This topic describes the security and compliance certifications for ApsaraDB RDS for PostgreSQL and provides links to download the compliance documents.
ApsaraDB RDS for PostgreSQL is committed to the highest internal and external standards for product quality, technical service, stability, security, and compliance. The service is regularly assessed and validated by authoritative third-party organizations. These certifications help customers and organizations efficiently meet regional and industry-specific security and compliance requirements.
Certification | Description |
Alibaba Cloud uses this certification to implement standardized processes that ensure its technical services meet business needs, improve service quality and operational efficiency, and increase customer satisfaction. | |
Alibaba Cloud leverages this certification to establish systematic and standardized quality management processes for its products and services. These processes foster continuous improvement, ensure product lifecycle management meets all requirements, reduce defects, and enhance customer satisfaction. | |
As one of the most widely recognized international frameworks for information security management, this standard helps organizations design and implement a management system and control measures covering security organization, personnel security, physical security, and security technology. Alibaba Cloud uses this certification to effectively manage risks across physical, network, application, data, and supply chain security. This protects information assets and enhances business security and compliance. | |
This standard provides a management framework for establishing, implementing, maintaining, and continuously improving a business continuity management system to respond to disruptive incidents and ensure the rapid recovery of critical business functions. Alibaba Cloud applies this certification to systematically identify potential threats, develop preventive and response measures, and refine plans for handling technical failures, cyberattacks, or other events. This ensures the swift recovery of critical business functions during emergencies, demonstrating its commitment to customers and stakeholders. | |
This standard provides a systematic framework for the security management of cloud services. Based on the ISO/IEC 27001 information security management system and ISO/IEC 27002 code of practice for information security controls, it offers additional controls and guidance for both cloud service providers (CSPs) and customers. Alibaba Cloud uses this certification to enhance controls specific to cloud environments, such as virtual machine security, data isolation, and data protection after service termination. These enhancements ensure the effective management of information security risks in the cloud. | |
CSA STAR is a global cloud security certification and assessment program from the Cloud Security Alliance (CSA). It combines the ISO/IEC 27001 standard with the CSA's Cloud Controls Matrix (CCM) to provide a transparent and trusted security assessment framework for cloud service providers and customers. Alibaba Cloud uses this certification to assess, improve, and certify the security and compliance of its cloud products and services across multiple domains, including infrastructure, network, application, and data security, as well as privacy protection, compliance, and risk management. | |
ISO 27701 is a privacy extension to ISO 27001 for information security management and ISO 27002 for security controls. It integrates privacy protection principles and methodologies into the information security framework, covering requirements for privacy risk management, data subject rights, data sharing and transfer, privacy by design, transparency, and incident response. Alibaba Cloud leverages this certification to establish, implement, maintain, and continuously improve its privacy information management system and controls. This enhances compliance when processing private information. | |
This standard specifically addresses the privacy protection requirements for a cloud service provider (CSP) when processing personally identifiable information (PII). This enhances data security and customer trust in public cloud environments. Building on the ISO 27002 code of practice, Alibaba Cloud implements an additional set of controls for protecting personal information. These controls emphasize principles such as data minimization, user control, and data subject consent to ensure strict adherence to privacy protection principles when processing customer PII. | |
This standard provides a best-practice framework for a personal information management system, referencing the principles of the EU GDPR. It is a key tool for achieving privacy protection goals, helping organizations implement compliant and reliable management measures throughout the entire lifecycle of personal information, including collection, storage, processing, sharing, and disposal. This certification helps Alibaba Cloud establish a standardized management system that reduces data breach and misuse risks, improves privacy management, enhances customer trust, and meets compliance requirements. | |
This is a certification standard for compliance management systems. It helps ensure an organization's operations adhere to applicable laws, regulations, industry standards, and internal policies by identifying and assessing compliance risks, and by establishing, implementing, maintaining, and improving compliance management processes. Alibaba Cloud uses this certification to increase the efficiency and transparency of its internal compliance management, foster a culture of compliance, and better engage internal and external stakeholders. | |
The Payment Card Industry Data Security Standard (PCI DSS) is developed and maintained by the PCI Security Standards Council (PCI SSC). It provides a unified baseline and specific control requirements for protecting account data, covering areas such as security management, network security, physical security, and data encryption. As a cloud service provider, Alibaba Cloud proactively adheres to this standard, fulfills its security responsibilities for the cloud platform, and helps customers build secure data environments in the cloud with its products and services. | |
China implements the Multi-Level Protection Scheme (MLPS). Under this system, network operators must fulfill security protection obligations to safeguard networks from interference, sabotage, or unauthorized access, and to prevent data breaches, theft, or tampering. Adhering to the principles of proactive and comprehensive defense on key systems, Alibaba Cloud has established a robust network security framework. The Alibaba Cloud public cloud data and development service platform (PaaS) undergoes an annual MLPS assessment by a third-party authority. This process involves continuous security enhancements and improvements to meet its responsibilities and satisfy national cybersecurity protection requirements. | |
Trusted Cloud - Verification of cloud service user data protection capability | The Trusted Cloud assessment is a professional evaluation system for cloud computing services and software in China, organized by the China Academy of Information and Communications Technology (CAICT). Its core objectives are to establish an evaluation system for cloud service providers, help users select secure and trustworthy cloud services, and improve service quality and integrity. Alibaba Cloud has passed the verification for cloud service user data protection capability, meeting assessment requirements across the three stages of pre-incident prevention, in-incident protection, and post-event traceability. These requirements cover data durability, data privacy, data migration security, intrusion prevention, and service auditability. |
Trusted Cloud - Verification of cloud computing security shared responsibility capability | The Trusted Cloud assessment is a professional evaluation system for cloud computing services and software in China, organized by the China Academy of Information and Communications Technology (CAICT). Alibaba Cloud has passed the verification for cloud computing security shared responsibility capability. This verification is based on the "Requirements for Cloud Computing Security Shared Responsibility Capability" standard and assesses dimensions including the responsibility assignment model, security capability support, and service agreement transparency. |
System and Organization Controls (SOC) reports are a series of auditing standards developed by the American Institute of Certified Public Accountants (AICPA). They are designed to assess the effectiveness of control measures at service organizations such as cloud service providers, data centers, and IT service companies. Alibaba Cloud SOC reports are independent audit reports issued by third-party auditors. They provide customers and their auditors with detailed information about the effectiveness of Alibaba Cloud's internal control mechanisms. There are three types of SOC reports:
|