ISO/IEC 42001:2023 箇条 7.5.3
文書化した情報の管理
Control of documented information
要求事項
支援
規格の記載(原文と日本語訳)
Clause 7.5.3
Documented information required by the AI management system and by this document shall be controlled to ensure: a) it is available and suitable for use, where and when it is needed; b) it is adequately protected (e.g. from loss of confidentiality, improper use or loss of integrity).
日本語訳AIマネジメントシステム及びこの規格で要求されている文書化した情報は、次の事項を確実にするために、管理しなければならない。a) 文書化した情報が、必要なときに、必要なところで、入手可能かつ利用に適した状態である。b) 文書化した情報が十分に保護されている(例えば、機密性の喪失、不適切な使用及び完全性の喪失からの保護)。
原文は参考サイト(WatchDog Security GRC Wiki / Control Stack)に引用掲載されたものです。日本語訳は本サイトによる非公式訳です。
わかりやすく言うと
文書・記録を、必要な人が必要なときに使え、かつ改ざん・漏えいから守られた状態で管理します。
- 文書管理システムでアクセス権・版管理・保管期間を設定する
- 最新版が利用されているか
- 旧版が誤用されない仕組みがあるか
- 文書管理規程
- アクセス権設定