ื“ืœื’ ืœืชื•ื›ืŸ ืจืืฉื™
Certyneo

ืชืื™ืžื•ืช FedRAMP ื‘ื‘ืจื™ืื•ืช: ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช

ื”ืžืกื’ืจืช FedRAMP ืžื˜ื™ืœื” ื“ืจื™ืฉื•ืช ืงืคื“ื ื™ื•ืช ืขืœ ืคืชืจื•ื ื•ืช ืขื ืŸ ื”ืžืฉืžืฉื™ื ื’ื•ืคื™ื่”้‚ฆื™ื™ื ื‘ืชื—ื•ื ื”ื‘ืจื™ืื•ืช ื‘ืืจืฆื•ืช ื”ื‘ืจื™ืช. ื’ืœื” ื›ื™ืฆื“ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืชื•ืืžืช HDS ื•-FedRAMP ืขื•ื ื” ืขืœ ืืชื’ืจื™ื ืืœื”.

ร‰quipe รฉditoriale Certyneo11 ื“ืงื•ืช ืงืจื™ืื”

ร‰quipe รฉditoriale Certyneo

ื›ื•ืชื‘ โ€” Certyneo ยท ืื•ื“ื•ืช Certyneo

ื”ื”ืชื›ื ืกื•ืช ื‘ื™ืŸ ืชืงื ื•ืช ืขื ืŸ ืืžืจื™ืงืื™ื•ืช ืœื‘ื™ืŸ ืชืงื ื™ื ืื™ืจื•ืคืื™ื™ื ืœืื‘ื˜ื—ืช ื ืชื•ื ื™ ื‘ืจื™ืื•ืช ืžืฉื ื” ืžื—ื“ืฉ ืืช ืงืจื™ื˜ืจื™ื•ื ื™ ื”ื‘ื—ื™ืจื” ืฉืœ ื›ืœื™ื ื“ื™ื’ื™ื˜ืœื™ื™ื ื‘ืขื ืฃ ื”ืจืคื•ืื™. ืขื‘ื•ืจ ืืจื’ื•ื ื™ื ื”ืคื•ืขืœื™ื ื‘ืฆื•ืžืช ืฉืœ ืฉื•ื•ืงื™ื่”้‚ฆื™ื™ื ืืžืจื™ืงืื™ื™ื ื•ืื™ืจื•ืคืื™ื™ื โ€” ื‘ืชื™ ื—ื•ืœื™ื, ืžืขื‘ื“ื•ืช ืชืจื•ืคื•ืช, ืกืคืงื™ ืฉื™ืจื•ืชื™ ื‘ืจื™ืื•ืช ืจื‘-ืœืื•ืžื™ื™ื โ€” ืชืื™ืžื•ืช FedRAMP ื‘ืชื—ื•ื ื”ื‘ืจื™ืื•ืช ืขื ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื”ืคื›ื” ืœืขื™ืœืช ื—ื•ื‘ื” ืืกื˜ืจื˜ื’ื™ืช, ื•ืœื ืขื•ื“ ืกืžืŸ ืชื™ื‘ื” ื‘ืœื‘ื“.

ืžืืžืจ ื–ื” ืคื•ืขื ื— ืืช ื™ืกื•ื“ื•ืช ืชื•ื›ื ื™ืช FedRAMP, ื”ื‘ื™ื˜ื•ื™ ืฉืœื” ืขื ื”ื”ืกืžื›ื” HDS (Hรฉbergeur de Donnรฉes de Santรฉ) ื”ืฆืจืคืชื™ืช, ื•ื”ื“ืจืš ืฉื‘ื” ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืžืื•ื‘ื˜ื—ืช ืžืฉืชืœื‘ืช ื‘ืฉืชื™ ืžืกื’ืจื•ืช ืจื’ื•ืœื˜ื•ืจื™ื•ืช ืืœื”. ื”ื•ื ืžื›ื•ื•ืŸ ืœ-DSI, DPO, ืžื ื”ืœื™ ืขื ื™ื™ื ื™ื ืจืคื•ืื™ื™ื ื•ืื—ืจืื™ื ืœืชืื™ืžื•ืช ืฉื—ื™ื™ื‘ื™ื ืœื”ื›ืจื™ืข ื‘ื‘ื—ื™ืจื•ืช ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืขื ื”ืฉืœื›ื•ืช ืžืฉืคื˜ื™ื•ืช ื•ื”ืคืขืœืชื™ื•ืช ืžืฉืžืขื•ืชื™ื•ืช.

ื”ื‘ื ืช ืชื•ื›ื ื™ืช FedRAMP ื•ื“ืจื™ืฉื•ืชื™ื” ืœืชื—ื•ื ื”ื‘ืจื™ืื•ืช

ืžื”ื• FedRAMP?

Federal Risk and Authorization Management Program (FedRAMP) ื”ื™ื ืชื•ื›ื ื™ืช ืžืžืฉืœืชื™ืช ืืžืจื™ืงืื™ืช ืฉื ื•ืฆืจื” ื‘ืฉื ืช 2011 ื‘ืกืžื›ื•ืชื” ืฉืœ Office of Management and Budget (OMB). ื”ื™ื ืžืชืงื ืช ื”ืขืจื›ื” ืฉืœ ืื‘ื˜ื—ื”, ื”ืจืฉืื” ื•ื›ื™ื•ืœ ืžืชืžืฉืš ืฉืœ ืฉื™ืจื•ืชื™ ืขื ืŸ ื”ืžื™ื•ืขื“ื™ื ืœืกื•ื›ื ื•ื™ื•ืช่”้‚ฆื™ื•ืช ืืžืจื™ืงืื™ื•ืช. ื‘ืฉื ืช 2023, ื—ื•ืง FedRAMP Authorization ื—ืชื•ื, ื”ืžืงื•ื“ื“ ืกื•ืคื™ืช ืืช ื”ืชื•ื›ื ื™ืช ื‘ื—ื•ืง่”้‚ฆื™ (44 U.S.C. ยง 3607).

ื›ื“ื™ ืœื”ืฉื™ื’ ื”ืจืฉืืช FedRAMP, ืกืคืง ืฉื™ืจื•ืชื™ ืขื ืŸ (CSP) ื—ื™ื™ื‘ ืœื”ื“ื’ื™ื ืืช ืขืžื™ื“ืชื• ื‘ืงื‘ื™ืขื™ ื”ืื‘ื˜ื—ื” ื”ืžื•ื’ื“ืจื™ื ื‘-NIST SP 800-53. ืฉืœื•ืฉ ืจืžื•ืช ื”ืฉืคืขื” ืงื™ื™ืžื•ืช: Low, Moderate ื•-High. ื‘ืชื—ื•ื ื”ื‘ืจื™ืื•ืช่”้‚ฆื™ โ€” ื”ื›ื•ืœืœ ื‘ืขื™ืงืจ ืืช Department of Veterans Affairs (VA), Department of Health and Human Services (HHS), Centers for Medicare & Medicaid Services (CMS) โ€” ื”ืจืžื” High ื ื“ืจืฉืช ืœืขืชื™ื ืงืจื•ื‘ื•ืช, ื‘ื’ืœืœ ื”ืจื’ื™ืฉื•ืช ืฉืœ ื ืชื•ื ื™ PHI (Protected Health Information) ื”ืžื›ื•ืกื™ื ื‘ื—ื•ืง HIPAA.

HIPAA, FedRAMP ื•ืฉืจืฉืจืช ื”ืฆื™ื•ืช ื”ืชื™ืขื•ื“ื™

ื”ื‘ื™ื˜ื•ื™ ื‘ื™ืŸ HIPAA (Health Insurance Portability and Accountability Act ืžืฉื ืช 1996) ื•-FedRAMP ื™ื•ืฆืจ ืžื’ื‘ืœื” ื›ืคื•ืœื” ืœืคืชืจื•ื ื•ืช SaaS ืฉืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื”ืžืคื•ืชื—ื™ื ื‘ื”ืงืฉืจ่”้‚ฆื™ ืฉืœ ื‘ืจื™ืื•ืช. HIPAA ืžื˜ื™ืœื” ื›ืœืœื™ื ืงืคื“ื ื™ื™ื ืขืœ ืกื•ื“ื™ื•ืช (Privacy Rule) ื•ืื‘ื˜ื—ื” (Security Rule) ืฉืœ PHI, ื‘ืขื•ื“ FedRAMP ืžืืฉืจืช ื›ื™ ื”ืชืฉืชื™ืช ื”ืขื ืŸ ืฉืขืœื™ื” ืžื‘ื•ืกืกืช ื”ืคืชืจื•ืŸ ืžื›ื‘ื“ืช ืชืงื ื™ื ืœื‘ื™ื˜ื—ื•ืŸ ืฉื ื™ืชื ื™ื ืœื‘ื™ืงื•ืจืช ื•ืžืชืžืฉื›ื™ื.

ื‘ืžื™ืœื™ื ื‘ืจื•ืจื•ืช, ืกืคืง ื”ืžืฆื™ืข ืคืชืจื•ื ื•ืช ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื‘ื‘ืจื™ืื•ืช ืœื’ื•ืคื™ื่”้‚ฆื™ื™ื ืืžืจื™ืงืื™ื™ื ื—ื™ื™ื‘:

  • ืœื”ืฉื™ื’ ืื• ืœื”ื™ืฉืขืŸ ืขืœ ATO (Authority to Operate) ืฉืœ FedRAMP ืฉื”ื•ืฆืื” ืขืœ ื™ื“ื™ ืกื•ื›ื ื•ืช ืกืคื•ื ืกืจื™ืช ืื• ื“ืจืš Joint Authorization Board (JAB);
  • ืœื—ืชื•ื ืขืœ Business Associate Agreement (BAA) ืฉืœ HIPAA ืขื ืžืชืงื ื™ ื”ืœืงื•ื—ื•ืช;
  • ืœื”ื‘ื˜ื™ื— audit logging ืฉืœ ื›ืœ ืคืขื•ืœืช ื—ืชื™ืžื”, ื‘ื”ืชืื ืœื“ืจื™ืฉื•ืช ืฉืœืžื•ืช ื”ืžืกืžื›ื™ื;
  • ืœื”ื’ื™ืข ืœื‘ื™ื˜ื—ื•ืŸ residency ืฉืœ ื ืชื•ื ื™ื ื‘ืื–ื•ืจื™ื ื’ื™ืื•ื’ืจืคื™ื™ื ืžืื•ืฉืจื™ื.

ืจืžื•ืช FedRAMP ื•ื”ืฉืคืขืชืŸ ืขืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช

ื”ื‘ื—ื™ืจื” ืฉืœ ืจืžืช FedRAMP ืงื•ื‘ืขืช ื™ืฉื™ืจื•ืช ืืช ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ื˜ื›ื ื™ืช ืฉืœ ืคืชืจื•ืŸ ื”ื—ืชื™ืžื”. ื‘ืจืžื” High, ื”ื“ืจื™ืฉื•ืช ื›ื•ืœืœื•ืช ื‘ืขื™ืงืจ:

  • ื”ืฆืคื ืช AES-256 ืœื ืชื•ื ื™ื ื‘ืžื ื•ื—ื” ื•-TLS 1.2+ ืœื ืชื•ื ื™ื ื‘ืชื ื•ืขื”;
  • Authentication multifactor (MFA) ื—ื•ื‘ื” ืœื›ืœ ื”ื’ื™ืฉื•ืช ืฉืœ ืžื ื”ืœื™ื;
  • ื™ื•ืžื ื™ื ืœื‘ื™ืงื•ืจืช ื‘ืœืชื™ ื ื™ืชื ื™ื ืœื”ืฉื™ื ื•ื™ ื•ื”ื—ื–ืงื” ืžื™ื ื™ืžืœื™ืช ืฉืœ 3 ืฉื ื™ื;
  • ืกืจื™ืงืช ืคื’ื™ืขื•ื™ื•ืช ื—ื•ื“ืฉื™ืช ื•ื‘ื“ื™ืงื•ืช penetration ืฉื ืชื™ื•ืช ืขืœ ื™ื“ื™ ืฆื“ ืฉืœื™ืฉื™ ืžื•ืจืฉื” (3PAO โ€” Third-Party Assessment Organization);
  • ื ื™ื”ื•ืœ ืžืชืžืฉืš ืฉืœ ืชืงืœื•ืช ืื‘ื˜ื—ื” ืขื ื”ื•ื“ืขื” ืชื•ืš ืฉืขื” ืœ-US-CERT.

ื“ืจื™ืฉื•ืช ื˜ื›ื ื™ื•ืช ืืœื” ื™ื•ืฆืจื•ืช ืชืงืŸ ืœืื‘ื˜ื—ืช ืžืกืžื›ื™ื ื”ื—ื•ืจื’ ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืžื–ื” ื”ืžืชื‘ืงืฉ ื‘ืงื“ืจ ื”ืื™ืจื•ืคื™ ื‘ืœื‘ื“, ืžื” ืฉื”ื•ืคืš ืืช ื”ืฆื™ื•ืช ื”ื›ืคื•ืœ FedRAMP/HDS ืœืžื™ื•ื—ื“ ืงืฉื”.

HDS ื•-FedRAMP: ื”ืฆื™ื•ืช ื”ื›ืคื•ืœ ืœื’ื•ืจืžื™ื ืจื‘-ืœืื•ืžื™ื™ื

ื”ื”ืกืžื›ื” HDS: ื”ืชืงืŸ ื”ืฆืจืคืชื™ ืฉืœ ื”ื”ืชื™ื™ื—ืกื•ืช

ื‘ืฆืจืคืช, ืื—ืกื•ืŸ ื ืชื•ื ื™ ื‘ืจื™ืื•ืช ืžื•ืกื“ืจ ืœืคื™ ืกืขื™ืฃ L.1111-8 ืฉืœ Code de la santรฉ publique, ืžืฉืœื™ื ืขื decree nยฐ2018-137 ืž-26 ื‘ืคื‘ืจื•ืืจ 2018. ื›ืœ ืžืื—ืกืŸ ื”ืžื˜ืคืœ ื‘ื ืชื•ื ื™ ื‘ืจื™ืื•ืช ื‘ืื•ืคื™ ืื™ืฉื™ ืขื‘ื•ืจ ืžืงืฆื•ืข ืื• ืชืงืŸ ื‘ืจื™ืื•ืช ื—ื™ื™ื‘ ืœืงื‘ืœ ื”ืกืžื›ื” HDS ืฉื”ื•ืฆืื” ืขืœ ื™ื“ื™ ืืจื’ื•ืŸ ืžื•ืกืžืš ืขืœ ื™ื“ื™ COFRAC.

ื”ื”ืกืžื›ื” HDS ืžื‘ื•ืกืกืช ืขืœ ืฉืฉ ืคืขื•ืœื•ืช ืื—ืกื•ืŸ (ืชืฉืชื™ืช ืคื™ื–ื™ืช, ืชืฉืชื™ืช ื•ื™ืจื˜ื•ืืœื™ืช, ืคืœื˜ืคื•ืจืžืช ืื—ืกื•ืŸ, ื ื™ื”ื•ืœ ื•ื ื™ืฆื•ืœ, ื’ื™ื‘ื•ื™, infogรฉrance) ื•ืชื•ืžื›ืช ื‘ืชืงื ื™ื ISO/IEC 27001 ื•-ISO/IEC 27701. ืœืคืชืจื•ืŸ ืฉืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืชื•ืืžืช ืชืงื ื•ืช ืื™ืจื•ืคืื™ื•ืช, ืฉื™ืžื•ืฉ ื‘ืžืื—ืกืŸ ืžื•ืกืžืš HDS ืื™ื ื• ืื•ืคืฆื™ื•ื ืœื™ ื›ืืฉืจ ืžืกืžื›ื™ื ื—ืชื•ืžื™ื ืžื›ื™ืœื™ื ื ืชื•ื ื™ ื‘ืจื™ืื•ืช.

ื ืงื•ื“ื•ืช ื”ืชื›ื ืกื•ืช ื•ื•ื™ืกื•ืช ื‘ื™ืŸ FedRAMP ืœ-HDS

ื”ื”ืฉื•ื•ืื” ื‘ื™ืŸ ืฉื ื™ ื”ืชืงื ื™ื ื—ื•ืฉืคืช ื ืงื•ื“ื•ืช ื”ืชื›ื ืกื•ืช ืžืฉืžืขื•ืชื™ื•ืช ืืš ื’ื ื”ื‘ื“ืœื™ื ื‘ื•ืœื˜ื™ื:

ื ืงื•ื“ื•ืช ืžืฉื•ืชืคื•ืช:

  • ื“ืจื™ืฉื” ืœื ื™ื”ื•ืœ ืชื•ืขื“ื•ืช ืฉืœ ืกื›ื ื•ืช ืื‘ื˜ื—ื”;
  • ื‘ืงืจื•ืช ื’ื™ืฉื” ืงืคื“ื ื™ื•ืช ื•ืขื™ืงืจื•ืŸ ืฉืœ ื”ืคื—ื•ืช ื”ืจืฉืื”;
  • ืชื•ื›ื ื™ืช ืจืฆื™ืคื•ืช ืขืกืงื™ืช (PCA/BCP) ื•ืชื•ื›ื ื™ืช ื”ืชืื•ืฉืฉื•ืช ืœืื—ืจ ืืกื•ืŸ (PRA/DRP) ืฉื ื‘ื“ืงื•ืช ืžืขืช ืœืขืช;
  • ืžื™ืขื“ื•ืช ืฉืœ ื’ื™ืฉื•ืช ืœื ืชื•ื ื™ื ืจื’ื™ืฉื™ื.

ื”ื‘ื“ืœื™ื ืขื™ืงืจื™ื™ื:

  • Residency ืฉืœ ื ืชื•ื ื™ื: HDS ื ื™ื™ื˜ืจืœื™ืช ื’ื™ืื•ื’ืจืคื™ืช ืืš ืžืขื“ื™ืคื” ื‘ืื•ืคืŸ ืžืฉืชืžืข ืืช ื”ืื™ื—ื•ื“ ื”ืื™ืจื•ืคื™; FedRAMP ื“ื•ืจืฉืช ื‘ื“ืจืš ื›ืœืœ ืื—ืกื•ืŸ ืขืœ ืงืจืงืข ืืžืจื™ืงืื™ืช (FedRAMP High ื›ื•ืคื” ืœืขืชื™ื ืงืจื•ื‘ื•ืช GovCloud ื™ื™ืขื•ื“ื™ื•ืช);
  • ื“ื’ื ื‘ื™ืงื•ืจืช: FedRAMP ืžืฉืชืžืฉืช ื‘-3PAOs ืžื•ืจืฉื™ื ืขืœ ื™ื“ื™ ื”ืชื•ื›ื ื™ืช ืขืฆืžื”; HDS ืžืกืชืžื›ืช ืขืœ ืืจื’ื•ื ื™ ื”ืกืžื›ื” ืžื•ืจืฉื™ื COFRAC;
  • ืžื—ื–ื•ืจ ื”ืชื—ื“ืฉื•ืช: FedRAMP ื›ื•ืคื” ื ื™ื˜ื•ืจ ืžืชืžืฉืš (ConMon) ืขื ื“ื•ื—ื•ืช ื—ื•ื“ืฉื™ื™ื; HDS ื“ื•ืจืฉืช ื‘ื™ืงื•ืจืช ื”ืชื—ื“ืฉื•ืช ืชืœืช-ืฉื ืชื™ืช.

ื”ื‘ื“ืœื™ื ืืœื” ืžื›ืจื™ื—ื™ื ืคืชืจื•ื ื•ืช ื”ืคื•ืขืœื•ืช ื‘ืฉื ื™ ื”ืฉื•ื•ืงื™ื ืœืชื—ื–ื•ืง ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช ืขื ืŸ ื ืคืจื“ื•ืช ืื• ืœื”ืคืขื™ืœ ืกืคืงื™ hyperscalers ื‘ืขืœื™ ื”-AWS GovCloud FedRAMP High ATO ื•ื’ื ืชืฉืชื™ืช ืžื•ืกืžื›ืช HDS ื‘ืื™ืจื•ืคื”.

ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื›ื›ืœื™ ืฉืœ ืฆื™ื•ืช ื‘ื–ืจื™ืžื•ืช ืขื‘ื•ื“ื” ืฉืœ ื‘ืจื™ืื•ืช

ืขืจืš ืขื“ื•ืช ื•ืฉืœืžื•ืช ืžืกืžื›ื™ื

ื‘ืกื‘ื™ื‘ื” ืžืกื“ืจืช ื›ืžื• ื‘ืจื™ืื•ืช, ื”ืขืจืš ื”ืžืฉืคื˜ื™ ืฉืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื ืฉืขืŸ ืขืœ ืฉื ื™ ืขืžื•ื“ื™ื: ื”ืฉืœืžื•ืช ืฉืœ ื”ืžืกืžืš (ืื™-ืฉื™ื ื•ื™ ืœืื—ืจ ื—ืชื™ืžื”) ื•-ื–ื™ื”ื•ื™ ืืžื™ืŸ ืฉืœ ื”ื—ื•ืชื (authentication). ืฉืชื™ ื“ืจื™ืฉื•ืช ืืœื” ื”ืŸ ื‘ืœื‘ ืฉืœ ื”ืจื’ื•ืœืฆื™ื” eIDAS ื•ื’ื ืฉืœ ืชืงื ื™ื NIST ื”ืžืฉืžืฉื™ื FedRAMP.

ืชืงื ื•ืŸ eIDAS ืžืกืคืจ 910/2014 ืžื‘ื—ื™ืŸ ื‘ื™ืŸ ืฉืœื•ืฉ ืจืžื•ืช ื—ืชื™ืžื”: ืคืฉื•ื˜ื” (SES), ืžืชืงื“ืžืช (AdES) ื•ืžื•ืกืžื›ืช (QES). ื‘ืชื—ื•ื ื”ื‘ืจื™ืื•ืช ื”ืื™ืจื•ืคื™ื•ืช, ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืžืชืงื“ืžืช (AdES), ืชื•ืืžืช ืœืชืงื ื™ื ETSI EN 319 132 ืœืคื•ืจืžื˜ื™ื XAdES, CAdES ื•-PAdES, ื‘ื“ืจืš ื›ืœืœ ืžื•ืžืœืฆืช ืœืžืกืžื›ื™ื ืจืคื•ืื™ื™ื ืจื’ื™ืฉื™ื (ื”ืกื›ืžื•ืช ืžื•ื“ืขื•ืช, ืžืจืฉืžื•ืช ืืœืงื˜ืจื•ื ื™ื•ืช, ืงื‘ืฆื™ ืžื—ืงืจ ืงืœื™ื ื™).

ื‘ืืจืฆื•ืช ื”ื‘ืจื™ืช, ื”ืžืกื’ืจืช ื”ื—ืœื” ื”ื™ื ESIGN Act (Electronic Signatures in Global and National Commerce Act ืžืฉื ืช 2000) ื•-UETA (Uniform Electronic Transactions Act), ื”ืžื›ื™ืจื•ืช ื‘ืชื•ืงืฃ ืžืฉืคื˜ื™ ืฉืœ ื—ืชื™ืžื•ืช ืืœืงื˜ืจื•ื ื™ื•ืช ืžื‘ืœื™ ืœื”ื˜ื™ืœ ืคื•ืจืžื˜ ื˜ื›ื ื™ ืกืคืฆื™ืคื™. ืขื ื–ืืช, ื‘ื”ืงืฉืจ FedRAMP, ื“ืจื™ืฉื•ืช ื˜ื›ื ื™ื•ืช ืœืื‘ื˜ื—ื” (ื”ืฆืคื ื”, audit trail, MFA) ื›ื•ืคื™ื de facto ืจืžื” ื”ืžืงื‘ื™ืœื” ืœ-AdES ื”ืื™ืจื•ืคื™ื•ืช.

Authentication ืฉืœ ืžืงืฆื•ืขื•ืช ื”ื‘ืจื™ืื•ืช ื•ื–ื”ื•ืช ื“ื™ื’ื™ื˜ืœื™ืช

ืื—ื“ ื”ืืชื’ืจื™ื ื”ืกืคืฆื™ืคื™ื™ื ืฉืœ ืชื—ื•ื ื”ื‘ืจื™ืื•ืช ื”ื•ื ื”-authentication ื”ื—ื–ืง ืฉืœ ืžืงืฆื•ืขื•ืช. ื‘ืฆืจืคืช, Carte de Professionnel de Santรฉ (CPS) ื•ื”ืฉืงื•ืœื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœื” e-CPS, ืžื ื•ื”ืœื•ืช ืขืœ ื™ื“ื™ ANS (Agence du Numรฉrique en Santรฉ), ืžื”ื•ื•ื•ืช ื‘ืกื™ืก ืฉืœ ื–ื”ื•ืช ื“ื™ื’ื™ื˜ืœื™ืช ืฉืžื•ื›ืจื” ืœื’ื™ืฉื” ืœืžืขืจื›ื•ืช ื‘ืจื™ืื•ืช ื•ื—ืชื™ืžื” ืฉืœ ืžืกืžื›ื™ื ืจืคื•ืื™ื™ื. ื”ืื™ื ื˜ื’ืจืฆื™ื” ืฉืœ ื”-e-CPS ื‘ืคืชืจื•ืŸ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืžืืคืฉืจืช ืœื”ื’ื™ืข ืœืจืžืช ื—ืชื™ืžื” ืžื•ืกืžื›ืช (QES) ืœืžืงืจื™ื ื”ื“ื•ืจืฉื™ื ืืช ื”ืขืจืš ื”ื”ื•ื›ื—ื™ ื”ื’ื‘ื•ื” ื‘ื™ื•ืชืจ.

ื‘ืฆื“ ืืžืจื™ืงื ื™, ื”-PIV (Personal Identity Verification, FIPS 201) ื”ื•ื ืชืงืŸ ื”ื–ื”ื•ืช่”้‚ฆื™ ื”ืฉืงื•ืœ. ืกื•ื›ื ื•ื™ื•ืช่”้‚ฆื™ื•ืช ืฉืœ ื‘ืจื™ืื•ืช ื“ื•ืจืฉื•ืช ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืื™ืžื•ืช PIV ืœืขืกืงืื•ืช ืจื’ื™ืฉื•ืช ืžืื•ื“, ืžื” ืฉื›ื•ืคื” ืขืœ ืคืชืจื•ื ื•ืช ื—ืชื™ืžื” ืœืฉืœื‘ ืžื—ื‘ืจื™ื ืชื•ืืžื™ื ืขื ืชืฉืชื™ืช ื–ื•.

ืขื‘ื•ืจ ืืจื’ื•ื ื™ื ื”ืžื‘ืงืฉื™ื ืœื”ื‘ื™ืŸ ืืช ืžื›ืœื•ืœ ื”ืืคืฉืจื•ื™ื•ืช ื”ื–ืžื™ื ื•ืช, ื”-ื”ืฉื•ื•ืื” ืฉืœ ืคืชืจื•ื ื•ืช ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืžืืคืฉืจืช ืœื”ืขืจื™ืš ืจืžื•ืช authentication ื”ื ืชืžื›ื•ืช ืขืœ ื™ื“ื™ ื›ืœ ืคืœื˜ืคื•ืจืžื”.

ื ื™ื”ื•ืœ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ืฉืœ ืžืกืžื›ื™ ื‘ืจื™ืื•ืช

ื”ืฆื™ื•ืช FedRAMP/HDS ืœื ืžืกืชื™ื™ื ื‘ืคืขื•ืœืช ื—ืชื™ืžื”. ื”ื™ื ืžื›ืกื” ืืช ื›ืœ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ื”ืชื™ืขื•ื“ื™:

  • ื™ืฆื™ืจื” ื•templating: ื“ื’ืžื™ ื”ืกื›ืžื” ืžื•ื“ืขืช, ื˜ืคืกื™ ื›ื ื™ืกื” ืื• ืคืจื•ื˜ื•ืงื•ืœื™ ืžื—ืงืจ ืงืœื™ื ื™ ื—ื™ื™ื‘ื™ื ืœื”ื™ื•ืช ื’ืจืกื•ืช ื•ืื•ื“ื™ื˜ื™ื•ืช;
  • ื—ืชื™ืžื” ื•horodatage: ื›ืœ ื—ืชื™ืžื” ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ืžืœื•ื•ื” ื‘-horodatage ืžื•ืกืžืš (RFC 3161) ื”ืžื‘ื˜ื™ื— ืืช ื”ืชืืจื™ืš ื”ื‘ื˜ื•ื— ืฉืœ ื”ืคืขื•ืœื”;
  • ืืจื›ื™ื•ืŸ ื”ื•ื›ื—: ืฉืžื™ืจืช ื”ืจืื™ื•ืช ืฉืœ ื—ืชื™ืžื” (ื“ื•ื— ื‘ื™ืงื•ืจืช, ืชืขื•ื“ื•ืช, hash ืฉืœ ื”ืžืกืžืš) ื—ื™ื™ื‘ืช ืœืฆื™ื™ืช ืœืชืงื•ืคื•ืช ื”ื—ื•ืงื™ื•ืช โ€” ืžื™ื ื™ืžื•ื 10 ืฉื ื™ื ืœืชื™ืงื™ื•ืช ืจืคื•ืื™ื•ืช ื‘ืฆืจืคืช (ืกืขื™ืฃ R.1112-7 CSP), 6 ืฉื ื™ื ืœืชื™ืงื™ื•ืช HIPAA;
  • ืฉืœื™ืœื” ื•ื‘ื™ื˜ื•ืœ: ืžื ื’ื ื•ื ื™ OCSP (Online Certificate Status Protocol) ืื• CRL (Certificate Revocation List) ื—ื™ื™ื‘ื™ื ืœื”ืืคืฉืจ ื‘ื“ื™ืงื” ืฉืœ ืชื•ืงืฃ ืชืขื•ื“ื•ืช ื‘ืขืช ื”ื—ืชื™ืžื”.

ื’ื™ืฉื” ื–ื• ืฉืœ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ื”ืžืœื ืžืฉืชืœื‘ืช ื‘ื’ื™ืฉื” ืจื—ื‘ื” ื™ื•ืชืจ ืฉืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืœืขืกืงื™ื ื”ืžื‘ืงืฉื™ื ืœืชืขืฉื™ื™ื” ืืช ืชื”ืœื™ื›ื™ื”ื ื”ืชื™ืขื•ื“ื™ื™ื ื‘ื”ืชืื.

ื”ืขืจื›ื” ื‘ื—ื™ืจื” ืฉืœ ืคืชืจื•ืŸ ืชื•ืื FedRAMP ื•-HDS

ืงืจื™ื˜ืจื™ื•ื ื™ื ื˜ื›ื ื™ื™ื ืฉืœ ื‘ื—ื™ืจื”

ืžื•ืœ ื”ืžื•ืจื›ื‘ื•ืช ืฉืœ ื”ืชืงืŸ ื”ื›ืคื•ืœ FedRAMP/HDS, ืงืจื™ื˜ืจื™ื•ื ื™ ื‘ื—ื™ืจื” ืฉืœ ืคืชืจื•ืŸ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืœืชื—ื•ื ื”ื‘ืจื™ืื•ืช ื—ื™ื™ื‘ื™ื ืœื”ืกืชื™ืจ ืžื™ืžื“ื™ื ืจื‘ื™ื:

ืชืฉืชื™ืช ื•ื—ืกื ื•ืŸ:

  • ื”ืกืžื›ื” HDS ืคืขื™ืœื”, ื‘ื“ื•ืงื” ื‘ื—ื–ืงื” PSCE ืฉืœ ANS;
  • ATO FedRAMP ืชื™ืขื•ื“ื” ืขืœ ื”bazaar marketplace.fedramp.gov ืจืฉืžื™;
  • ื”ืคืจื“ื” ืฉืœ environments UE/US ืขื ืžื“ื™ื ื™ื•ืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื ืชื•ืืžื•ืช ืœ-Data Privacy Framework (DPF);
  • SLA ืฉืœ ื–ืžื™ื ื•ืช โ‰ฅ 99,9% ืขื ื”ืชื—ื™ื™ื‘ื•ืช RTO < 4h ื•-RPO < 1h.

ื™ื›ื•ืœื•ืช ืฉืœ ืฆื™ื•ืช:

  • support native ืฉืœ ืจืžื•ืช AdES (XAdES, PAdES, CAdES) ืขื horodatage RFC 3161;
  • ืžื—ื‘ืจื™ื e-CPS ื•-PIV ืœืื™ืžื•ืช ืฉืœ ืžืงืฆื•ืขื•ืช ื‘ืจื™ืื•ืช;
  • API REST ืชื™ืขื•ื“ื” ืœืื™ื ื˜ื’ืจืฆื™ื” ื‘-SI ืฉืœ ื‘ืชื™ ื—ื•ืœื™ื (DMP, SIH, PACS);
  • ืœื•ื— ืžื—ื•ื•ื ื™ื ืฉืœ ืฆื™ื•ืช ืขื ื™ื™ืฆื•ื ืฉืœ ื“ื•ื—ื•ืช ื‘ื™ืงื•ืจืช ื‘ืชื‘ื ื™ืช ืชืงื ื™ืช.

ื™ื›ื•ืœื•ืช ื—ื•ื–ื™ื•ืช:

  • BAA HIPAA ื–ืžื™ืŸ ื‘ืชืงืŸ;
  • DPA (Data Processing Agreement) RGPD ืชื•ืื ืœืกืขื™ืฃ 28;
  • clause ื‘ื™ืงื•ืจืช ื”ืžืืคืฉืจืช ื‘ื“ื™ืงื•ืช ืขืฆืžืื™ื•ืช.

ืื™ื ื˜ื’ืจืฆื™ื” ื‘ืžืขืจื›ื•ืช ืžื™ื“ืข ืฉืœ ื‘ืจื™ืื•ืช

ืื™ื ื˜ื’ืจืฆื™ื” ืฉืœ ืคืชืจื•ืŸ ื—ืชื™ืžื” ื‘-SI ื‘ืจื™ืื•ืช ืžื•ืจื›ื‘ืช ื”ื™ื ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื’ื•ืจื ืžื’ื‘ื™ืœ ืœื”ืชืงื‘ื•ืœ. ื”ืžืžืฉืงื™ื HL7 FHIR (Fast Healthcare Interoperability Resources), ื›ืขืช ืชืงืŸ ื‘ืืจืฆื•ืช ื”ื‘ืจื™ืช ืชื—ืช ื“ื—ื™ืคื” ืฉืœ 21st Century Cures Act, ื•ืื™ื ื˜ื’ืจืฆื™ื•ืช DMP/Mon Espace Santรฉ ื‘ืฆืจืคืช, ืžื˜ื™ืœื•ืช ืžื’ื‘ืœื•ืช ืฉืœ interoperability ืฉืคืชืจื•ืŸ ื”ื—ืชื™ืžื” ื—ื™ื™ื‘ ืœื›ื‘ื“.

ืืจื’ื•ื ื™ื ืฉื›ื‘ืจ ืžืฆื•ื™ื“ื™ื ื‘ืคืชืจื•ื ื•ืช ืงื™ื™ืžื™ื (DocuSign, Adobe Sign) ื™ื›ื•ืœื™ื ืœื”ืคื™ืง ืชื•ืขืœืช ืž-ื”ื’ื™ืจื” ืœืคืชืจื•ืŸ ื”ืžื•ืชืื ื™ื•ืชืจ ืœื“ืจื™ืฉื•ืช HDS, ื”ืžืืคืฉืจืช ืฉื™ืžื•ืจ ืฉืœ ืืจื›ื™ื‘ื™ื ืชื™ืขื•ื“ื™ื™ื ื‘ื–ืžืŸ ืฉืžืฉื™ื’ื” ืฆื™ื•ืช ืจื’ื•ืœื˜ื•ืจื™ ื˜ื•ื‘ ื™ื•ืชืจ.

ื”-ืžื—ืฉื‘ื•ืŸ ROI ื–ืžื™ืŸ ื‘-Certyneo ืžืืคืฉืจ ืœื”ืขืจื™ืš ื‘ื“ื™ื•ืง ืืช ื”ื”ื—ื–ืจ ืขืœ ื”ืฉืงืขื” ืฉืœ ื”ื’ื™ืจื” ื›ื–ื•, ืขืœ ื™ื“ื™ ืฉื™ืœื•ื‘ ืฉืœ ืขืœื•ื™ื•ืช ืฉืœ ืฆื™ื•ืช, ืจื•ื•ื—ื™ื ืฉืœ ืคืจื•ื“ื•ืงื˜ื™ื‘ื™ื•ืช ื•ื™ืจื™ื“ื” ืฉืœ ืกื™ื›ื•ื ื™ ืžืฉืคื˜ื™.

ืžืกื’ืจืช ืžืฉืคื˜ื™ืช ื”ื—ืœื” ืขืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื‘ื‘ืจื™ืื•ืช: FedRAMP, HDS ื•-eIDAS

ื˜ืงืกื˜ื™ื ื™ืกื•ื“ ืื™ืจื•ืคืื™ื™ื

ื‘ื“ื™ืŸ ืฆืจืคืชื™ ื•ืื™ืจื•ืคืื™, ื”ืขืจืš ื”ืžืฉืคื˜ื™ ืฉืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื ืฉืขืŸ ืขืœ ืกืขื™ืฃ 1366 ืฉืœ Code civil, ื”ืงื•ื‘ืข ื›ื™ "ื”ื›ืชื‘ ื”ืืœืงื˜ืจื•ื ื™ ื‘ืขืœ ืื•ืชื• ื›ื•ื— ื”ื•ื›ื—ื” ื›ืžื• ื”ื›ืชื‘ ืขืœ ืชื•ืžืš ื ื™ื™ืจ, ื‘ื›ืคื•ืฃ ืœื›ืš ืฉื ื™ืชืŸ ืœื”ื–ื”ื•ืช ื›ืจืื•ื™ ืืช ื”ื’ื•ืคืŸ ืฉืžืžื ื• ื”ื•ื ื ื•ื‘ืข ื•ื›ื™ ื”ื•ื ื‘ื ื•ื™ ื•ื ืฉืžืจ ื‘ืชื ืื™ื ืฉื ื™ืชืŸ ืœื”ื‘ื˜ื™ื— ืืช ืฉืœืžื•ืชื•". ืกืขื™ืฃ 1367 ืฉืœ Code civil ืžืฉื“ืจื’ ื›ื™ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช "ืžื•ืจื›ื‘ืช ืžื”ืฉื™ืžื•ืฉ ื‘ืชื”ืœื™ืš ืžื”ื™ืžืŸ ืฉืœ ื”ื–ื”ื•ื™ ื”ืžื•ื‘ื˜ื— ืืช ื”ื–ื™ืงื” ืฉืœื• ืœืคืขื•ืœื” ืฉืืœื™ื” ื”ื™ื ืžืฆื•ืจืคืช".

ื‘ืจืžื” ืื™ืจื•ืคืื™ืช, ืชืงื ื•ืŸ (EU) ืžืก' 910/2014 eIDAS (Electronic Identification, Authentication and Trust Services) ืžืฉืžืฉ ื›ื‘ืกื™ืก ืฉืœ ื”ื”ื›ืจื” ื”ื”ื“ื“ื™ืช ืฉืœ ื—ืชื™ืžื•ืช ืืœืงื˜ืจื•ื ื™ื•ืช ื‘ื™ืŸ ืžื“ื™ื ื•ืช ื—ื‘ืจื•ืช. ื”ื™ื ืžื’ื“ื™ืจื” ืืช ืฉืœื•ืฉ ืจืžื•ืช ื”ื—ืชื™ืžื” (SES, AdES, QES) ื•ื™ื•ืฆืจืช ืืช ื”ืขื™ืงืจื•ืŸ ืฉื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืžื•ืกืžื›ืช "ื‘ืขืœืช ื”ืฉืคืขื” ืžืฉืคื˜ื™ืช ืฉืงื•ืœื” ืœืœื ืฉืœ ื—ืชื™ืžื” ื›ืชื•ื‘ื” ื‘ืขื“ื›ืŸ" (art. 25, ยง2). ืชืงื ื•ืŸ eIDAS 2.0 (ืชืงื ื•ืŸ (EU) 2024/1183), ืฉื ื›ื ืก ืœืชื•ืงืฃ ื‘ืžืื™ 2024, ืžืจื—ื™ื‘ ืืช ื”ืžืกื’ืจืช ื–ื• ืขื ื”ืฆื’ืช ื”-Portefeuille Europรฉen d'Identitรฉ Numรฉrique (EUDI Wallet), ื™ืฉื™ืจื•ืช ื—ืœ ืขืœ ืชื—ื•ื ื”ื‘ืจื™ืื•ืช ืœื”ื–ื”ื•ืช ื—ื•ืœื™ื ื•ืžืงืฆื•ืขื•ืช.

ืชืงื ื™ื ื˜ื›ื ื™ื™ื ืฉืœ ื”ืชื™ื™ื—ืกื•ืช ืžืคื•ืจืกืžื™ื ืขืœ ื™ื“ื™ ETSI: ETSI EN 319 101 (ืžื“ื™ื ื™ื•ืช ื›ืœืœื™ืช), ETSI EN 319 132 (XAdES), ETSI EN 319 122 (CAdES) ื•-ETSI EN 319 142 (PAdES). ืชืงื ื™ื ืืœื” ืžื’ื“ื™ืจื™ื ืคื•ืจืžื˜ื™ื ืฉืœ ื—ืชื™ืžื” ืœื˜ื•ื•ื— ืืจื•ืš (LTA โ€” Long Term Archive), ื—ื™ื•ื ื™ื™ื ืœื”ื‘ื˜ื—ืช ื‘ื“ื™ืงื•ืช ืฉืœ ื—ืชื™ืžื•ืช ืขืœ ืชืงื•ืคื•ืช ืฉืœ ืฉืžื™ืจื” ืฉืœ 10 ืขื“ 30 ืฉื ื™ื.

ื”ื’ื ื” ืฉืœ ื ืชื•ื ื™ ื‘ืจื™ืื•ืช: RGPD ื•ื—ื•ืง ืžื’ื–ืจื™

ืชืงื ื•ืŸ (EU) 2016/679 (RGPD) ืžืกื•ื•ื’ืช ื ืชื•ื ื™ ื‘ืจื™ืื•ืช ื›"ื ืชื•ื ื™ื ืื™ืฉื™ื™ื ื”ื ื•ื’ืขื™ื ืœื‘ืจื™ืื•ืช" ื”ืžื•ืคืขืœื™ื ื‘-ืงื˜ื’ื•ืจื™ื•ืช ืžื™ื•ื—ื“ื•ืช (art. 9), ืฉืขื™ื‘ื•ื“ื” ืืกื•ืจ ื‘ืขื™ืงืจื•ืŸ ืืœื ื—ืจื™ื’ ืžืคื•ืจืฉ (ื”ืกื›ืžื”, ื”ื›ืจื— ืœื˜ื™ืคื•ืœ, ืจื™ื‘ื™ืช ืฆื™ื‘ื•ืจื™ืช ื‘ืชื—ื•ื ื”ื‘ืจื™ืื•ืช ื”ืฆื™ื‘ื•ืจื™ืช). ื›ืœ ืคืชืจื•ืŸ ื—ืชื™ืžื” ื”ืžื˜ืคืœ ื‘ื ืชื•ื ื™ ื‘ืจื™ืื•ืช ื—ื™ื™ื‘ ืœืฆื™ื™ืช ืœืขื™ืงืจื•ื ื•ืช ืฉืœ ืฆืžืฆื•ื, ื”ื’ื‘ืœื” ืฉืœ ืžื˜ืจื•ืช ื•ืื‘ื˜ื—ื” (art. 5 ื•-32 RGPD), ื•ืžื™ื ื•ื™ sub-processor ื“ืจืš DPA ื‘ื”ืชืื ืœืกืขื™ืฃ 28.

ื‘ื“ื™ืŸ ืฆืจืคืชื™, ืกืขื™ืฃ L.1111-8 ืฉืœ Code de la santรฉ publique ื›ื•ืคื” ืืช ื”ืฉื™ืžื•ืฉ ื‘ืžืื—ืกืŸ ืžื•ืกืžืš HDS ืœื›ืœ ืื—ืกื•ืŸ ืฉืœ ื ืชื•ื ื™ ื‘ืจื™ืื•ืช ืฉืœ ืื•ืคื™ ืื™ืฉื™. ื”ืคืจื” ืฉืœ ื—ื•ื‘ื” ื–ื• ื—ื™ื™ื‘ืช ืœืขื•ื ืฉ ืคืœื™ืœื™ (ืกืขื™ืฃ L.1115-1 CSP).

ืžืกื’ืจืช ืืžืจื™ืงืื™ืช: HIPAA, FedRAMP ื•-ESIGN Act

ื‘ืืจืฆื•ืช ื”ื‘ืจื™ืช, HIPAA Security Rule (45 CFR Part 164) ื›ื•ืคื” ืขืจื‘ื•ื™ื•ืช ืฉืœ ื ื™ื”ื•ืœ, ืคื™ื–ื™ื•ืช ื•ื˜ื›ื ื™ื•ืช ืœื”ื’ื ืช ePHI (electronic Protected Health Information). ืกืคืงื™ ืฉืœ ืคืชืจื•ื ื•ืช ืขื ืŸ ื—ื™ื™ื‘ื™ื ืœื—ืชื•ื ืขืœ Business Associate Agreement (BAA) ื—ื•ื‘ื”.

FedRAMP Authorization Act (ืžืงื•ื“ื“ ื‘ืฉื ืช 2022, 44 U.S.C. ยง 3607) ื”ื•ืคืš ืืช ื”ืฆื™ื•ืช FedRAMP ืœื—ื•ื‘ื” ืœื›ืœ ืฉื™ืจื•ืช ืขื ืŸ ื”ืžืฉืžืฉ ืกื•ื›ื ื•ืช่”้‚ฆื™ืช. ื”ืคืจื” ืฉืœ ืฆื™ื•ืช ืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื”ืฉืžื˜ื” ืฉืœ ATO ื•ื—ืจื•ื’ ืžื”ืฉื•ืง่”้‚ฆื™. ESIGN Act (15 U.S.C. ยง 7001 et seq.) ืžื‘ื˜ื™ื— ืืช ืชื•ืงืฃ ื”ืžืฉืคื˜ื™ ืฉืœ ื—ืชื™ืžื•ืช ืืœืงื˜ืจื•ื ื™ื•ืช ื‘ืขืกืงืื•ืช ืžืกื—ืจื™ื•ืช ื•ืงืฆืจื•ืช, ืžื‘ืœื™ ืœื”ื˜ื™ืœ ืคื•ืจืžื˜ ื˜ื›ื ื™ ืืš ื‘ื›ืคื•ืฃ ืœืฆื™ื•ืช ืฉืœ ื“ืจื™ืฉื•ืช authentication.

ืœื‘ืกื•ืฃ, ื”ื ื—ื™ื” NIS2 (Directive (EU) 2022/2555), ืฉื”ื•ืขื‘ืจื” ืœื“ื™ืŸ ืฆืจืคืชื™ ืขืœ ื™ื“ื™ ื—ื•ืง ืžืกืคืจ 2023-703 ืž-1 ื‘ืื•ื’ื•ืกื˜ 2023, ืžืฉื“ืจื’ืช ืืช ื—ื•ื‘ื•ืช ื”ืกื™ื™ื‘ืจ ืœื™ืฉื•ื™ื•ืช ื—ื™ื•ื ื™ื•ืช, ืงื˜ื’ื•ืจื™ื” ืฉื‘ื” ืขื•ืœื™ื ื”ืจื•ื‘ ืฉืœ ื‘ืชื™ ื—ื•ืœื™ื ื‘ื’ื•ื“ืœ ืžืฉืžืขื•ืชื™. ื”ื™ื ื›ื•ืคื” ื”ื•ื“ืขืช ืชืงืœื” ืชื•ืš 24 ืฉืขื•ืช ืœืจืฉื•ื™ื•ืช ืžื•ืกืžื›ื•ืช (ANSSI ื‘ืฆืจืคืช) ื•ืžื›ื ื™ืกื” ืื—ืจื™ื•ืช ืฉืœ ืžื ื”ืœื™ื ื‘ืžืงืจื” ืฉืœ ื”ืคืจื”.

ืชืจื—ื™ืฉื™ ืฉื™ืžื•ืฉ: FedRAMP, HDS ื•ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ื‘ื‘ืจื™ืื•ืช

ืชืจื—ื™ืฉ 1: ืงื‘ื•ืฆืช ื‘ืชื™ ื—ื•ืœื™ื ืื•ื ื™ื‘ืจืกื™ื˜ืื™ืช ื ื™ื”ื•ืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉืœ ืžื—ืงืจ ืงืœื™ื ื™ transatlantiques

ืงื‘ื•ืฆืช ื‘ืชื™ ื—ื•ืœื™ื ืฉืœ ื›-1,200 ืžื˜ื•ืช, ืฉื•ืชืฃ ืฉืœ ืกื•ื›ื ื”่”้‚ฆื™ืช ืืžืจื™ืงืื™ืช ืฉืœ ืžื—ืงืจ ืจืคื•ืื™ (ืกื•ื’ ืฉืœ ืชืงืŸ NIH-affiliated), ืžื ื”ืœืช ื‘ื“ื™ืงื•ืช ืงืœื™ื ื™ื•ืช ืฉืœ ืฉืœื‘ III ื”ื›ื•ืœืœื•ืช ืžืจื›ื–ื™ื ื‘ื—ื•ืงืจื™ื ื‘ืฆืจืคืช ื•ื‘ืืจืฆื•ืช ื”ื‘ืจื™ืช. ื›ืœ ื”ื›ืœืœืช ื—ื•ืœื” ื“ื•ืจืฉืช ื”ืกื›ืžื” ืžื•ื“ืขืช ื—ืชื•ืžื” ืืœืงื˜ืจื•ื ื™ืช, ืžื•ืจื—ืงืช ืœืžืฉืš 15 ืฉื ื™ื ื‘ื”ืชืื ืœื“ืจื™ืฉื•ืช ICH E6(R2) ืฉืœ Bonnes Pratiques Cliniques.

ืœืคื ื™ ื”ืงืžืช ืคืชืจื•ืŸ ืชื•ืื FedRAMP/HDS, ื”ืชื”ืœื™ืš ื”ืกืชืžืš ืขืœ ื—ืชื™ืžื•ืช ื ื™ื™ืจ ืžืžื•ื›ื ื•ืช, ื™ื•ืฆืจ ืขื™ื›ื•ื‘ื™ื ืžืžื•ืฆืขื™ื ืฉืœ 4 ืขื“ 7 ื™ืžื™ื ืขืกืงื™ื™ื ืœืชื™ืงื™ื™ืช ื”ื›ืœืœื” ื•ืงืฆื‘ ืฉื’ื™ืื” ืชื™ืขื•ื“ื™ ืฉืœ 12% (ื˜ืคืกื™ื ืœื ืžืœืื™ื, ื—ืชื™ืžื•ืช ื—ืกืจื•ืช). ืœืื—ืจ ืคืจื™ืกื” ืฉืœ ืคืชืจื•ืŸ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืžืชืงื“ื, ืžื—ื•ื‘ืจืช ืœืชืฉืชื™ืช ืžื•ืกืžื›ืช HDS ื‘ืื™ืจื•ืคื” ื•ืงื‘ืข ATO FedRAMP Moderate ืœืขืœ ืžืจื›ื–ื™ื ืืžืจื™ืงืื™ื™ื:

  • ืฆืžืฆื•ื ืฉืœ ืขื™ื›ื•ื‘ ื”ื›ืœืœื” ืž-4-7 ื™ืžื™ื ืœืคื—ื•ืช ืž-24 ืฉืขื•ืช (ื–ื›ื™ื™ื” ืฉืœ 80 ืขื“ 85%);
  • ืงืฆื‘ ืฉื’ื™ืื” ืชื™ืขื•ื“ื™ ืžื•ืคื—ืช ืœืคื—ื•ืช ืž-1% ื”ื•ื“ื•ืช ืœื–ืจื™ืžื•ืช ืขื‘ื•ื“ื” ืฉืœ validation ืžืขื•ื›ื•ืช;
  • ืฆื™ื•ืช ื‘ื™ืงื•ืจืช: 100% ืฉืœ ื”ืกื›ืžื•ืช ืžื•ืจื—ืงื•ืช ืขื horodatage RFC 3161 ื•-proof ืฉืœ ื—ืชื™ืžื” ื™ื™ืฆื•ื ื‘ื”ื ืงืœื” ืฉืœ 1 ืœื—ื™ืฆื” ืœื‘ื™ืงื•ืจื™ื ืจื’ื•ืœื˜ื•ืจื™ื™ื FDA/ANSM.

ืชืจื—ื™ืฉ 2: ืขื•ืจืš ืฉืœ logiciel ืจืคื•ืื™ ืžืืฉืจืช ืืช ื”ืคืชืจื•ืŸ ืฉืœื• ื‘ืงืจื‘ ืกื•ื›ื ื•ื™ื•ืช่”้‚ฆื™ื•ืช US

PME ืฆืจืคืชื™ืช ืžืชืžื—ื” ื‘ืชื•ื›ื ื” ืฉืœ ื ื™ื”ื•ืœ ืฉืœ ืชื™ืงื™ื•ืช ืจืคื•ืื™ื•ืช ืืœืงื˜ืจื•ื ื™ื•ืช ืžืขื•ื ื™ื™ื ืช ืœื”ื—ืœื™ืง ืืช ืคืชืจื•ืŸ ืฉืœื” ื‘ืงืจื‘ ื‘ืชื™ ื—ื•ืœื™ื ืฉืœ Veterans Affairs (VA) ืืžืจื™ืงืื™ื™ื. ื”ื’ื™ืฉื” ืœืฉื•ืง ื–ื”่”้‚ฆื™ ื“ื•ืจืฉืช ATO FedRAMP High, ื‘ื™ื“ืข ืฉื”ืคืชืจื•ืŸ ืžืฉืœื‘ ืžื•ื“ื•ืœ ืฉืœ ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช ืœืžืจืฉืžื•ืช ื•ื›ืœืœ

ื ืกื• Certyneo ื‘ื—ื™ื ื

ืฉืœื—ื• ืืช ืžืขื˜ืคืช ื”ื—ืชื™ืžื” ื”ืจืืฉื•ื ื” ืฉืœื›ื ื‘ืคื—ื•ืช ืž-5 ื“ืงื•ืช. 5 ืžืขื˜ืคื•ืช ื—ื™ื ื ื‘ื—ื•ื“ืฉ, ืœืœื ื›ืจื˜ื™ืก ืืฉืจืื™.

ื”ืขืžืงืช ื”ื ื•ืฉื

ื”ืžื“ืจื™ื›ื™ื ื”ืžืœืื™ื ืฉืœื ื• ืœืฉืœื™ื˜ื” ื‘ื—ืชื™ืžื” ืืœืงื˜ืจื•ื ื™ืช.

ื”ืขืžื™ืงื• ืืช ื”ื™ื“ืข ืฉืœื›ื ืขื ืžืืžืจื™ื ืืœื” ื”ืงืฉื•ืจื™ื ืœื ื•ืฉื.

ืื™ืžื•ืช ื”ืกืžื›ื•ืช ืฉืœ ืžืกืžืš ื—ืชื•ื: ื”-DUER

ื”ืขืจืš ื”ืžืฉืคื˜ื™ ืฉืœ ืžืกืžืš ื”ื”ืขืจื›ื” ื”ื™ื™ื—ื•ื“ื™ ืฉืœืš ืขื‘ื•ืจ ืกื™ื›ื•ื ื™ื ืชืœื•ื™ ื™ืฉื™ืจื•ืช ื‘ืกืžื›ื•ืช ื”ื—ืชื™ืžื” ืฉืœื•. ื’ืœื” ืืช ื”ืฉื™ื˜ื•ืช ื”ืงื•ื ืงืจื˜ื™ื•ืช ืœืื™ืžื•ืช ื–ื”.

8 min

ื‘ื“ื™ืงืช ื–ื”ื•ืช ืื•ืชื ื˜ื™ื•ืช ืฉืœ ืžืกืžืš ื—ืชื•ื ื‘ืชืงืฉื•ืจืช

ื‘ืชื—ื•ื ื”ืชืงืฉื•ืจืช, ืชื•ืงืคื• ืฉืœ ื—ื•ื–ื” ื”ื—ืชื•ื ื‘ืฆื•ืจื” ืืœืงื˜ืจื•ื ื™ืช ื›ืจื•ืš ื‘ืกื›ื ื•ืช ืคื™ื ื ืกื™ื•ืช ื•ื›ืœืœ-ืจื’ื•ืœื˜ื•ืจื™ื•ืช ืžืฉืžืขื•ืชื™ื•ืช. ื’ืœื” ืืช ื”ืฉื™ื˜ื•ืช ื”ืžืขืฉื™ื•ืช ืœื‘ื“ื™ืงืช ื–ื”ื•ืช ืื•ืชื ื˜ื™ื•ืช ืฉืœ ืžืกืžืš ื—ืชื•ื ื•ืœื”ื‘ื˜ื—ืช ืื‘ื˜ื—ืช ื–ืจื™ืžื•ืช ื”ืžืกืžื›ื™ื ืฉืœืš.

8 min

Webhooks Certyneo : automatiser le bilan comptable en ERP

Webhooks Certyneo ืžืืคืฉืจื™ื ืœื—ื‘ืจ ืืช ืคืชืจื•ืŸ ื”ื—ืชื™ืžื” ื”ืืœืงื˜ืจื•ื ื™ืช ืฉืœืš ืœ-ERP ืื• ืœื—ืฉื‘ื•ืŸ ืฉืœืš ื‘ื–ืžืŸ ืืžืช. ื’ืœื” ื›ื™ืฆื“ ืœื”ืคืขื™ืœ ืื•ื˜ื•ืžืฆื™ื” ืœืื™ืกื•ืฃ ืžืกืžื›ื™ื ื—ืชื•ืžื™ื ื‘ื–ืจื™ืžืช ื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš.

8 min