ApsaraDB RDS for PostgreSQL security and compliance certifications

Updated at:

This topic describes the security and compliance certifications for ApsaraDB RDS for PostgreSQL and provides links to download the compliance documents.

ApsaraDB RDS for PostgreSQL is committed to the highest internal and external standards for product quality, technical service, stability, security, and compliance. The service is regularly assessed and validated by authoritative third-party organizations. These certifications help customers and organizations efficiently meet regional and industry-specific security and compliance requirements.

Certification

Description

ISO 20000 IT Service Management System

Defines the requirements for the development, implementation, monitoring, maintenance, and improvement of an IT service management system, covering service level management, incident and problem management, change management, availability management, relationship management, configuration and release management, and more. Alibaba Cloud obtains this certification to ensure that the technical services and support provided can meet business needs, and to improve service quality, customer satisfaction, and operational efficiency through standardized processes.

ISO 9001 Quality Management System

The core principle is customer-centricity, emphasizing the identification, management, and optimization of key business processes to improve efficiency and effectiveness. It covers the planning, implementation, monitoring, correction, and improvement of the entire process from requirement confirmation, design, R&D, testing, sales to pre-delivery. Alibaba Cloud obtains this certification to establish systematic and standardized product and service quality management processes and a continuous improvement approach, and to ensure that the full lifecycle management of products meets requirements, reduce defects and errors, and improve customer satisfaction.

ISO 27001 Information Security Management System

One of the internationally widely recognized general information security management frameworks, helping enterprises design and implement a management system and controls covering security organization, personnel security, physical security, and security technology. Alibaba Cloud obtains this certification to effectively manage physical security, network security, application security, data security, and supply chain security risks, protect information assets, and improve business security and compliance.

ISO 22301 Business Continuity Management System

Provides a management framework for establishing, implementing, maintaining, and continuously improving a business continuity management system to respond to disruption events and ensure that critical business functions can be quickly restored during a crisis. Alibaba Cloud obtains this certification to use a systematic approach to identify potential threats, formulate prevention and response measures, and improve plans for technical failures, cyber attacks, or other events, so as to quickly restore critical business capabilities during emergencies and fulfill its responsibilities to customers and stakeholders through effective business continuity management.

ISO 27017 Cloud Security Management System

Provides a systematic framework for the security management of cloud services. Based on ISO/IEC 27001 information security management system and ISO/IEC 27002 information security control practice guidelines, it provides additional controls and guidance for cloud service providers and cloud service users. Alibaba Cloud obtains this certification to enhance controls specific to cloud environments, such as virtual machine security, data isolation, and data protection after cloud service termination, and to effectively manage information security risks in cloud environments.

CSA STAR Cloud Security Management System

CSA STAR is a global cloud security certification and assessment program launched by the Cloud Security Alliance. It combines the ISO/IEC 27001 information security management system standard and the CSA Cloud Controls Matrix to provide a transparent and trusted cloud security assessment framework for cloud service providers and users. Alibaba Cloud obtains this certification to assess, improve, and certify the security and compliance of cloud products and services from multiple domains such as infrastructure security, network security, application security, data security, privacy protection, compliance, and risk management.

ISO 27701 Privacy Information Management System

ISO 27701 is a privacy extension to ISO 27001 information security management and ISO 27002 security controls. It integrates privacy protection principles, concepts, and methods into the information security protection system, covering privacy risk management, data subject rights protection, sharing and transmission, privacy by design, transparency requirements, incident response, and handling. Alibaba Cloud obtains this certification to establish, implement, maintain, and continuously improve the privacy security management system and controls, and continuously enhance the compliance of privacy information processing.

ISO 27018 Public Cloud Personal Information Protection Management System

This standard is specifically aimed at the privacy protection requirements for cloud service providers (CSPs) when processing personally identifiable information (PII), enhancing data security and customer trust in public cloud environments. Based on the ISO 27002 information security control practice guidelines, Alibaba Cloud implements a set of additional personal information protection controls, emphasizing minimum necessity, user control rights, and data subject consent, and strictly adheres to privacy protection principles when processing customer PII.

BS 10012 Personal Information Management System

Provides a best-practice framework for personal information management systems that references the principles of the EU GDPR, and is an important tool for achieving privacy protection goals. It helps organizations implement compliant and reliable management measures throughout the full lifecycle of personal information collection, storage, processing, sharing, and destruction. Alibaba Cloud obtains this certification to establish a standardized management system and reduce the risks of data leakage and misuse, thereby enhancing privacy management, customer trust, and meeting compliance requirements.

ISO 37301 Compliance Management System

This is a certification standard for compliance management systems. By identifying and assessing compliance risks, it establishes, implements, maintains, and improves the compliance management system and processes to ensure that the organization complies with applicable laws, regulations, industry standards, and internal policies during operations. Alibaba Cloud obtains this certification to improve the efficiency and transparency of internal compliance management, foster a compliance culture, and strengthen compliance awareness and engagement among internal and external stakeholders.

PCI DSS V4.0

PCI DSS (Payment Card Industry Data Security Standard) is developed and maintained by the PCI SSC (Payment Card Industry Security Standards Council). It provides a unified baseline and specific control for the technical and operational requirements for protecting account data, including security management systems, network security, physical security, and data encryption. As a cloud service provider, Alibaba Cloud proactively practices industry standards, actively assumes the security responsibilities of the cloud platform side in the data environment, and helps customers build a secure cloud data environment through cloud products and services.

Classified cybersecurity protection Level 3 - Public cloud data and development service platform (PaaS)

The state implements a classified cybersecurity protection system. Network operators shall fulfill security protection obligations in accordance with the requirements of the classified cybersecurity protection system, ensure that networks are free from interference, damage, or unauthorized access, and prevent network data leakage, theft, or tampering. Adhering to the principles of focusing on key points, active defense, and comprehensive prevention and control, Alibaba Cloud establishes and improves the network security protection system. Every year, third-party authorities assess the classified cybersecurity protection of Alibaba Cloud public cloud data and development service platform (PaaS), carry out security construction and rectification, implement security responsibilities, and meet national network security protection requirements.

Trusted Cloud - Cloud service user data protection capability assessment

Trusted Cloud assessment is a professional assessment system for cloud computing services and software in China, organized and implemented by the China Academy of Information and Communications Technology (CAICT). Its core goal is to establish an assessment system for cloud service providers, helps users choose secure and trusted cloud service providers, and improve service quality and integrity. Alibaba Cloud has passed the cloud service user data protection capability verification, meeting assessment requirements for data persistence, data confidentiality, data migration security, intrusion prevention, and service auditability across the three stages of pre-event prevention, in-event protection, and post-event traceability.

Trusted Cloud - Cloud computing shared security responsibility capability assessment

Trusted Cloud assessment is a professional assessment system for cloud computing services and software in China, organized and implemented by the China Academy of Information and Communications Technology (CAICT). Alibaba Cloud has passed the cloud computing shared security responsibility capability verification, meeting the assessment dimensions of responsibility allocation model, security capability support, and service agreement transparency based on the Cloud Computing Shared Security Responsibility Capability Requirements standard.

SOC reports

SOC (System and Organization Controls) reports are a series of audit standards established by the American Institute of Certified Public Accountants (AICPA), aimed at evaluating the effectiveness of controls at service organizations (such as cloud service providers, data centers, and IT service companies). Alibaba Cloud SOC reports are independent audit reports issued by independent third-party auditors, detailing the effectiveness of Alibaba Cloud's internal control mechanisms to customers and their auditors. SOC reports are divided into three types:

  1. SOC 1 report: This report focuses on internal controls related to financial reporting, usually issued as Type II, evaluating the effectiveness of controls over a specific period.

  2. SOC 2 report: This report evaluates controls related to system security, availability, and confidentiality, usually issued as Type II, evaluating the effectiveness of controls over a specific period.

  3. SOC 3 report: This report is a simplified version of the SOC 2 report, suitable for public release, aiming to convey the effectiveness of controls without including sensitive information.