確èªããã ãã§ãªãã6ã12 ãæã®æéã«ããã£ãŠå®éã®éçšå¹æãæ€èšŒããŸãã
ð ç£æ»ç¯å²:
- 6ãæéã®èг坿é çµ±å¶ã®ç¶ç¶çã¢ãã¿ãªã³ã°
- éçšè©Šéš çè«ã ãã§ãªããå®è·µã§æ€èšŒãããã³ã³ãããŒã«
- 蚌æ èŠä»¶: å®éã®ã»ãã¥ãªãã£ã€ãã³ãã®ææžå
- 第äžè ã«ããæ€èšŒ: ç¬ç«ç£æ»äººã«ããæ€èšŒ
ð¡ïž 管çã«ããŽãªãŒ:
- ã¢ã¯ã»ã¹å¶åŸ¡ ãŠãŒã¶ãŒèªèšŒãšèªå¯
- ãã§ã³ãžãããžã¡ã³ã ã·ã¹ãã ã®æŽæ°ããã³å€æŽç®¡ç
- ããŒã¿ä¿è·: æå·åãšããŒã¿åŠçæé
- ã€ã³ã·ãã³ãå¯Ÿå¿ ã»ãã¥ãªãã£ã€ãã³ãã®æ€ç¥ãšå¯Ÿå¿
ð ã»ãã¥ãªãã£ç®¡çã®å®è£
ð ããŒã¿ä¿è·ã³ã³ãããŒã«
ð¡ïž æå·åæšæº:
- AES-256æå·å æ¥çæšæºã®ããŒã¿æå·å
- TLS 1.3ïŒ å®å šãªããŒã¿éä¿¡
- ãšã³ãããŒãšã³ãæå·å ãã«ããŒã¿ã©ã€ããµã€ã¯ã«ä¿è·
- éµç®¡ç å®å šãªæå·éµã®åãæ±ã
- ä¿åããŒã¿ æå·åãããããŒã¿ããŒã¹ã¹ãã¬ãŒãž
ð ã¢ã¯ã»ã¹ç®¡ç:
- å€èŠçŽ èªèšŒ ãã¹ãŠã®ã¢ã«ãŠã³ãã«å¿ é
- ããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ æå°æš©éã®åå
- ã»ãã·ã§ã³ç®¡ç èªåã¿ã€ã ã¢ãŠããšã»ãã¥ã¢ããŒã¯ã³
- 宿çãªã¢ã¯ã»ã¹ã¬ãã¥ãŒ ååæããšã®æš©éç£æ»
- ç¹æš©ã¢ã¯ã»ã¹ã®ç£èŠ ç®¡çè ã¢ã¯ã·ã§ã³ã®æ¡åŒµãã°èšé²
ðïž ã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£
âïž ã¯ã©ãŠãã»ãã¥ãªãã£:
- AWS SOC2 æºæ ãã¹ãã£ã³ã° å®å šãªã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£
- ãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ éé¢ãããæ¬çªç°å¢
- äŸµå ¥æ€ç¥ 24æé幎äžç¡äŒã®ç£èŠã·ã¹ãã
- DDoSä¿è· èªåæ»æç·©å
- ããã¯ã¢ããã®ã»ãã¥ãªãã£: æå·åãããå°ççã«åæ£ããã
ð éçšç®¡çã³ã³ãããŒã«:
- ãã§ã³ãžãããžã¡ã³ã æŽæ°ã«é¢ããæ£åŒãªæ¿èªããã»ã¹
- ã³ãŒãã¬ãã¥ãŒ: ã»ãã¥ãªãã£éèŠã®éçºææ³
- ãããã¬ãŒã·ã§ã³ãã¹ã ååæããšã®ç¬¬äžè ã»ãã¥ãªãã£è©äŸ¡
- è匱æ§ã¹ãã£ã³: èªååã»ãã¥ãªãã£ç£èŠ
- ã€ã³ã·ãã³ãå¯Ÿå¿ 24æé幎äžç¡äŒã®ã»ãã¥ãªãã£ããŒã ã«ãã察å¿
ð GDPRãšãã©ã€ãã·ãŒã³ã³ãã©ã€ã¢ã³ã¹
ðªðº GDPR ã³ã³ãã©ã€ã¢ã³ã¹ç¶æ³
Sembly AI ã¯ããšãŒãããã®ãŠãŒã¶ãŒããŒã¿ãä¿è·ããèŠå¶èŠä»¶ãæºããããã«èšèšãããå æ¬çãªãã©ã€ãã·ãŒç®¡çæ©èœãåããGDPR ã«å®å šæºæ ããŠããŸãã
ð ããŒã¿ä¿è·ã«é¢ããæš©å©:
- ã¢ã¯ã»ã¹ããæš©å© ãŠãŒã¶ãŒã¯èªåã®ããŒã¿ããªã¯ãšã¹ãã§ããŸã
- èšæ£ãæ±ããæš©å©: ããŒã¿ä¿®æ£æ©èœ
- æ¶å»æš©: ãªã¯ãšã¹ãã«å¿ããå®å šãªããŒã¿åé€
- ããŒã¿ã®å¯æ¬æ§ã®æš©å© ããŒã¿ãæšæºçãªåœ¢åŒã§ãšã¯ã¹ããŒã
- åŠçãå¶éããæš©å©: ããŒã¿äœ¿çšéãå¶éãã
ð ãã©ã€ãã·ãŒå®è£ :
- ããŒã¿æå°å å¿ èŠãªæ å ±ã ããåéãã
- ç®çéå® èšèŒãããç®çã®ããã«ã®ã¿ããŒã¿ã䜿çšãã
- åæç®¡ç æç¢ºãªãªããã€ã³ïŒãªããã¢ãŠãã®ä»çµã¿
- ããŒã¿ä¿æå¶é: æå®æéåŸã®èªååé€
- è¶å¢ç§»è»¢ä¿è· æšæºå¥çŽæ¡é
ð ããŒã¿åŠçå¥çŽ
ð å©çšå¯èœãªæ³çå¥çŽæž:
ããŒã¿åŠçå¥çŽïŒDPAïŒ
- GDPR 第28æ¡ã«æºæ
- ã»æšæºå¥çŽæ¡é ãå«ã
- ã»ãšã³ã¿ãŒãã©ã€ãºé¡§å®¢åãã«æäŸ
- ã»åœéçãªããŒã¿ç§»è»¢ã察象ãšãã
ããžãã¹ã¢ãœã·ãšã€ãå¥çŽïŒBAAïŒ
- ã»ãã«ã¹ã±ã¢åãã®HIPAAã³ã³ãã©ã€ã¢ã³ã¹
- ã»ä¿è·å¯Ÿè±¡å»çæ å ±ã®ä¿è·å¯Ÿç
- ã»å»çæ©é¢åãã«å©çšå¯èœ
- ⢠éåéç¥æç¶ã
ð¢ ãšã³ã¿ãŒãã©ã€ãºåãã»ãã¥ãªãã£æ©èœ
ð¥ ã¢ã€ãã³ãã£ãã£ããã³ã¢ã¯ã»ã¹ç®¡ç
ð èªèšŒãªãã·ã§ã³:
- SSO çµ±å SAML 2.0 ãš OpenID Connect
- Active Directory åæ èªåãŠãŒã¶ãŒããããžã§ãã³ã°
- å€èŠçŽ èªèšŒ SMSãã¢ããªãããã³ããŒããŠã§ã¢ããŒã¯ã³
- æ¡ä»¶ä»ãã¢ã¯ã»ã¹ å Žæããã³ããã€ã¹ã«åºã¥ãããªã·ãŒ
- ã»ãã·ã§ã³ã³ã³ãããŒã«: ã¿ã€ã ã¢ãŠããšåæã»ãã·ã§ã³ã®å¶é
âïž ã¢ã¯ã»ã¹å¶åŸ¡:
- ããŒã«ããŒã¹ã®æš©éèšå® è©³çŽ°ãªæ©èœã¢ã¯ã»ã¹å¶åŸ¡
- ããŒã éå±€: çµç¹æ§é ã®åŒ·å¶
- ããŒã¿åé¡: æ©åŸ®ãªããŒã¿ã®åãæ±ãã«ãŒã«
- ç£æ»ãã°èšé² å æ¬çãªã¢ã¯ã»ã¹è¿œè·¡
- ç¹æš©ã¢ã¯ã»ã¹ç®¡ç 匷åããã管çè ã³ã³ãããŒã«
ð ã¢ãã¿ãªã³ã°ãšã³ã³ãã©ã€ã¢ã³ã¹
ð ã»ãã¥ãªãã£ç£èŠ:
- ãªã¢ã«ã¿ã€ã éç¥ å³æã®ã»ãã¥ãªãã£ã€ãã³ãéç¥
- è¡ååæ: ãŠãŒã¶ãŒã¢ã¯ãã£ããã£ã®ç°åžžæ€ç¥
- è åšã€ã³ããªãžã§ã³ã¹ ããã¢ã¯ãã£ããªã»ãã¥ãªãã£è åšã®èå¥
- ã»ãã¥ãªãã£ããã·ã¥ããŒã ãªã¢ã«ã¿ã€ã ã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹æŠèŠ
- ã€ã³ã·ãã³ãå¯Ÿå¿ èªåããã³æåã®å¯Ÿå¿æé
ð ã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒã:
- ç£æ»èšŒè·¡ ã³ã³ãã©ã€ã¢ã³ã¹ããŒã åãã®è©³çްãªã¢ã¯ãã£ããã£ãã°
- ã«ã¹ã¿ã ã¬ããŒã: ç¹åãããã³ã³ãã©ã€ã¢ã³ã¹å ±åæ©èœ
- ããŒã¿ãªããŒãžã¥ å®å šãªããŒã¿åŠçå±¥æŽ
- ä¿æããªã·ãŒ èªååãããããŒã¿ã©ã€ããµã€ã¯ã«ç®¡ç
- ãšã¯ã¹ããŒãæ©èœ: ã³ã³ãã©ã€ã¢ã³ã¹ããŒã¿æœåºããŒã«
ð¥ æ¥çç¹ååã³ã³ãã©ã€ã¢ã³ã¹
ð¥ å»çïŒHIPAAïŒ
â HIPAA æºæ æ©èœ:
- â¢ äºæ¥ææºå¥çŽæžã®å©çšãå¯èœ
- ã»PHIã®æå·åãšã¢ã¯ã»ã¹å¶åŸ¡
- ã»ãã«ã¹ã±ã¢ããŒã¿ã®ç£æ»ãã°
- ⢠éåéç¥æç¶ã
- ã»ç®¡ççä¿è·æªçœ®ãžã®æºæ
ð 远å ã®ä¿è·:
- ⢠æäœéå¿ èŠãªåºæºã®é©çš
- ãã«ã¹ã±ã¢ç¹åã®ããŒã¿ä¿æ
- ã»PHIéä¿¡ã®ããã®å®å šãªã¡ãã»ãŒãžã³ã°
- ã»ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãææž
ðŠ éèãµãŒãã¹
ð 財åã³ã³ãã©ã€ã¢ã³ã¹:
- ã»SOX ã³ã³ãã©ã€ã¢ã³ã¹æ¯æŽ
- ã»æ±ºæžããŒã¿ã«å¯ŸããPCI DSSãžã®æºæ
- ã»éèããŒã¿ä¿è·åºæº
- ã»èŠå¶å ±åæ©èœ
- ã»ããŒã¿ã¬ãžãã³ã·ãŒç®¡ç
ð ã»ãã¥ãªãã£èŠä»¶:
- ã»éèããŒã¿ã®åŒ·åãããæå·å
- ã»ãã©ã³ã¶ã¯ã·ã§ã³ç£èŠæ©èœ
- ã»ã³ã³ãã©ã€ã¢ã³ã¹ç£æ»èšŒè·¡ã®ç¶æ
- ã»èŠå¶å€æŽç®¡ç
ð¡ å®è£ ã®ãã¹ããã©ã¯ãã£ã¹
ð¯ ãããã€æšå¥šäºé
ð åæèšå®:
- ã»ãã¥ãªãã£è©äŸ¡: çŸåšã®ã»ãã¥ãªãã£äœå¶ãèŠçŽã
- ããªã·ãŒã®æŽåæ§ Semblyã®èšå®ãäŒç€Ÿã®ããªã·ãŒã«åããã
- ãŠãŒã¶ãŒåããã¬ãŒãã³ã° ãã¹ãŠã®ãŠãŒã¶ãŒã®ããã®ã»ãã¥ãªãã£æè
- çµ±åèšç»: SSO ãšãã£ã¬ã¯ããªãµãŒãã¹ã®ã»ããã¢ãã
- ã³ã³ãã©ã€ã¢ã³ã¹ãããã³ã°: èŠå¶èŠä»¶ã«æºæ ãã
ð ç¶ç¶çãªç®¡ç:
- å®æç£æ» ååæããšã®ã¢ã¯ã»ã¹ããã³æš©éã¬ãã¥ãŒ
- ã»ãã¥ãªãã£ç£èŠ ç¶ç¶çãªè åšæ€ç¥
- ã³ã³ãã©ã€ã¢ã³ã¹ã®æŽæ°: èŠå¶ã®å€æŽã«åžžã«å¯Ÿå¿ãã
- ã€ã³ã·ãã³ã察å¿ãã¹ã: 宿çãªã»ãã¥ãªãã£èšç·ŽæŒç¿
- ããã¥ã¡ã³ãä¿å®: ã³ã³ãã©ã€ã¢ã³ã¹èšé²ãææ°ã®ç¶æ ã«ä¿ã€
ð èªå®ã®æ€èšŒ
ð SOC2èªèšŒã確èªããæ¹æ³ïŒ
- ⢠Sembly AI ããçŽæ¥ SOC2 ã¬ããŒãããªã¯ãšã¹ããã
- ã»ç£æ»äººã®è³æ Œããã³ç¬ç«æ§ãæ€èšŒãã
- ã»ç£æ»æéããã³ç¯å²ã®ã«ãã¬ããžã確èªãã
- ã»ãããžã¡ã³ãã¬ã¿ãŒã®ã³ã¡ã³ãããªãã確èªãã
- ã»èªå®æ¥ãšæå¹æéã確èªãã
ð ãã¥ãŒããªãžã§ã³ã¹ãã§ãã¯ãªã¹ã:
- ã»ã»ãã¥ãªãã£è³ªå祚ã®åçã確èªãã
- ã»ããŒã¿åŠçå¥çŽãè©äŸ¡ãã
- ã»æå·åãšã¢ã¯ã»ã¹å¶åŸ¡ãæ€èšŒãã
- ã»ã€ã³ã·ãã³ã察å¿èœåãè©äŸ¡ãã
- ã»æ¥çèŠå¶ãžã®æºæ ã確èªãã