RELIANOID ISO/IEC 27017および27018コンプライアンス

最終レビュー日: 2026年7月
次回のレビュー期限: 2027年7月

ISO/IEC 27017および27018コンプライアンスステートメント

クラウドセキュリティとデータプライバシーの連携 RELIANOID プラットフォームと組織

RELIANOID 両方の原則に沿っている ISO / IEC 27017 (クラウド固有のセキュリティ制御)と ISO / IEC 27018 (Protection of personal data in cloud environments). These standards guide our security, data protection, and operational practices for both our RELIANOID ロードバランサ組織全体のプロセス.

一方、 RELIANOID is not officially certified under ISO/IEC 27017 or 27018, we maintain security and data protection controls aligned with the relevant principles across our infrastructure, internal policies, vulnerability management processes, and customer-facing operations.

クラウド固有のセキュリティプラクティス(ISO/IEC 27017)

責任分担

RELIANOID maintains defined security responsibilities across its organizational and technical operations. Security, data protection, access control, incident response, and third-party risk management are supported by documented policies and procedures that are reviewed regularly.

IDおよびアクセス管理

Access control is a key component of RELIANOID’s security framework. 100% of employee accounts are protected by multi-factor authentication (MFA), while account lifecycle controls are maintained to prevent unnecessary or inactive accounts from remaining enabled.

Cloud Infrastructure and Network Security

RELIANOID maintains network security controls designed to protect communications between services and infrastructure. サービス内通信の100%はプライベートIPを使用する, while services support SSL/TLS for secure communications.

RELIANOID also maintains network abuse IP protection and network DoS protection, together with Web Application Firewall (WAF) capabilities as part of its layered security approach.

Cloud Usage and Data Protection Policies

RELIANOID maintains formal policies covering data protection, business continuity, incident response, third-party risk management, and service-level management. These policies are reviewed on an annual basis and support the organization’s security and privacy commitments.

Data classification and retention practices are maintained according to the RELIANOID Data Processing Agreement (DPA), supporting controlled handling and retention of information processed within the organization’s operations.

インフラストラクチャの回復力

RELIANOID maintains tested backup and restoration processes to support operational resilience. Backup and restoration procedures are tested 季刊, while third-party infrastructure providers are assessed for availability, resilience, security certifications, and contingency capabilities.

データプライバシーバイデザイン(ISO/IEC 27018)

Data Protection in Cloud Environments

RELIANOID maintains controls designed to protect data processed through its services and supporting infrastructure.

  • Encryption is applied to data in transit
  • Data classification and retention policies are maintained according to the Data Processing Agreement
  • Backup and restoration processes are tested quarterly
  • Third-party providers are assessed for security, resilience, and data protection considerations

RELIANOID’s current security assessment identifies encryption at rest as an area not currently implemented across the assessed environment. Data Loss Prevention (DLP) tooling and effectiveness are planned as a future security improvement.

透明性とクライアントコントロール

RELIANOID maintains documented data protection and processing practices through its policies and Data Processing Agreement. Data classification and retention requirements are established according to the applicable DPA and organizational processes.

Access and Security Monitoring

Access controls are supported by mandatory MFA for employee accounts. RELIANOID also maintains alert accuracy and escalation procedures and performs incident and near-miss reviews.

Centralized log correlation through a Security Information and Event Management (SIEM) platform is currently planned as a future improvement to strengthen monitoring and detection capabilities.

Third-Party Confidentiality and Risk Management

RELIANOID maintains an inventory and risk assessment process for critical ICT suppliers. Third-party services are evaluated according to their security certifications, operational risks, SLA and resilience commitments, and available contingency plans.

適切な場において、 RELIANOID maintains alternative providers, backup systems, redundant infrastructure, or other contingency mechanisms to reduce dependency and support continuity of critical operations.

コンプライアンスをサポートする組織的慣行

従業員のトレーニングと意識向上

RELIANOID maintains security awareness and training programs, tracks training completion, and updates security awareness training content. Phishing simulation exercises and the incorporation of new threat intelligence into security awareness content are identified as future improvement areas.

インシデント対応

RELIANOID maintains documented Incident Response & Reporting Procedures and reviews incident response team contact information. Incident reviews and near-miss processes are in place.

Formal testing and review of the Incident Response Plan, together with systematic documentation and implementation of lessons learned, are identified as planned improvements within the security roadmap.

ベンダーのリスク管理

RELIANOID maintains a structured third-party risk management process covering critical ICT suppliers, security certifications, operational risks, SLAs, resilience commitments, and contingency plans.

Vulnerability and Security Monitoring

RELIANOID conducts regular vulnerability scanning, patch management, security monitoring, and service and product testing. The latest security assessment dated 29 June 2026 reported 104件の脆弱性を修正しました (NAIST) と 修正すべき脆弱性が15件残っています within product vulnerability monitoring.

Service and product security testing launched 1,007テスト, with findings tracked according to risk level and remediation requirements. These processes support continuous improvement of the security posture of RELIANOIDの製品とサービス。

安全なクラウド運用への取り組み

RELIANOID continues to enhance its security alignment with ISO/IEC 27017 and 27018 through:

  • Regular review of security and data protection policies
  • Continuous vulnerability scanning, security testing, and remediation
  • Strengthening access controls and MFA enforcement
  • Maintaining encryption for data in transit
  • Quarterly backup and restoration testing
  • Continuous assessment of critical third-party providers and their resilience
  • Planned improvements in SIEM-based centralized monitoring and DLP capabilities
  • Transparent documentation for customer security and compliance assessments

規制環境でも信頼される

RELIANOID 規制対象セクターで事業を展開するクライアントを以下のようにサポートします。

  • Security documentation mapped to ISO/IEC 27017/27018 principles
  • Security and compliance information supporting customer assessments
  • Guidance for secure deployment and operational practices
  • Documentation covering data protection, vulnerability management, access controls, and third-party risk
  • Security and compliance documentation available for customer audits and assessments upon request

ドキュメントレビュー

日付コメント
10th July 202527017および27018のアライメントステートメントの初版発行
30th June 2026セキュリティとコンプライアンスレビューは、 RELIANOID セキュリティコンプライアンスレポート 2026年第2四半期

連絡と保証

詳細なコンプライアンス文書、技術マッピング、統合支援に関するお問い合わせをお待ちしております。 RELIANOID ISO 準拠のインフラストラクチャ内。

コンプライアンス&セキュリティチームにお問い合わせください

最新のセキュリティレポートをダウンロード