SAP SuccessFactors: ISMAP 2024 Renewal Certificate

The Information systems supporting SAP SuccessFactors (SFSF) have been audited and found to comply with the requirements of the Information system Security Management and Assessment Program (ISMAP), which is the Japanese Government’s Security Assessment System for Government Information Systems.Link to certificate page: https://www.ismap.go.jp/csm?id=cloud_service_list Download the Document

01/05/25, 09:44ISMAP Cloud Service List Details - ISMAP PortalPage 1 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=de3c20dd2b78aa50f0bbfd69fe91bf6bCloud service list detailsRegistration number C23-0059-2Name of cloud service SAP Success FactorsThe URL of the cloud service'shomepageHttps://www.sap.com/japan/products/hcm.htmlName of the cloud serviceproviderSAP SECorporate numberLocation of the cloud serviceoperatorDietmar-Hopp-Allee 16, D-69190 Walldorf, Germany.Date of registration 12/25/2023Registration expiration date 01/31/2026Scope of the statement SAP SuccessFactors_Spe of Coverage.pdfManagement measures forcontrol targets implementedamong the basic statementrequirementsSAP SuccessFactors_Management measures for control targets implementedamong the basic statement requirements.pdfAudit period 2023/10/01 to 2024/09/30late event No applicable mattersAvailability of an improvementplanNoneInformation on the applicant'scapital relationship and officersat the time of applicationSAP SuccessFactors_Information on capital relations and executives, etc.pdfInformation necessary for riskassessmentSAP SuccessFactors_About the provision of information specified in the ISMAPCloud Service Registration Rules 3.4(2).pdfInformation on the governing SAP SuccessFactors_Information on applicable law and jurisdiction.pdf*1*234
01/05/25, 09:44ISMAP Cloud Service List Details - ISMAP PortalPage 2 of 2https://www.ismap.go.jp/csm?id=cloud_service_list_detail&sys_id=de3c20dd2b78aa50f0bbfd69fe91bf6blaw and jurisdiction stipulated inthe contractInformation on theimplementation status andacceptance of third-party testssuch as penetration tests andvulnerability diagnosisSAP SuccessFactors_ISMAP Cloud Service Registration Rules 3.4(4) Provision ofinformation.pdfSpecial notes on cloud serviceregistrationRemarks 2025/04/28 Change the expiration date of registration, audit period, scope ofstatement, information, etc.1 In principle, all management measures as control goals must be implemented, but cloud service providersare not eligible for management measures as control goals that cannot be reasonably applied in light of theservices they provide. You can do it.In addition, the management measures as control goals that are excluded are slashed.2 If the audit is carried out only based on the maintenance status evaluation, the audit reference date is listed.3 If there are minor findings in the management measure standard in the implementation result report, andan improvement plan indicating that the control related to the findings will be improved within 2 monthsfrom the date of the implementation result report has been submitted by the cloud service provider, " It isdescribed as "yes".4 The information necessary for risk assessment is stipulated in ISMAP Cloud Service Registration Rule 3.4(2),"Laws and regulations other than domestic laws apply to information handled by cloud services, andprocurement is unintended by procurement ministries, etc. It refers to the information necessary for thesystem management committee and the ministry, etc. to conduct a risk assessment regarding the risk ofaccessing or processing information managed by the government ministry, etc.(Note)When utilizing the ISMAP cloud service list, please refer to "Notes on Generated AI Services" for handlingwhen the registered service includes a generated AI service. In addition, information about the generated AIwill be posted in the "Scope of the statement" or "Special notes related to the registration of cloud services".