Skip to content

    合規就緒 評估

    回答幾個問題以評估您的安全態勢,並獲得個人化的合規建議。

    1
    2
    3
    4

    告訴我們您的組織

    協助我們瞭解您的業務,以便量身定制建議。

    您所屬的產業為何?
    員工人數?
    是否處理敏感的客戶資料?
    請回答所有問題

    How the Compliance Assessment Works

    Our free compliance readiness assessment walks through four short steps. It maps your industry, headcount, existing security posture, and regulatory exposure to the frameworks that apply to your business, then produces a readiness score and a prioritized action plan. Nothing you enter is required to view the framework guidance below.

    1. 1
      告訴我們您的組織

      協助我們瞭解您的業務,以便量身定制建議。

    2. 2
      您目前的安全態勢

      我們將評估您現有的安全基礎,找出優勢與差距。

    3. 3
      合規要求

      選擇與您業務相關的法規和框架。

    4. 4
      您的合規就緒結果

      根據您的回答,以下是您的合規就緒評估。

    Frameworks the Finder Can Recommend

    Based on your answers, the finder surfaces the standards and regulations most relevant to your organization. The matrix below shows each trigger question, the framework it maps to, and what that framework covers, so you can see the full range of recommendations before you begin.

    Frameworks the Finder Can Recommend
    If this applies to youRecommended frameworkWhat it covers
    企業客戶是否要求 SOC 2?SOC 2安全性、可用性及機密性的信賴服務準則,大多數企業買家的要求。
    是否處理受保護的健康資訊(PHI)?[EN] HIPAA[EN] Required for organizations that create, receive, maintain, or transmit protected health information (PHI). Covers administrative, physical, and technical safeguards.
    是否處理受保護的健康資訊(PHI)?HITRUST對應 HIPAA 要求的綜合安全框架,用於保護健康資訊。
    是否處理支付卡資料?PCI DSS支付卡產業資料安全標準,適用於處理持卡人資料的組織。
    是否與美國國防部合作?CMMC國防部承包商所需的 Cybersecurity Maturity Model Certification。
    是否有歐盟客戶或處理歐盟個人資料?GDPR處理歐盟個人資料的組織須遵守的一般資料保護規則合規。
    是否有加州客戶?CCPA / CPRA服務加州居民的企業須遵守的加州消費者隱私法及加州隱私權法。
    是否為上市公司或計劃 IPO?SOX IT 合規上市公司及計劃 IPO 組織須遵守的 Sarbanes-Oxley 第 404 條 IT 一般控制措施。
    是否製造醫療器材或 SaMD?FDA 網路安全醫療器材製造商及 SaMD 公司須遵守的 FDA 第 524B 條上市前網路安全要求。
    是否處理印度個人的個人資料?India DPDP Act處理印度個人資料的組織須遵守的數位個人資料保護法合規。
    您的產品或服務中是否使用 AI/ML?ISO 42001AI 管理系統國際標準。為開發、部署或採購 AI 系統的組織展示負責任的 AI 治理。
    您的產品或服務中是否使用 AI/ML?NIST AI RMF用於值得信賴之 AI 設計、開發、部署及使用的 NIST AI 風險管理框架。涵蓋治理、對應、衡量及 AI 風險管理。
    您是否向澳洲政府銷售或與其合作?IRAP澳洲政府 ICT 安全評估計畫。為澳洲政府機構提供服務的組織必須符合此要求。
    您是否向新加坡政府銷售或與其合作?ISMAP新加坡政府雲端安全評估框架。向新加坡政府銷售的雲端服務供應商必須符合此要求。
    您是否向西班牙或歐盟政府機構銷售或與其合作?ENS西班牙國家安全框架(Esquema Nacional de Seguridad)。與西班牙公共部門實體及歐盟政府機構合作的組織必須遵守。

    Understanding Your Readiness Score

    Your responses are scored from 0 to 100 across documented policies, security ownership, prior audits, automation tooling, and data sensitivity. The score maps to one of four maturity tiers, each with tailored guidance on where to focus next.

    Understanding Your Readiness Score
    Score rangeMaturity tierWhat it means
    0 - 30初期階段貴組織正處於建立合規方案的初期階段。這對成長中的公司而言十分常見,正確的指導能大幅加速就緒進程。
    31 - 60建設中您已有部分基礎,但仍存在差距。結構化的合規路線圖將幫助您有效彌補差距並準備認證。
    61 - 85日趨成熟您的安全態勢已有良好發展。透過針對性改善與專家指導,您可以達成並維持多框架合規。
    86 - 100進階貴組織展現了強大的安全成熟度。專注於維持合規、優化流程,並在不斷演變的要求中保持領先。