15
AWSが取得している 第三者認証について 株式会社サーバーワークス 1から学ぶクラウドのセキュリティ勉強会@九州 JAWSUG 九州・福岡合同】 h*p://jawskitaq.doorkeeper.jp/events/13701

2014/08/23 JAWSUG北九州福岡 AWSが取得している第三者認証について

Embed Size (px)

DESCRIPTION

http://jaws-kitaq.doorkeeper.jp/events/13701 1から学ぶクラウドのセキュリティ勉強会@北九州【JAWS-UG 北九州・福岡合同】 で発表した資料です

Citation preview

  • 1. AWS JAWS-UGh*p://jaws-kitaq.doorkeeper.jp/events/13701

2. ! ! AWS ! ! ! ! Web/! ! AWS Samurai 2014! AWS! IAM ( Identity and Access Management )! Route53 3. AWS! HIPAA! SOC1/SSAE16/ISAE3402 SAS70! SOC2! SOC3! PCIDSS 1! ISO27001! FedRAMPSM)! DIACAP FISMA! ITAR! FIPS140-2! CSA! MPAAh*p://aws.amazon.com/jp/compliance/h*p://bit.ly/1BBrTBg 4. HIPAA! :! U.S.HealthInsurancePortabilityandAccountabilityAct! (1996! /! ! h*p://www.mhlw.go.jp/shingi/2010/06/dl/s0616-4g.pdfh*p://www.hhs.gov/ocr/privacy/ 5. SOC1/SSAE16/ISAE3402! :! ServiceOrganizaonControls1,TypeII! (AICPA)(TrustServicesPrinciples)! ! StatementonStandardsforA*estaonEngagementsNo.16(USA! InternaonalStandardonAssuranceEngagementsNo.3402()! h*p://giolog.iij.ad.jp/2012/10/24/7169/ 6. SOC2! :! ServiceOrganizaonControls2,TypeII! (AICPA)(TrustServicesPrinciples)! ATSecon101,A*estEngagementsAICPA(USA)! h*p://giolog.iij.ad.jp/2012/10/24/7169/ 7. SOC3! :! ServiceOrganizaonControls3! AWSSOC2! AICPASysTrust! AWSAWSh*p://giolog.iij.ad.jp/2012/10/24/7169/ 8. PCIDSS 1! :! PaymentCardIndustryPCIDataSecurityStandard/DSS 1! PCISecurityStandardsCouncil! ! 1: 30/2: 30 9. ISO27001! :! InternaonalOrganizaonforStandardizaonISO27001! ! ! C:ConfidenalityI:IntegrityA:Availability3ISMS 10. FedRAMP(SM)! ! FederalRiskandAuthorizaonManagementProgram(FedRAMP Moderate! ! !FedRAMPCompliantCloudServiceProviderCSP! FedRAMP 11. DIACAP FISMA! :?! DoDInformaonAssuranceCerficaonandAccreditaonProcessDIACAP! UnitedStatesDepartmentofDefense(DoD)! :! FederalInformaonSecurityManagementAct/FISMA! ! 12. ITAR! :! U.S.InternaonalTrafficinArmsRegulaons! ! UnitedStatesMunionsList(USML)=! ITARh*ps://www.pmddtc.state.gov/regulaons_laws/itar.htmlh*p://www.legaldocohno.com/itarnituite.html 13. FIPS140-2! :! FederalInformaonProcessingStandardFIPSPublicaon140-2! ! DepartmentofCommerce/NaonalInstuteofStandardsandTechnology(/)! FIPS140-22001/FIPS1401982h*p://csrc.nist.gov/groups/STM/cmvp/standards.htmlh*p://dev.sbins.co.jp/cryptography/CMVP03.html 14. CSA! :! CloudSecurityAlliance! ! 140h*ps://cloudsecurityalliance.org/ 15. MAPP! ! MoonPictureAssociaonofAmerica! ! AWS