åäžçŽã®60幎代ã«ãåæ¥éšéã§ã®äŒèšã®ããã®æ å ±ã·ã¹ãã ã®å°å ¥ãå§ãŸããITã®åéã§ã®æ°ããå°éè·ãã€ãŸãITç£æ»äººãåºçŸããŸããã ããã«ãITç£æ»äººã®æåã®å°é家åäŒãèšç«ãããŸããããã®ç®æšã¯ãITç£æ»ãå®æœããããã®æšæºãšãã¹ããã©ã¯ãã£ã¹ãéçºããããšã§ããã
ãã以æ¥ãITç£æ»ã®å°éè·ã®éèŠæ§ã¯å€§å¹ ã«é«ãŸã£ãŠããŸãã ä»æ¥ãITçµ±å¶ã®ç£æ»ã¯ãã¹ãŠã®ç¬ç«ãã財åç£æ»ã®å¿ é éšåã§ãããITç£æ»ãµãŒãã¹ã¯åžå Žã§éèŠãããã倧äŒæ¥ã¯ITããã»ã¹ãå®æçã«ç£èŠããæ¹åã«åœ¹ç«ã€ç¬èªã®ITç£æ»ãŠããããæã£ãŠããŸãã åæã«ã確ç«ãããæšæºãšãã¹ããã©ã¯ãã£ã¹ã«åŸãããšããæé©ãªæ¹æ³ã§é«å質ã®ç£æ»ãå®æœããããã®åææ¡ä»¶ã§ãã
ãã®èšäºã®ç®çã¯ãããŸããŸãªçš®é¡ã®æ å ±æè¡ç£æ»ãå®æœããéã«äœ¿çšããããITç£æ»ã®åéã«ãããäž»èŠãªé¢é£æšæºããã³ã¬ã€ãã©ã€ã³ãæ瀺ããããšã§ãã ãã®èšäºã¯ãITç£æ»ãšæ å ±ã»ãã¥ãªãã£ã®åéã§ãã£ãªã¢ãéå§ããå°é家ã察象ãšããŠããŸãã ãã®èšäºã¯ãæ¢åã®ITç£æ»æšæºã«ç²ŸéããããšèããŠãã財å/å éšç£æ»äººã«ãšã£ãŠãèå³æ·±ããã®ã§ãã
ãã®èšäºã§ã¯ãåœéæ©é¢ISACA ã å éšç£æ»æ©é¢ïŒIIAïŒ ã ISO / IEC ã IAASBïŒåœéç£æ»ããã³ä¿èšŒåºæºå§å¡äŒïŒ ã PCAOBãªã©ã«ãã£ãŠéçºãããæšæºããã³ã¬ã€ãã©ã€ã³ã«ã€ããŠèª¬æããŸããåæšæºã«ã€ããŠããã®æ§é ãšæ©èœäœ¿çšããŸãã
1.ãIT Audit Framework 2nd EditionãïŒITAFïŒ-çµç¹ISACAããITç£æ»ãå®æœããããã®åœéæšæº
ææ°çã¯2013幎7æã«ãªãªãŒã¹ãããŸããã ãã®èŠæ Œã®å¯Ÿè±¡èªè ã¯ãITç£æ»ã®åéã®å°é家ã§ãã ãã®èŠæ Œã¯ãæ å ±ã·ã¹ãã ãšITã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ£åŒãªç£æ»ã®å®æœã«äœ¿çšããããšãç®çãšããŠããŸãã
æšæºã§ã¯ä»¥äžãå®çŸ©ããŠããŸãïŒ
â¢ITç£æ»ã®åéã®å°é家ã«åºæã®åºæ¬çãªçšèªãšæŠå¿µã
â¢æ å ±ã·ã¹ãã ã®ç£æ»ãå®æœããå°é家ã®ã¹ãã«ãšç¥èã®æå°èŠä»¶ã
â¢æ å ±ã·ã¹ãã ã®ç£æ»ãå®æœããç£æ»ã¬ããŒããäœæããäž»èŠãªæ®µéã
â¢æ å ±ã·ã¹ãã ãç£æ»ããããã®äœæ¥åºæºãäœæ¥ããã°ã©ã ãããã³ããŒã«ããµããŒãããã¬ã€ãã©ã€ã³ã®ãªã¹ãã
ITAFã¯ãæ å ±ã·ã¹ãã ã®åå¥ç£æ»ã®å®æœãšã財åããã³æ¥åç£æ»ã®äžç°ãšããŠæ å ±ã·ã¹ãã ã®ç£æ»ã®å®æœã®äž¡æ¹ã«é©çšã§ããæšæºãšããŠéçºãããŸããã
ITAFæšæºã¯3ã€ã®éšåã§æ§æãããŠããŸãã
1.äžè¬åºæº-æ å ±ã·ã¹ãã ã®ç£æ»ã®åéã®å°é家åãã®ã¬ã€ãã©ã€ã³ãå«ãŸããŸããç¬ç«æ§ã客芳æ§ãè·æ¥å«çã®ç¶æãç¥èãèœåãã¹ãã«ã®ç¶æã§ãã
2.ç£æ»ãå®æœããããã®åºæº-ç£æ»ã®èšç»ãšç®¡çã®å®è·µãç£æ»ã®äžç°ãšããŠã®äœæ¥ç¯å²ã®æ±ºå®ããªã¹ã¯ãšéèŠæ§ã®å¢çã®ç®¡çããªãœãŒã¹ã®åå¡ããããžã§ã¯ã管çãç£æ»èšŒæ ã®åéãšä¿åãå°é家ã®è©äŸ¡æ¹æ³ã®äœ¿çšãå«ãã
3.ã¬ããŒãæšæº-ã¬ããŒãã®çš®é¡ãã¬ããŒãããŒã«ãããã³è¡šç€ºãããæ å ±ã®çš®é¡ã®èª¬æãå«ãŸããŸãã
ISACAã¯ãæšæºã®åéšåã«ã€ããŠã説æãããŠããç£æ»æé ã®å®æœããµããŒãããã¬ã€ãã©ã€ã³ãäœæ¥ããã°ã©ã ãããã³æ瀺ãéçºããŸããã ã¬ã€ããäœæ¥ããã°ã©ã ãããã³æé ã¯ã åäŒã®å ¬åŒãŠã§ããµã€ãã§å ¥æã§ããŸãã
å·çæç¹ã§ã¯ãITAFæšæºã¯ITç£æ»å¡ã«ãšã£ãŠæãå æ¬çãªæ å ±æºã§ãããITã·ã¹ãã ããã³ITããã»ã¹ã®ç£æ»ã®ãã¹ãŠã®æ®µéãèšè¿°ããŠããŸãã
2.ãCobit 5 for Assuranceã-COBIT v.5ã«æºæ ããç£æ»ã¬ã€ãã³ã¹
ããã¥ã¢ã«ã®ææ°çã¯ã2013幎7æã«ISACAã«ãã£ãŠçºè¡ãããŸããã ãã®ããã¥ã¢ã«ã¯ã COBIT 5ãã¹ããã©ã¯ãã£ã¹ã³ã¬ã¯ã·ã§ã³ã«åŸã£ãŠæ å ±ã·ã¹ãã ã®ç£æ»ãå®æœããéã«ãITç£æ»ãITãªã¹ã¯ãããã³IT管çã®åéã®å°é家ã䜿çšããããšãç®çãšããŠããŸãã COBITã®ãã¹ããã©ã¯ãã£ã¹ã³ã¬ã¯ã·ã§ã³ã®ä»¥åã®ããŒãžã§ã³ïŒvã4.1ïŒã¯2007幎ã«ãªãªãŒã¹ãããçŸåšãããã®ç°å¢ã§åºã䜿çšãããŠããŸã1 ã
ä¿èšŒã®ããã®ã³ããã5ïŒ
â¢COBIT 5ã䜿çšããŠäŒæ¥ã®å éšITç£æ»æ©èœãæŽçããã³ç¶æããããã®è©³çŽ°ãªã¬ã€ãã³ã¹ãæäŸããŸãã
â¢COBIT 5ã«èšèŒãããŠããããã»ã¹ãšèŠå ïŒ*ã€ããŒãã©ãŒïŒã«åŸã£ãŠITç£æ»ãå®æœããããã®æ§é åãããã¢ãããŒããå«ãŸããŠããŸãã
â¢ITç£æ»ã®å®æœã«COBIT 5ã䜿çšããç¹å®ã®äŸã瀺ããŸãã
ITAFãšæ¯èŒããŠãCobit 5 for Assurance Managementã¯ãç£æ»æé ã®åœ¢åŒåã®çšåºŠãäœãããã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠITããã»ã¹ãç·šæããããšã«é¢é£ããåé¡ãããåºç¯å²ã«ã«ããŒããŠããŸãã
3.ãå éšç£æ»åºæºã®ããã®åœéå°é家å®è·µãã¬ãŒã ã¯ãŒã¯ïŒIPPFïŒã
å éšç£æ»äººåäŒïŒIIAïŒã«ããå éšç£æ»ã®åœéåºæºã çŸåšã®ãšãã£ã·ã§ã³ã¯2013幎ã«ãªãªãŒã¹ãããŸããã æšæºã®å¯Ÿè±¡èªè ã¯å éšç£æ»ã¹ã¿ããã§ãã
ãã®èŠæ Œã®ç®çã¯ä»¥äžã決å®ããããšã§ãïŒ
â¢å éšç£æ»ã®åºæ¬ååã
â¢å éšç£æ»æ £è¡ã®æšæºã»ããã
â¢å éšç£æ»æé ã®æå¹æ§ãè©äŸ¡ããããã®åºæ¬çãªææšã
ãã®æšæºã¯ITç£æ»æšæºãšããŠéçºããããã®ã§ã¯ãããŸããããå éšè²¡åããã³éçšç£æ»ã®å®æœãšæ å ±æè¡ã®å éšç£æ»ã®å®æœã®äž¡æ¹ã«äœ¿çšã§ããæ®éçãªååãšã¢ãããŒããå®çŸ©ããŠããŸãã
ITç£æ»ã®å®æœã«é¢ããèŠæ Œã®æ¹æ³è«çãµããŒãã®ããã«ãIIAã¯ITãªã¹ã¯ã®è©äŸ¡ïŒITãªã¹ã¯ã®è©äŸ¡ã®ã¬ã€ãïŒããã³æ å ±æè¡ã®ç£æ»ïŒã°ããŒãã«ãã¯ãããžãŒç£æ»ã¬ã€ãïŒã®è©³çŽ°ãªã¬ã€ãã©ã€ã³ãéçºããŸããã
ITãªã¹ã¯è©äŸ¡ã¬ã€ãïŒGAITïŒã¯ãããžãã¹ãªã¹ã¯ãããžãã¹ããã»ã¹ã«çµã¿èŸŒãŸããäž»èŠãªã³ã³ãããŒã«ãèªååãããã³ã³ãããŒã«ãéèŠãªITæ©èœãããã³ITäžè¬ã³ã³ãããŒã«2ã®é¢ä¿ã説æããŠããŸãã
GAITã¬ã€ãã«ã¯ã次ã®åºçç©ãå«ãŸããŠããŸãã
1ïŒGAITæ¹æ³è«ïŒGAITæ¹æ³è«ïŒ-ãµãŒãã³ã¹ã»ãªã¯ã¹ãªãŒæ³ã®ã»ã¯ã·ã§ã³404ã«æºæ ããããã«å¿ èŠãªå éšçµ±å¶ã·ã¹ãã ã®ç®¡çã®è©äŸ¡ã®äžéšãšããŠãäžè¬çãªITçµ±å¶ã®å®çŸ©ãšè©äŸ¡ã«å¯Ÿãããªã¹ã¯ããŒã¹ã®ã¢ãããŒãã説æããŸãã
2ïŒITäžè¬çµ±å¶æ¬ é¥è©äŸ¡ïŒGAITïŒã®ããã®GAIT-ãµãŒãã³ã¹ã»ãªã¯ã¹ãªãŒæ³404é©åæ§è©äŸ¡ã®äžéšãšããŠç¹å®ãããäžè¬ITçµ±å¶æ¬ é¥ã®éèŠæ§ãšéèŠæ§ã決å®ããã¢ãããŒãã«ã€ããŠèª¬æããŸãã
3ïŒããžãã¹ããã³ITãªã¹ã¯è©äŸ¡ã®ããã®GAITïŒããžãã¹ããã³ITãªã¹ã¯ã®ããã®GAITïŒ-çµç¹ã®ããžãã¹ç®æšããã³ç®æšãéæããããã«éèŠãªäž»èŠãªITã³ã³ãããŒã«ãèå¥ããæé ã説æããŸãã
æ å ±æè¡ç£æ»ã¬ã€ãã§ããGlobal Technology Audit GuideïŒGATGïŒã¯ãæ å ±ã·ã¹ãã ã®ç£æ»ã«äœ¿çšãããããã»ã¹ãæé ãããã³ææ³ã説æãã15ã®åºçç©ã§æ§æãããŠããŸãã
1. ITã®ãªã¹ã¯ãšç®¡çïŒæ å ±æè¡ã®ãªã¹ã¯ãšç®¡çïŒ
2.å€æŽãè¡ã£ãŠITã·ã¹ãã ãæŽæ°ããããã»ã¹ã®ã³ã³ãããŒã«ïŒå€æŽããã³ããã管çã³ã³ãããŒã«ïŒ
3.ç¶ç¶ç£æ»ã®ããã»ã¹ïŒç¶ç¶ç£æ»ïŒ
4. ITç£æ»ããã»ã¹ã®ç®¡çïŒITç£æ»ã®ç®¡çïŒ
5. ITã¢ãŠããœãŒã·ã³ã°ïŒæ å ±æè¡ã¢ãŠããœãŒã·ã³ã°ïŒ
6.èªååãããã³ã³ãããŒã«ã®ç£æ»ïŒã¢ããªã±ãŒã·ã§ã³ã³ã³ãããŒã«ã®ç£æ»ïŒ
7. IDããã³ã¢ã¯ã»ã¹ç®¡ç
8.ããžãã¹ç¶ç¶æ§ç®¡ç
9. ITç£æ»èšç»ã®äœæ
10. ITãããžã§ã¯ãã®ç£æ»ïŒITãããžã§ã¯ãã®ç£æ»ïŒ
11. ITãã¯ãããžãŒã®äœ¿çšã«é¢é£ããäžæ£ã®æ€åºãšé²æ¢ïŒèªååãããäžçã§ã®äžæ£é²æ¢ãšæ€åºïŒ
12.ãŠãŒã¶ãŒéçºã¢ããªã±ãŒã·ã§ã³ã®ç£æ»
13.æ å ±ã»ãã¥ãªãã£ã¬ããã³ã¹
14.æ å ±åææè¡ïŒããŒã¿åææè¡ïŒ
15. ITã¬ããã³ã¹ã®ç£æ»
ãããã®æšæºã®è©³çŽ°ãšããžãã¹æåã¯ããã®åŒ·ã¿ã§ãã ããã«ãããããããæšæºããã³ãµããŒãã¬ã€ãã©ã€ã³ã¯ãITã®æ·±ãããã¯ã°ã©ãŠã³ããæããªãå°é家ã䜿çšããããã«äœæãããŠããããã䜿çšãããçšèªã¯ITç£æ»ãå®æœããæè¡çåŽé¢ãå¿ ãããæ£ç¢ºã«èª¬æããŸããã ãŸããããã€ãã®ããã¥ã¢ã«ã¯æ°å¹ŽéæŽæ°ãããŠããŸããã
4.åœéèŠæ ŒãISAE No. 3402ãããã³ãSSAE No. 16 "
ãISAE No. 3402ãåœéäŒèšå£«é£çïŒIFACãåœéäŒèšå£«é£çïŒã®äžéšã§ããåœéçµç¹IAASBïŒåœéç£æ»ããã³ä¿èšŒåºæºå§å¡äŒïŒã«ãã£ãŠéçºãããç£æ»ãµãŒãã¹çµç¹ã®åœéåºæºã
æšæºãSSAE No. ç±³åœå ¬èªäŒèšå£«åäŒïŒAICPAïŒã«ããçºè¡ããã16âïŒæ§SAS 70ïŒã¯ãåœéèŠæ ŒISAE No.3402ã®ã¢ã¡ãªã«çã«é©åãããã®ã§ãã
ISAEçªå·ã®ç®ç 3402ãã¯ãä¿¡é Œã§ãã財åè«žè¡šã®äœæãšãã芳ç¹ããããµãŒãã¹çµç¹ã®å éšçµ±å¶ã·ã¹ãã ã®æå¹æ§ãè©äŸ¡ããããã®çµ±äžãããã¢ãããŒãã®æäŸã§ãã èŠæ Œã«ããã°ãè©äŸ¡äžã«IT管çã®æå¹æ§ã®æ€èšŒãå¿ èŠã§ãã
æšæºãISAE No. 3402ããæ¿èªãããç£æ»çµç¹ã¯ãå éšçµ±å¶ã·ã¹ãã ã®æå¹æ§ã«é¢ããæ£åŒãªç£æ»å ±åæžãçºè¡ããå ŽåããããŸãã ãããã®èª¿æ»çµæã¯ã2åç®ã®ç£æ»ãå¿ èŠãšããã«ã第äžè ãå©çšã§ããå ŽåããããŸãã
ãµãŒãã¹çµç¹ã®å éšçµ±å¶ã·ã¹ãã ã§ååãªã¬ãã«ã®ä¿¡é Œ/ä¿¡é ŒãåŸãã«ã¯ïŒ
1ïŒãµãŒãã¹çµç¹ã¯ãITã®åŽé¢ãå«ããç£æ»å¯Ÿè±¡æéã®å éšçµ±å¶ã·ã¹ãã ã®æ§é ãæ確ã«èšè¿°ããå¿ èŠããããŸãã
2ïŒçµç¹ã®å éšçµ±å¶ã·ã¹ãã ã®èª¬æã«ãããçµ±å¶ç®æšã«é¢é£ããçµ±å¶ã¯ããªã¹ã¯ïŒè²¡åãéçšãITãªã©ïŒãé©åã«ã«ããŒããã®ã«ååãªæ¹æ³ã§ã¢ãã«åïŒèšç»ïŒããå¿ èŠããããŸãã
3ïŒçµç¹ã®å éšçµ±å¶ã·ã¹ãã ã®èª¬æã«ç€ºãããçµ±å¶ç®æšãç£æ»æéã«éæããããšããååãªã¬ãã«ã®ä¿¡é Œã確ä¿ããããã«ãçµ±å¶ã¯ç£æ»ã®ç¯å²ã«å«ãŸããå¹ççã«å®æœãããã¹ãã§ãã
ãã®æšæºãžã®æºæ ã®ç£æ»ã¯ãç±³åœãšãšãŒãããã§ã¯éåžžã«äžè¬çã§ããããã·ã¢ã§ã¯ãŸã åºã䜿çšãããŠããŸããã
5. PCAOBç£æ»åºæºçªå· 5ã財åè«žè¡šã®ç£æ»ãšçµ±åããã財åå ±åã«é¢ããå éšçµ±å¶ã®ç£æ»ã
ãã®æšæºã®ææ°çã¯ã2007幎ã«å ¬éäŒç€ŸäŒèšç£èŠå§å¡äŒïŒPCAOBïŒã«ãã£ãŠéçºããã³çºè¡ãããŸããã
å ¬éäŒç€ŸäŒèšç£èŠå§å¡äŒïŒPCAOBïŒã¯ãç¬ç«ç£æ»æèŠãäœæããæè³å®¶ã®å©çãä¿è·ããããã«ãç±³åœååŒæã«äžå ŽããŠããäŒæ¥ã®ç£æ»ãç£èŠããéå¶å©çµç¹ãšããŠ2002幎ã«Sarbanes-Oxleyã«ãã£ãŠäœæãããŸããã PCAOBã®åµèšã«ãããSarbanes-Oxley Actã¯æŽå²äžåããŠãæ°éç£æ»äŒç€Ÿã«ç¬ç«ããç£èŠã矩åä»ããŸããã ããã«å ç«ã¡ãç±³åœã®ç£æ»äººã®è·æ¥ã¯èªäž»èŠå¶ã§ããã
ç£æ»æšæºPCAOBçªå· 5ã財åè«žè¡šã®ç£æ»ãšçµ±åããã財åå ±åã®å éšçµ±å¶ã®ç£æ»ãã¯ãå€éšè²¡åç£æ»ãå®æœããéã«å¿ é ã®ç£æ»æé ã®ç¯å²ã«ITããã»ã¹ãšITã·ã¹ãã ã®ãã§ãã¯ãå«ããããã®èŠä»¶ãå®çŸ©ããŸãã
åºæºã«ããã°ã財åè«žè¡šã®äœæã«é¢é£ããçµ±å¶ã®ç£æ»ãå®æœããå Žåãç£æ»äººã¯ã䜿çšãããŠããæ å ±ã·ã¹ãã ãšæè¡ã財åè«žè¡šã®äœæããã»ã¹ã«ã©ã®ããã«åœ±é¿ããããç解ããå¿ èŠããããŸãã ç£æ»äººã¯ãã©ã®å¶åŸ¡ãæåã§å®è¡ãããã©ã®å¶åŸ¡ãæ å ±ã·ã¹ãã ã®ã¬ãã«ã§å®è£ ãããŠããããç解ããå¿ èŠããããŸã-èªåå¶åŸ¡ãèªåå¶åŸ¡ã®å¹æçãªéçšã«éèŠãªäžè¬çãªITå¶åŸ¡ã®å®è¡æ¹æ³ãå«ãã æ å ±ã·ã¹ãã ã§åŠçããã財åæ å ±ã®æªã¿ã®ãªã¹ã¯ãè©äŸ¡ããéã«ã¯ããã®æ å ±ãèæ ®ããå¿ èŠããããŸãã
6.ãISO / IEC 27007ïŒæ å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã 管çã®ã¬ã€ãã©ã€ã³ãããã³ãISO / IEC TR 27008ïŒæ å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã 管çã®ã¬ã€ãã©ã€ã³ã
2011幎ã«åœéçµç¹ISO / IECã«ãã£ãŠå ¬éãããæšæºã
æšæºã®å¯Ÿè±¡èªè ã¯ãæ å ±ã»ãã¥ãªãã£ããã³ITç£æ»èšç»ã®åéã®å°é家ã§ãããISO27001ããã³ISO27002ã®èŠä»¶ã«æºæ ããããã®ã³ã³ãã©ã€ã¢ã³ã¹ç£æ»ãå®æœããŸãã
èŠæ Œã®ç®çã¯ãç£æ»å¯Ÿè±¡ã®çµç¹/éšéãISO / IEC 27001ããã³ISO / IEC 27002ã§å®ããããèŠä»¶ã«æºæ ããŠãããã©ãããè©äŸ¡ããããšã§ãã
æšæºã«ã¯ãç£æ»ã®æ¬¡ã®åŽé¢ã®èª¬æãå«ãŸããŠããŸãã
1.ç£æ»ç®¡çïŒç£æ»ç¯å²ã®æ±ºå®ãç£æ»ããŒã ã®ç·šæãç£æ»ãªã¹ã¯ã®ç®¡çãç£æ»èšŒæ ã®ä¿ç®¡ãç£æ»ããã»ã¹ã®æ¹åïŒã
2.çŽæ¥ç£æ»ïŒèšç»ãå®æœããµã³ããªã³ã°ãšåæãå«ãäž»èŠãªæŽ»åãå ±åãããã³å®è£ ã®ãã®åŸã®ç£èŠïŒã
3.ç£æ»ããŒã ã®ç®¡çïŒèœåãšã¹ãã«ã®ç¶æãããŒã ã¡ã³ããŒã®è©äŸ¡ïŒã
ãããã®æšæºã®æ¬ ç¹ã¯ããªã¹ã¯è©äŸ¡ã®æ¬ åŠãšãç£æ»ã®èšç»ãšå®æœã«ããã管çã®åªå é äœä»ãã§ãã ãã ãããã®èŠæ Œã¯ãISO / IEC 27001ããã³ISO / IEC 27002ã«æºæ ããããã®ã³ã³ãã©ã€ã¢ã³ã¹ç£æ»ã®æºåã«äŸ¿å©ã§ãã
ITç£æ»ã®å®æœã«äœ¿çšã§ãããã®ä»ã®æšæºãšã¬ã€ãã©ã€ã³
å Žåã«ãã£ãŠã¯ãITç£æ»ãå®æœããéã«ãçŽæ¥çãªç£æ»æšæºã§ã¯ãªãåœéæšæºãšãã¹ããã©ã¯ãã£ã¹ã䜿çšã§ããŸãããITããã»ã¹ã®æç床ãšæå¹æ§ã®ã¬ãã«ãè©äŸ¡ããã«ã¯äŸ¿å©ã§ãã
ãã®ãããªæšæºã®äŸïŒ
1. ISO 20000-ITãµãŒãã¹ã®ç®¡çãšä¿å®ã®ããã®åœéæšæºã
2. ITILïŒIT Infrastructure LibraryïŒ-ITãµãŒãã¹ã®æäŸã«é¢äžããéšéãŸãã¯äŒæ¥ã®äœæ¥ãæŽçããããã®æè¯ã®å®çšçãªæ¹æ³ãèšè¿°ããã©ã€ãã©ãªã
3. PCI DSSã¯ãåœé決æžã·ã¹ãã VisaãMasterCardãAmerican ExpressãJCBãããã³Discoverã«ãã£ãŠç¢ºç«ãããã決æžã«ãŒãæ¥çã®ããŒã¿ã»ãã¥ãªãã£æšæºã§ãã
4.æ å ±ã»ãã¥ãªãã£ã«é¢ããNIST 800-xxã·ãªãŒãºã®åºçç©ã
5.æ å ±ââã»ãã¥ãªãã£ã®ISFã°ãããã©ã¯ãã£ã¹æšæº-åœéæ©é¢ã®æ å ±ã»ãã¥ãªãã£ãã©ãŒã©ã ïŒISFïŒããã®æ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã管çããããã®ããžãã¹æåã®å®è·µã¬ã€ãã