合規就緒 評估
回答幾個問題以評估您的安全態勢,並獲得個人化的合規建議。
告訴我們您的組織
協助我們瞭解您的業務,以便量身定制建議。
How the Compliance Assessment Works
Our free compliance readiness assessment walks through four short steps. It maps your industry, headcount, existing security posture, and regulatory exposure to the frameworks that apply to your business, then produces a readiness score and a prioritized action plan. Nothing you enter is required to view the framework guidance below.
- 1告訴我們您的組織
協助我們瞭解您的業務,以便量身定制建議。
- 2您目前的安全態勢
我們將評估您現有的安全基礎,找出優勢與差距。
- 3合規要求
選擇與您業務相關的法規和框架。
- 4您的合規就緒結果
根據您的回答,以下是您的合規就緒評估。
Frameworks the Finder Can Recommend
Based on your answers, the finder surfaces the standards and regulations most relevant to your organization. The matrix below shows each trigger question, the framework it maps to, and what that framework covers, so you can see the full range of recommendations before you begin.
| If this applies to you | Recommended framework | What it covers |
|---|---|---|
| 企業客戶是否要求 SOC 2? | SOC 2 | 安全性、可用性及機密性的信賴服務準則,大多數企業買家的要求。 |
| 是否處理受保護的健康資訊(PHI)? | [EN] HIPAA | [EN] Required for organizations that create, receive, maintain, or transmit protected health information (PHI). Covers administrative, physical, and technical safeguards. |
| 是否處理受保護的健康資訊(PHI)? | HITRUST | 對應 HIPAA 要求的綜合安全框架,用於保護健康資訊。 |
| 是否處理支付卡資料? | PCI DSS | 支付卡產業資料安全標準,適用於處理持卡人資料的組織。 |
| 是否與美國國防部合作? | CMMC | 國防部承包商所需的 Cybersecurity Maturity Model Certification。 |
| 是否有歐盟客戶或處理歐盟個人資料? | GDPR | 處理歐盟個人資料的組織須遵守的一般資料保護規則合規。 |
| 是否有加州客戶? | CCPA / CPRA | 服務加州居民的企業須遵守的加州消費者隱私法及加州隱私權法。 |
| 是否為上市公司或計劃 IPO? | SOX IT 合規 | 上市公司及計劃 IPO 組織須遵守的 Sarbanes-Oxley 第 404 條 IT 一般控制措施。 |
| 是否製造醫療器材或 SaMD? | FDA 網路安全 | 醫療器材製造商及 SaMD 公司須遵守的 FDA 第 524B 條上市前網路安全要求。 |
| 是否處理印度個人的個人資料? | India DPDP Act | 處理印度個人資料的組織須遵守的數位個人資料保護法合規。 |
| 您的產品或服務中是否使用 AI/ML? | ISO 42001 | AI 管理系統國際標準。為開發、部署或採購 AI 系統的組織展示負責任的 AI 治理。 |
| 您的產品或服務中是否使用 AI/ML? | NIST AI RMF | 用於值得信賴之 AI 設計、開發、部署及使用的 NIST AI 風險管理框架。涵蓋治理、對應、衡量及 AI 風險管理。 |
| 您是否向澳洲政府銷售或與其合作? | IRAP | 澳洲政府 ICT 安全評估計畫。為澳洲政府機構提供服務的組織必須符合此要求。 |
| 您是否向新加坡政府銷售或與其合作? | ISMAP | 新加坡政府雲端安全評估框架。向新加坡政府銷售的雲端服務供應商必須符合此要求。 |
| 您是否向西班牙或歐盟政府機構銷售或與其合作? | ENS | 西班牙國家安全框架(Esquema Nacional de Seguridad)。與西班牙公共部門實體及歐盟政府機構合作的組織必須遵守。 |
Understanding Your Readiness Score
Your responses are scored from 0 to 100 across documented policies, security ownership, prior audits, automation tooling, and data sensitivity. The score maps to one of four maturity tiers, each with tailored guidance on where to focus next.
| Score range | Maturity tier | What it means |
|---|---|---|
| 0 - 30 | 初期階段 | 貴組織正處於建立合規方案的初期階段。這對成長中的公司而言十分常見,正確的指導能大幅加速就緒進程。 |
| 31 - 60 | 建設中 | 您已有部分基礎,但仍存在差距。結構化的合規路線圖將幫助您有效彌補差距並準備認證。 |
| 61 - 85 | 日趨成熟 | 您的安全態勢已有良好發展。透過針對性改善與專家指導,您可以達成並維持多框架合規。 |
| 86 - 100 | 進階 | 貴組織展現了強大的安全成熟度。專注於維持合規、優化流程,並在不斷演變的要求中保持領先。 |