aimeos / aimeos/pagible

Make PagibleAI suitable for regulated industries

未关闭
#267 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
PHP
星标
586
派生
14
平均合并
4 小时 57 分钟
30 天内合并 PR
19

描述

## United States

- HIPAA Security Rule — Systems handling ePHI must enforce access controls, uniquely identify users, protect data integrity, and record and examine system activity. Required security documentation must generally be retained for six years. 45 CFR §§164.312 and 164.316 (https://www.ecfr.gov/current/title-45/part-164/section-164.312)

- FDA 21 CFR Part 11 — FDA-regulated electronic records require secure, computer-generated, time-stamped audit trails covering creation, modification, and deletion without obscuring previous information. Trails must be retained and available for inspection. 21 CFR §11.10 (https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11/subpart-B/section-11.10)

- GLBA/FTC Safeguards Rule — Covered financial institutions must periodically review access rights, log authorized-user activity, detect unauthorized access, and supervise relevant service providers. FTC Safeguards Rule (https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know)

- Sarbanes–Oxley Act — Public companies must maintain effective controls over financial reporting and preserve relevant records. Audit trails may provide evidence of changes to financial or disclosure content, although SOX does not prescribe a specific event format. Sarbanes–Oxley Act (https://www.govinfo.gov/app/details/PLAW-107publ204)

- NYDFS Cybersecurity Regulation, 23 NYCRR Part 500 — Covered New York financial entities must restrict and periodically review access privileges and retain audit trails capable of detecting and responding to material cybersecurity events. 23 NYCRR Part 500 (https://www.dfs.ny.gov/system/files/documents/2023/12/rf23_nycrr_part_500_amend02_20231101.pdf)

## European Union

- GDPR — Requires accountability, appropriate access security, data protection by design, and evidence that controls are effective. Audit records are personal data and therefore require minimization, access protection, a legal basis, and defined retention. GDPR (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679)

- NIS2 Directive — Covered essential and important entities must implement access control, incident handling, security monitoring, risk management, and control-effectiveness reviews. NIS2 (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555)

- NIS2 Implementing Regulation 2024/2690 — Covered digital providers must document and log access-right changes, maintain access-right registers, review permissions, protect logs against modification, retain them appropriately, and synchronize timestamps. Regulation 2024/2690 (https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj)

- DORA — EU financial entities must uniquely identify users, control and periodically review access rights, log security and configuration events, and protect logs against deletion, tampering, and unauthorized access. DORA (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554), technical requirements (https://eur-lex.europa.eu/eli/reg_del/2024/1774/oj/eng)

- European Health Data Space Regulation — EHR systems must provide detailed logging of access to electronic health data. This applies only when the system operates as an EHR system, not to an ordinary healthcare website. EHDS (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32025R0327)

- EU AI Act — High-risk AI systems require automatic event logging and retention sufficient for traceability, monitoring, and incident investigation. This applies only where Pagible forms part of a regulated high-risk AI system. EU AI Act (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689)

- Cyber Resilience Act — Commercial software products must follow secure-development, vulnerability-handling, incident-reporting, and security-update requirements. An access audit trail can provide supporting evidence but does not satisfy the Act by itself. Cyber Resilience Act (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847)

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。