SAP SuccessFactors: ISMAP 2024 Renewal Certificate
01/05/25, 09:44ISMAP Cloud Service List Details - ISMAP Portal
Page 1 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=de3c20dd2b78aa50f0bbfd69fe91bf6b
Cloud service list details
Registration number C23-0059-2
Name of cloud service SAP Success Factors
The URL of the cloud service's
homepage
Https://www.sap.com/japan/products/hcm.html
Name of the cloud service
provider
SAP SE
Corporate number
Location of the cloud service
operator
Dietmar-Hopp-Allee 16, D-69190 Walldorf, Germany.
Date of registration 12/25/2023
Registration expiration date 01/31/2026
Scope of the statement SAP SuccessFactors_Spe of Coverage.pdf
Management measures for
control targets implemented
among the basic statement
requirements
SAP SuccessFactors_Management measures for control targets implemented
among the basic statement requirements.pdf
Audit period 2023/10/01 to 2024/09/30
late event No applicable matters
Availability of an improvement
plan
None
Information on the applicant's
capital relationship and officers
at the time of application
SAP SuccessFactors_Information on capital relations and executives, etc.pdf
Information necessary for risk
assessment
SAP SuccessFactors_About the provision of information specified in the ISMAP
Cloud Service Registration Rules 3.4(2).pdf
Information on the governing SAP SuccessFactors_Information on applicable law and jurisdiction.pdf
*1
*2
※3
※4
Page 1 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=de3c20dd2b78aa50f0bbfd69fe91bf6b
Cloud service list details
Registration number C23-0059-2
Name of cloud service SAP Success Factors
The URL of the cloud service's
homepage
Https://www.sap.com/japan/products/hcm.html
Name of the cloud service
provider
SAP SE
Corporate number
Location of the cloud service
operator
Dietmar-Hopp-Allee 16, D-69190 Walldorf, Germany.
Date of registration 12/25/2023
Registration expiration date 01/31/2026
Scope of the statement SAP SuccessFactors_Spe of Coverage.pdf
Management measures for
control targets implemented
among the basic statement
requirements
SAP SuccessFactors_Management measures for control targets implemented
among the basic statement requirements.pdf
Audit period 2023/10/01 to 2024/09/30
late event No applicable matters
Availability of an improvement
plan
None
Information on the applicant's
capital relationship and officers
at the time of application
SAP SuccessFactors_Information on capital relations and executives, etc.pdf
Information necessary for risk
assessment
SAP SuccessFactors_About the provision of information specified in the ISMAP
Cloud Service Registration Rules 3.4(2).pdf
Information on the governing SAP SuccessFactors_Information on applicable law and jurisdiction.pdf
*1
*2
※3
※4
01/05/25, 09:44ISMAP Cloud Service List Details - ISMAP Portal
Page 2 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=de3c20dd2b78aa50f0bbfd69fe91bf6b
law and jurisdiction stipulated in
the contract
Information on the
implementation status and
acceptance of third-party tests
such as penetration tests and
vulnerability diagnosis
SAP SuccessFactors_ISMAP Cloud Service Registration Rules 3.4(4) Provision of
information.pdf
Special notes on cloud service
registration
Remarks 2025/04/28 Change the expiration date of registration, audit period, scope of
statement, information, etc.
※1 In principle, all management measures as control goals must be implemented, but cloud service providers
are not eligible for management measures as control goals that cannot be reasonably applied in light of the
services they provide. You can do it.
In addition, the management measures as control goals that are excluded are slashed.
※2 If the audit is carried out only based on the maintenance status evaluation, the audit reference date is listed.
※3 If there are minor findings in the management measure standard in the implementation result report, and
an improvement plan indicating that the control related to the findings will be improved within 2 months
from the date of the implementation result report has been submitted by the cloud service provider, " It is
described as "yes".
※4 The information necessary for risk assessment is stipulated in ISMAP Cloud Service Registration Rule 3.4(2),
"Laws and regulations other than domestic laws apply to information handled by cloud services, and
procurement is unintended by procurement ministries, etc. It refers to the information necessary for the
system management committee and the ministry, etc. to conduct a risk assessment regarding the risk of
accessing or processing information managed by the government ministry, etc.
(Note)When utilizing the ISMAP cloud service list, please refer to "Notes on Generated AI Services" for handling
when the registered service includes a generated AI service. In addition, information about the generated AI
will be posted in the "Scope of the statement" or "Special notes related to the registration of cloud services".
Page 2 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=de3c20dd2b78aa50f0bbfd69fe91bf6b
law and jurisdiction stipulated in
the contract
Information on the
implementation status and
acceptance of third-party tests
such as penetration tests and
vulnerability diagnosis
SAP SuccessFactors_ISMAP Cloud Service Registration Rules 3.4(4) Provision of
information.pdf
Special notes on cloud service
registration
Remarks 2025/04/28 Change the expiration date of registration, audit period, scope of
statement, information, etc.
※1 In principle, all management measures as control goals must be implemented, but cloud service providers
are not eligible for management measures as control goals that cannot be reasonably applied in light of the
services they provide. You can do it.
In addition, the management measures as control goals that are excluded are slashed.
※2 If the audit is carried out only based on the maintenance status evaluation, the audit reference date is listed.
※3 If there are minor findings in the management measure standard in the implementation result report, and
an improvement plan indicating that the control related to the findings will be improved within 2 months
from the date of the implementation result report has been submitted by the cloud service provider, " It is
described as "yes".
※4 The information necessary for risk assessment is stipulated in ISMAP Cloud Service Registration Rule 3.4(2),
"Laws and regulations other than domestic laws apply to information handled by cloud services, and
procurement is unintended by procurement ministries, etc. It refers to the information necessary for the
system management committee and the ministry, etc. to conduct a risk assessment regarding the risk of
accessing or processing information managed by the government ministry, etc.
(Note)When utilizing the ISMAP cloud service list, please refer to "Notes on Generated AI Services" for handling
when the registered service includes a generated AI service. In addition, information about the generated AI
will be posted in the "Scope of the statement" or "Special notes related to the registration of cloud services".