

AWS Audit Manager は新規顧客に公開されなくなりました。既存のお客様は、通常どおりサービスを引き続き使用できます。詳細については、「[AWS Audit Manager  可用性の変更](https://docs.aws.amazon.com/audit-manager/latest/userguide/audit-manager-availability-change.html)」を参照してください。

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

# GDPR 2016
<a name="GDPR"></a>





AWS Audit Manager は、一般データ保護規則 (GDPR) 2016 をサポートする構築済みの標準フレームワークを提供します。

このフレームワークには手動コントロールのみが含まれています。これらの手動コントロールは、証拠を自動的に収集しません。ただし、GDPR に基づく一部のコントロールの証拠収集を自動化する場合は、Audit Manager のカスタムコントロール機能を使用できます。詳細については、「[このフレームワークを使用する](#framework-GDPR)」を参照してください。

**Topics**
+ [GDPR とは](#what-is-GDPR)
+ [このフレームワークを使用する](#framework-GDPR)
+ [次の手順](#next-steps-GDPR)
+ [その他のリソース](#resources-GDPR)

## GDPR とは
<a name="what-is-GDPR"></a>

GDPR は、2018 年 5 月 25 日に発効した欧州のプライバシー関連法令です。GDPR は、[指令 95/46/EC](http://en.wikipedia.org/wiki/Data_Protection_Directive) (Directive 95/46/EC) としても知られる EU データ保護指令 (EU Data Protection Directive) に代わるものです。欧州連合 (EU) 全体のデータ保護関連法令を調和させることを目的としています。そのために、全 EU 加盟国において、拘束力のある 1 つのデータ保護関連法令を適用します。

GDPR は、EU 内に設立されたすべての組織、および EU 内に設立されたかどうかにかかわらず、EU 内のデータ主体に対する商品またはサービスの提供、または EU 内で行われる行動のモニタリングに関連して、EU データ主体の個人データを処理する組織に適用されます。個人データとは、識別された、または識別可能な自然人に関する情報です。

 GDPR フレームワークは、Audit Manager のフレームワークライブラリのページにあります。詳細については、「[General Data Protection Regulation (GDPR) Center](https://aws.amazon.com/compliance/gdpr-center/)」を参照してください。

## このフレームワークを使用する
<a name="framework-GDPR"></a>

Audit Manager で GDPR 2016 フレームワークを使用すると、監査の準備をすることができます。

このフレームワークの詳細は以下のとおりです。


| のフレームワーク名 AWS Audit Manager | 自動化されたコントロールの数 | 手動コントロールの数 | コントロールセットの数 | 
| --- | --- | --- | --- | 
| General Data Protection Regulation (GDPR) 2016 | 0 | 378 | 10 | 

この標準フレームワークには手動コントロールのみが含まれています。

**注記**  
GDPR 向けの証拠収集を自動化する場合は、Audit Manager を使用して、GDPR 向けの[独自のカスタムコントロールを作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。次の表は、カスタムコントロールの GDPR 要件にマッピングできる AWS データソースに関する推奨事項を示しています。以下のデータソースの一部は複数のコントロールにマッピングされていますが、各リソース評価に対して要求されるのは 1 回だけであることに注意してください。  
以下の推奨事項では、データソース AWS Security Hub CSPM として AWS Config と を使用します。これらのデータソースから証拠を正常に収集するには、 [AWS Config で と を有効にして設定 AWS Security Hub CSPM](https://docs.aws.amazon.com/audit-manager/latest/userguide/setup-recommendations.html)する指示に従ってください AWS アカウント。この方法で両方のサービスを設定すると、Audit Manager は指定された AWS Config ルールまたは Security Hub CSPM コントロールの評価が行われるたびに証拠を収集します。


| コントロール名 | コントロールセット | 推奨されるコントロールのデータソースマッピング | 
| --- | --- | --- | 
| 第 25 条 Data protection by design and by default (データ保護バイデザインおよびデータ保護バイデフォルト).1 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する <br />+  AWS CloudTrail バケットが公開されていません <br />+  `Allow:*:*` を含むすべてのポリシーを表示し、それらのポリシーを使用しているすべてのプリンシパルとサービスをリストします [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [IAM\_ROOT\_ACCESS\_KEY\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/iam-root-access-key-check.html) <br />+   [ROOT\_ACCOUNT\_MFA\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/root-account-mfa-enabled.html) <br />+  [ROOT\_ACCOUNT\_HARDWARE\_MFA\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/root-account-hardware-mfa-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [ACCESS\_KEYS\_ROTATED](https://docs.aws.amazon.com/config/latest/developerguide/access-keys-rotated.html) <br />+  [IAM\_PASSWORD\_POLICY](https://docs.aws.amazon.com/config/latest/developerguide/iam-password-policy.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  1.1 [(CloudWatch.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-1) <br />+  1.1 [(IAM.20)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-20) <br />+  1.10 [(IAM.16)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-16) <br />+  1.11 [(IAM.17)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-17) <br />+  1.12 [(IAM.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-4) <br />+  1.13 [(IAM.9)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-9) <br />+  1.14 [(IAM.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-6) <br />+  1.16 [(IAM.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-2) <br />+  1.2 [(IAM.5)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-5) <br />+  1.20 [(IAM.18)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-18) <br />+  1.22 [(IAM.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-1) <br />+  1.3 [(IAM.8)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-8) <br />+  1.4 [(IAM.3)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-3) <br />+  1.5 [(IAM.11)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-11) <br />+  1.6 [(IAM.12)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-12) <br />+  1.7 [(IAM.13)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-13) <br />+  1.8 [(IAM.14)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-14) <br />+  1.9 [(IAM.15)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-15) <br />+  2.1 [(CloudTrail.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-1) <br />+  2.2 [(CloudTrail.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-4) <br />+  2.3 [(CloudTrail.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-6) <br />+  2.4 [(CloudTrail.5)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-5) <br />+  2.5 [(Config.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1) <br />+  2.6 [(CloudTrail.7)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-7) <br />+  2.7 [(CloudTrail.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-2) <br />+  2.8 [(KMS.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-4) <br />+  2.9 [(EC2.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-6) <br />+  3.1 [(CloudWatch.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-2) <br />+  3.10 [(CloudWatch.10)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-10) <br />+  3.11 [(CloudWatch.11)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-11) <br />+  3.12 [(CloudWatch.12)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-12) <br />+  3.13 [(CloudWatch.13)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-13) <br />+  3.14 [(CloudWatch.14)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-14) <br />+  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 25 条 Data protection by design and by default (データ保護バイデザインおよびデータ保護バイデフォルト).2 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する <br />+  AWS CloudTrail バケットが公開されていません <br />+  `Allow:*:*` を含むすべてのポリシーを表示し、それらのポリシーを使用しているすべてのプリンシパルとサービスをリストします [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [IAM\_ROOT\_ACCESS\_KEY\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/iam-root-access-key-check.html) <br />+  [ROOT\_ACCOUNT\_MFA\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/root-account-mfa-enabled.html) <br />+  [ROOT\_ACCOUNT\_HARDWARE\_MFA\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/root-account-hardware-mfa-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [ACCESS\_KEYS\_ROTATED](https://docs.aws.amazon.com/config/latest/developerguide/access-keys-rotated.html) <br />+  [IAM\_PASSWORD\_POLICY](https://docs.aws.amazon.com/config/latest/developerguide/iam-password-policy.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  1.1 [(CloudWatch.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-1) <br />+  1.1 [(IAM.20)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-20) <br />+  1.10 [(IAM.16)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-16) <br />+  1.11 [(IAM.17)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-17) <br />+  1.12 [(IAM.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-4) <br />+  1.13 [(IAM.9)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-9) <br />+  1.14 [(IAM.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-6) <br />+  1.16 [(IAM.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-2) <br />+  1.2 [(IAM.5)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-5) <br />+  1.20 [(IAM.18)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-18) <br />+  1.22 [(IAM.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-1) <br />+  1.3 [(IAM.8)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-8) <br />+  1.4 [(IAM.3)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-3) <br />+  1.5 [(IAM.11)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-11) <br />+  1.6 [(IAM.12)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-12) <br />+  1.7 [(IAM.13)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-13) <br />+  1.8 [(IAM.14)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-14) <br />+  1.9 [(IAM.15)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-15) <br />+  2.1 [(CloudTrail.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-1) <br />+  2.2 [(CloudTrail.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-4) <br />+  2.3 [(CloudTrail.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-6) <br />+  2.4 [(CloudTrail.5)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-5) <br />+  2.5 [(Config.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1) <br />+  2.6 [(CloudTrail.7)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-7) <br />+  2.7 [(CloudTrail.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-2) <br />+  2.8 [(KMS.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-4) <br />+  2.9 [(EC2.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-6) <br />+  3.1 [(CloudWatch.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-2) <br />+  3.10 [(CloudWatch.10)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-10) <br />+  3.11 [(CloudWatch.11)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-11) <br />+  3.12 [(CloudWatch.12)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-12) <br />+  3.13 [(CloudWatch.13)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-13) <br />+  3.14 [(CloudWatch.14)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-14) +  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 25 条 Data protection by design and by default (データ保護バイデザインおよびデータ保護バイデフォルト).3 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する <br />+  AWS CloudTrail バケットが公開されていません <br />+  `Allow:*:*` を含むすべてのポリシーを表示し、それらのポリシーを使用しているすべてのプリンシパルとサービスをリストします [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [IAM\_ROOT\_ACCESS\_KEY\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/iam-root-access-key-check.html) <br />+  [ROOT\_ACCOUNT\_MFA\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/root-account-mfa-enabled.html) <br />+  [ROOT\_ACCOUNT\_HARDWARE\_MFA\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/root-account-hardware-mfa-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [ACCESS\_KEYS\_ROTATED](https://docs.aws.amazon.com/config/latest/developerguide/access-keys-rotated.html) <br />+  [IAM\_PASSWORD\_POLICY](https://docs.aws.amazon.com/config/latest/developerguide/iam-password-policy.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  1.1 [(CloudWatch.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-1) <br />+  1.1 [(IAM.20)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-20) <br />+  1.10 [(IAM.16)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-16) <br />+  1.11 [(IAM.17)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-17) <br />+  1.12 [(IAM.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-4) <br />+  1.13 [(IAM.9)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-9) <br />+  1.14 [(IAM.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-6) <br />+  1.16 [(IAM.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-2) <br />+  1.2 [(IAM.5)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-5) <br />+  1.20 [(IAM.18)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-18) <br />+  1.22 [(IAM.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-1) <br />+  1.3 [(IAM.8)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-8) <br />+  1.4 [(IAM.3)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-3) <br />+  1.5 [(IAM.11)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-11) <br />+  1.6 [(IAM.12)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-12) <br />+  1.7 [(IAM.13)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-13) <br />+  1.8 [(IAM.14)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-14) <br />+  1.9 [(IAM.15)](https://docs.aws.amazon.com/securityhub/latest/userguide/iam-controls.html#iam-15) <br />+  2.1 [(CloudTrail.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-1) <br />+  2.2 [(CloudTrail.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-4) <br />+  2.3 [(CloudTrail.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-6) <br />+  2.4 [(CloudTrail.5)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-5) <br />+  2.5 [(Config.1)](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1) <br />+  2.6 [(CloudTrail.7)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-7) <br />+  2.7 [(CloudTrail.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-2) <br />+  2.8 [(KMS.4)](https://docs.aws.amazon.com/securityhub/latest/userguide/kms-controls.html#kms-4) <br />+  2.9 [(EC2.6)](https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-6) <br />+  3.1 [(CloudWatch.2)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-2) <br />+  3.10 [(CloudWatch.10)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-10) <br />+  3.11 [(CloudWatch.11)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-11) <br />+  3.12 [(CloudWatch.12)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-12) <br />+  3.13 [(CloudWatch.13)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-13) <br />+  3.14 [(CloudWatch.14)](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudwatch-controls.html#cloudwatch-14) +  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 30 条 Records of processing activities (取扱活動の記録).1 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [CMK\_BACKING\_KEY\_ROTATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cmk-backing-key-rotation-enabled.html) <br />+  [CLOUD\_TRAIL\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-enabled.html) <br />+  [ELB\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/elb-logging-enabled.html) <br />+  [CLOUDTRAIL\_SECURITY\_TRAIL\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-security-trail-enabled.html) <br />+  [REDSHIFT\_CLUSTER\_CONFIGURATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/redshift-cluster-configuration-check.html) <br />+  [CLOUD\_TRAIL\_CLOUD\_WATCH\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-cloud-watch-logs-enabled.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 30 条 Records of processing activities (取扱活動の記録).2 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [CMK\_BACKING\_KEY\_ROTATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cmk-backing-key-rotation-enabled.html) <br />+  [CLOUD\_TRAIL\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-enabled.html) <br />+  [ELB\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/elb-logging-enabled.html) <br />+  [CLOUD\_TRAIL\_CLOUD\_WATCH\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-cloud-watch-logs-enabled.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 30 条 Records of processing activities (取扱活動の記録).3 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する <br />+  AWS CloudTrail バケットが公開されていません <br />+  `Allow:*:*` を含むすべてのポリシーを表示し、それらのポリシーを使用しているすべてのプリンシパルとサービスをリストします [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [CMK\_BACKING\_KEY\_ROTATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cmk-backing-key-rotation-enabled.html) <br />+  [CLOUD\_TRAIL\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-enabled.html) <br />+  [ELB\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/elb-logging-enabled.html) <br />+  [CLOUD\_TRAIL\_CLOUD\_WATCH\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-cloud-watch-logs-enabled.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 30 条 Records of processing activities (取扱活動の記録).4 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する <br />+  AWS CloudTrail バケットが公開されていません <br />+  `Allow:*:*` を含むすべてのポリシーを表示し、それらのポリシーを使用しているすべてのプリンシパルとサービスをリストします [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [CMK\_BACKING\_KEY\_ROTATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cmk-backing-key-rotation-enabled.html) <br />+  [CLOUD\_TRAIL\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-enabled.html) <br />+  [ELB\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/elb-logging-enabled.html) <br />+  [CLOUD\_TRAIL\_CLOUD\_WATCH\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-cloud-watch-logs-enabled.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 30 条 Records of processing activities (取扱活動の記録).5 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  一定期間におけるすべてのルートアカウントイベントを表示する [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [VPC\_FLOW\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/vpc-flow-logs-enabled.html) <br />+  [CMK\_BACKING\_KEY\_ROTATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cmk-backing-key-rotation-enabled.html) <br />+  [CLOUD\_TRAIL\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-enabled.html) <br />+  [ELB\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/elb-logging-enabled.html) <br />+  [CLOUD\_TRAIL\_CLOUD\_WATCH\_LOGS\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-cloud-watch-logs-enabled.html) <br />データソースタイプ AWS Security Hub CSPM として を選択し、データソースマッピングとして次の Security Hub コントロールを選択します。+  [Config.1](https://docs.aws.amazon.com/securityhub/latest/userguide/config-controls.html#config-1)  | 
| 第 32 条 Security of processing (取扱いの安全性).1 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  すべてのサービスの保管中のデータ暗号化を表示する <br />+  すべてのサービスの転送中のデータ暗号化を表示する <br />+  Amazon S3 向けに MFA 削除が有効になっています <br />+  Amazon Inspector のすべてのスキャン <br />+  Amazon Inspector が有効になっていないすべてのインスタンスを表示する <br />+  HTTPS (SSL) でリッスンしているすべてのロードバランサーを表示する <br />+  AWS CloudTrail 保管時の暗号化 <br />+  すべての変更とコメントされたすべての設定 AWS Config を表示するための Amazon CloudWatch アラート <br />+  すべてのルートアクティビティ [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [S3\_BUCKET\_SSL\_REQUESTS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-ssl-requests-only.html) <br />+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUDWATCH\_LOG\_GROUP\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/cloudwatch-log-group-encrypted.html) <br />+  [EFS\_ENCRYPTED\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/efs-encrypted-check.html) <br />+  [ELASTICSEARCH\_ENCRYPTED\_AT\_REST](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-encrypted-at-rest.html) <br />+  [ENCRYPTED\_VOLUMES](https://docs.aws.amazon.com/config/latest/developerguide/encrypted-volumes.html) <br />+  [RDS\_STORAGE\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-storage-encrypted.html) <br />+  [REDSHIFT\_CLUSTER\_CONFIGURATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/redshift-cluster-configuration-check.html) <br />+  [S3\_BUCKET\_SERVER\_SIDE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-server-side-encryption-enabled.html) <br />+  [SAGEMAKER\_ENDPOINT\_CONFIGURATION\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-endpoint-configuration-kms-key-configured.html) <br />+  [SAGEMAKER\_NOTEBOOK\_INSTANCE\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-notebook-instance-kms-key-configured.html) <br />+  [SNS\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/sns-encrypted-kms.html) <br />+  [EC2\_EBS\_ENCRYPTION\_BY\_DEFAULT](https://docs.aws.amazon.com/config/latest/developerguide/ec2-ebs-encryption-by-default.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encrypted-kms.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encryption-enabled.html) <br />+  [RDS\_SNAPSHOT\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-snapshot-encrypted.html) <br />+  [S3\_DEFAULT\_ENCRYPTION\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/s3-default-encryption-kms.html) <br />+  [DAX\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dax-encryption-enabled.html) <br />+  [EKS\_SECRETS\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/eks-secrets-encrypted.html) <br />+  [RDS\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/rds-logging-enabled.html) <br />+  [REDSHIFT\_BACKUP\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/redshift-backup-enabled.html) <br />+  [RDS\_IN\_BACKUP\_PLAN](https://docs.aws.amazon.com/config/latest/developerguide/rds-in-backup-plan.html) <br />+  [WAF\_CLASSIC\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/waf-classic-logging-enabled.html) <br />+  [WAFV2\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/wafv2-logging-enabled.html) <br />+  [ALB\_HTTP\_TO\_HTTPS\_REDIRECTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-to-https-redirection-check.html) <br />+  [ELB\_ACM\_CERTIFICATE\_REQUIRED](https://docs.aws.amazon.com/config/latest/developerguide/elb-acm-certificate-required.html) <br />+  [ELB\_CUSTOM\_SECURITY\_POLICY\_SSL\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elb-custom-security-policy-ssl-check.html) <br />+  [REDSHIFT\_REQUIRE\_TLS\_SSL](https://docs.aws.amazon.com/config/latest/developerguide/redshift-require-tls-ssl.html) <br />+  [CLOUDFRONT\_VIEWER\_POLICY\_HTTPS](https://docs.aws.amazon.com/config/latest/developerguide/cloudfront-viewer-policy-https.html) <br />+  [ALB\_HTTP\_DROP\_INVALID\_HEADER\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-drop-invalid-header-enabled.html) <br />+  [ELASTICSEARCH\_NODE\_TO\_NODE\_ENCRYPTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-node-to-node-encryption-check.html) <br />+  [ELB\_TLS\_HTTPS\_LISTENERS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/elb-tls-https-listeners-only.html) <br />+  [ACM\_CERTIFICATE\_EXPIRATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/acm-certificate-expiration-check.html) <br />+  [API\_GW\_CACHE\_ENABLED\_AND\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/api-gw-cache-enabled-and-encrypted.html)  | 
| 第 32 条 Security of processing (取扱いの安全性).2 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  すべてのサービスの保管中のデータ暗号化を表示する <br />+  すべてのサービスの転送中のデータ暗号化を表示する <br />+  Amazon S3 向けに MFA 削除が有効になっています <br />+  Amazon Inspector のすべてのスキャン <br />+  Amazon Inspector が有効になっていないすべてのインスタンスを表示する <br />+  HTTPS (SSL) でリッスンしているすべてのロードバランサーを表示する <br />+  AWS CloudTrail 保管時の暗号化 <br />+  すべての変更とコメントされたすべての設定 AWS Config を表示するための Amazon CloudWatch アラート <br />+  すべてのルートアクティビティ [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [S3\_BUCKET\_SSL\_REQUESTS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-ssl-requests-only.html) <br />+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUDWATCH\_LOG\_GROUP\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/cloudwatch-log-group-encrypted.html) <br />+  [EFS\_ENCRYPTED\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/efs-encrypted-check.html) <br />+  [ELASTICSEARCH\_ENCRYPTED\_AT\_REST](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-encrypted-at-rest.html) <br />+  [ENCRYPTED\_VOLUMES](https://docs.aws.amazon.com/config/latest/developerguide/encrypted-volumes.html) <br />+  [RDS\_STORAGE\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-storage-encrypted.html) <br />+  [REDSHIFT\_CLUSTER\_CONFIGURATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/redshift-cluster-configuration-check.html) <br />+  [S3\_BUCKET\_SERVER\_SIDE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-server-side-encryption-enabled.html) <br />+  [SAGEMAKER\_ENDPOINT\_CONFIGURATION\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-endpoint-configuration-kms-key-configured.html) <br />+  [SAGEMAKER\_NOTEBOOK\_INSTANCE\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-notebook-instance-kms-key-configured.html) <br />+  [SNS\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/sns-encrypted-kms.html) <br />+  [EC2\_EBS\_ENCRYPTION\_BY\_DEFAULT](https://docs.aws.amazon.com/config/latest/developerguide/ec2-ebs-encryption-by-default.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encrypted-kms.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encryption-enabled.html) <br />+  [RDS\_SNAPSHOT\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-snapshot-encrypted.html) <br />+  [S3\_DEFAULT\_ENCRYPTION\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/s3-default-encryption-kms.html) <br />+  [DAX\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dax-encryption-enabled.html) <br />+  [EKS\_SECRETS\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/eks-secrets-encrypted.html) <br />+  [RDS\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/rds-logging-enabled.html) <br />+  [REDSHIFT\_BACKUP\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/redshift-backup-enabled.html) <br />+  [RDS\_IN\_BACKUP\_PLAN](https://docs.aws.amazon.com/config/latest/developerguide/rds-in-backup-plan.html) <br />+  [WAF\_CLASSIC\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/waf-classic-logging-enabled.html) <br />+  [WAFV2\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/wafv2-logging-enabled.html) <br />+  [ALB\_HTTP\_TO\_HTTPS\_REDIRECTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-to-https-redirection-check.html) <br />+  [ELB\_ACM\_CERTIFICATE\_REQUIRED](https://docs.aws.amazon.com/config/latest/developerguide/elb-acm-certificate-required.html) <br />+  [ELB\_CUSTOM\_SECURITY\_POLICY\_SSL\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elb-custom-security-policy-ssl-check.html) <br />+  [REDSHIFT\_REQUIRE\_TLS\_SSL](https://docs.aws.amazon.com/config/latest/developerguide/redshift-require-tls-ssl.html) <br />+  [CLOUDFRONT\_VIEWER\_POLICY\_HTTPS](https://docs.aws.amazon.com/config/latest/developerguide/cloudfront-viewer-policy-https.html) <br />+  [ALB\_HTTP\_DROP\_INVALID\_HEADER\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-drop-invalid-header-enabled.html) <br />+  [ELASTICSEARCH\_NODE\_TO\_NODE\_ENCRYPTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-node-to-node-encryption-check.html) <br />+  [ELB\_TLS\_HTTPS\_LISTENERS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/elb-tls-https-listeners-only.html) <br />+  [ACM\_CERTIFICATE\_EXPIRATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/acm-certificate-expiration-check.html) <br />+  [API\_GW\_CACHE\_ENABLED\_AND\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/api-gw-cache-enabled-and-encrypted.html)  | 
| 第 32 条 Security of processing (取扱いの安全性).3 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  すべてのサービスの保管中のデータ暗号化を表示する <br />+  すべてのサービスの転送中のデータ暗号化を表示する <br />+  Amazon S3 向けに MFA 削除が有効になっています <br />+  Amazon Inspector のすべてのスキャン <br />+  Amazon Inspector が有効になっていないすべてのインスタンスを表示する <br />+  HTTPS (SSL) でリッスンしているすべてのロードバランサーを表示する <br />+  AWS CloudTrail 保管時の暗号化 <br />+  すべての変更とコメントされたすべての設定 AWS Config を表示するための Amazon CloudWatch アラート <br />+  すべてのルートアクティビティ [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [S3\_BUCKET\_SSL\_REQUESTS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-ssl-requests-only.html) <br />+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUDWATCH\_LOG\_GROUP\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/cloudwatch-log-group-encrypted.html) <br />+  [EFS\_ENCRYPTED\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/efs-encrypted-check.html) <br />+  [ELASTICSEARCH\_ENCRYPTED\_AT\_REST](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-encrypted-at-rest.html) <br />+  [ENCRYPTED\_VOLUMES](https://docs.aws.amazon.com/config/latest/developerguide/encrypted-volumes.html) <br />+  [RDS\_STORAGE\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-storage-encrypted.html) <br />+  [REDSHIFT\_CLUSTER\_CONFIGURATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/redshift-cluster-configuration-check.html) <br />+  [S3\_BUCKET\_SERVER\_SIDE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-server-side-encryption-enabled.html) <br />+  [SAGEMAKER\_ENDPOINT\_CONFIGURATION\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-endpoint-configuration-kms-key-configured.html) <br />+  [SAGEMAKER\_NOTEBOOK\_INSTANCE\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-notebook-instance-kms-key-configured.html) <br />+  [SNS\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/sns-encrypted-kms.html) <br />+  [EC2\_EBS\_ENCRYPTION\_BY\_DEFAULT](https://docs.aws.amazon.com/config/latest/developerguide/ec2-ebs-encryption-by-default.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encrypted-kms.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encryption-enabled.html) <br />+  [RDS\_SNAPSHOT\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-snapshot-encrypted.html) <br />+  [S3\_DEFAULT\_ENCRYPTION\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/s3-default-encryption-kms.html) <br />+  [DAX\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dax-encryption-enabled.html) <br />+  [EKS\_SECRETS\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/eks-secrets-encrypted.html) <br />+  [RDS\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/rds-logging-enabled.html) <br />+  [REDSHIFT\_BACKUP\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/redshift-backup-enabled.html) <br />+  [RDS\_IN\_BACKUP\_PLAN](https://docs.aws.amazon.com/config/latest/developerguide/rds-in-backup-plan.html) <br />+  [WAF\_CLASSIC\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/waf-classic-logging-enabled.html) <br />+  [WAFV2\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/wafv2-logging-enabled.html) <br />+  [ALB\_HTTP\_TO\_HTTPS\_REDIRECTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-to-https-redirection-check.html) <br />+  [ELB\_ACM\_CERTIFICATE\_REQUIRED](https://docs.aws.amazon.com/config/latest/developerguide/elb-acm-certificate-required.html) <br />+  [ELB\_CUSTOM\_SECURITY\_POLICY\_SSL\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elb-custom-security-policy-ssl-check.html) <br />+  [REDSHIFT\_REQUIRE\_TLS\_SSL](https://docs.aws.amazon.com/config/latest/developerguide/redshift-require-tls-ssl.html) <br />+  [CLOUDFRONT\_VIEWER\_POLICY\_HTTPS](https://docs.aws.amazon.com/config/latest/developerguide/cloudfront-viewer-policy-https.html) <br />+  [ALB\_HTTP\_DROP\_INVALID\_HEADER\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-drop-invalid-header-enabled.html) <br />+  [ELASTICSEARCH\_NODE\_TO\_NODE\_ENCRYPTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-node-to-node-encryption-check.html) <br />+  [ELB\_TLS\_HTTPS\_LISTENERS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/elb-tls-https-listeners-only.html) <br />+  [ACM\_CERTIFICATE\_EXPIRATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/acm-certificate-expiration-check.html) <br />+  [API\_GW\_CACHE\_ENABLED\_AND\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/api-gw-cache-enabled-and-encrypted.html)  | 
| 第 32 条 Security of processing (取扱いの安全性).4 | 第 4 章 - コントローラーとプロセッサ | この GDPR [コントロールをサポートするカスタムコントロールを で作成](https://docs.aws.amazon.com/audit-manager/latest/userguide/create-controls.html)できます。 AWS Audit Manager <br />[コントロールの詳細を指定](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-1)するときは、**[Testing information]** (テスト情報) で次のように入力します。+  すべてのサービスの保管中のデータ暗号化を表示する <br />+  すべてのサービスの転送中のデータ暗号化を表示する <br />+  Amazon S3 向けに MFA 削除が有効になっています <br />+  Amazon Inspector のすべてのスキャン <br />+  Amazon Inspector が有効になっていないすべてのインスタンスを表示する <br />+  HTTPS (SSL) でリッスンしているすべてのロードバランサーを表示する <br />+  AWS CloudTrail 保管時の暗号化 <br />+  すべての変更とコメントされたすべての設定 AWS Config を表示するための Amazon CloudWatch アラート <br />+  すべてのルートアクティビティ [コントロールデータソースを設定する](https://docs.aws.amazon.com/audit-manager/latest/userguide/customize-control-from-scratch.html#from-scratch-step-2)ときは、以下のすべてをデータソースとして含めることをお勧めします。<br />データソースタイプ AWS Config として を選択し、データソースマッピングとして次の AWS Config マネージドルールを選択します。+  [CLOUD\_TRAIL\_LOG\_FILE\_VALIDATION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-log-file-validation-enabled.html) <br />+  [S3\_BUCKET\_SSL\_REQUESTS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-ssl-requests-only.html) <br />+  [CLOUD\_TRAIL\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/cloud-trail-encryption-enabled.html) <br />+  [CLOUDWATCH\_LOG\_GROUP\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/cloudwatch-log-group-encrypted.html) <br />+  [EFS\_ENCRYPTED\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/efs-encrypted-check.html) <br />+  [ELASTICSEARCH\_ENCRYPTED\_AT\_REST](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-encrypted-at-rest.html) <br />+  [ENCRYPTED\_VOLUMES](https://docs.aws.amazon.com/config/latest/developerguide/encrypted-volumes.html) <br />+  [RDS\_STORAGE\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-storage-encrypted.html) <br />+  [REDSHIFT\_CLUSTER\_CONFIGURATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/redshift-cluster-configuration-check.html) <br />+  [S3\_BUCKET\_SERVER\_SIDE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-server-side-encryption-enabled.html) <br />+  [SAGEMAKER\_ENDPOINT\_CONFIGURATION\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-endpoint-configuration-kms-key-configured.html) <br />+  [SAGEMAKER\_NOTEBOOK\_INSTANCE\_KMS\_KEY\_CONFIGURED](https://docs.aws.amazon.com/config/latest/developerguide/sagemaker-notebook-instance-kms-key-configured.html) <br />+  [SNS\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/sns-encrypted-kms.html) <br />+  [EC2\_EBS\_ENCRYPTION\_BY\_DEFAULT](https://docs.aws.amazon.com/config/latest/developerguide/ec2-ebs-encryption-by-default.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTED\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encrypted-kms.html) <br />+  [DYNAMODB\_TABLE\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dynamodb-table-encryption-enabled.html) <br />+  [RDS\_SNAPSHOT\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/rds-snapshot-encrypted.html) <br />+  [S3\_DEFAULT\_ENCRYPTION\_KMS](https://docs.aws.amazon.com/config/latest/developerguide/s3-default-encryption-kms.html) <br />+  [DAX\_ENCRYPTION\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/dax-encryption-enabled.html) <br />+  [EKS\_SECRETS\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/eks-secrets-encrypted.html) <br />+  [RDS\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/rds-logging-enabled.html) <br />+  [REDSHIFT\_BACKUP\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/redshift-backup-enabled.html) <br />+  [RDS\_IN\_BACKUP\_PLAN](https://docs.aws.amazon.com/config/latest/developerguide/rds-in-backup-plan.html) <br />+  [WAF\_CLASSIC\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/waf-classic-logging-enabled.html) <br />+  [WAFV2\_LOGGING\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/wafv2-logging-enabled.html) <br />+  [ALB\_HTTP\_TO\_HTTPS\_REDIRECTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-to-https-redirection-check.html) <br />+  [ELB\_ACM\_CERTIFICATE\_REQUIRED](https://docs.aws.amazon.com/config/latest/developerguide/elb-acm-certificate-required.html) <br />+  [ELB\_CUSTOM\_SECURITY\_POLICY\_SSL\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elb-custom-security-policy-ssl-check.html) <br />+  [REDSHIFT\_REQUIRE\_TLS\_SSL](https://docs.aws.amazon.com/config/latest/developerguide/redshift-require-tls-ssl.html) <br />+  [CLOUDFRONT\_VIEWER\_POLICY\_HTTPS](https://docs.aws.amazon.com/config/latest/developerguide/cloudfront-viewer-policy-https.html) <br />+  [ALB\_HTTP\_DROP\_INVALID\_HEADER\_ENABLED](https://docs.aws.amazon.com/config/latest/developerguide/alb-http-drop-invalid-header-enabled.html) <br />+  [ELASTICSEARCH\_NODE\_TO\_NODE\_ENCRYPTION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/elasticsearch-node-to-node-encryption-check.html) <br />+  [ELB\_TLS\_HTTPS\_LISTENERS\_ONLY](https://docs.aws.amazon.com/config/latest/developerguide/elb-tls-https-listeners-only.html) <br />+  [ACM\_CERTIFICATE\_EXPIRATION\_CHECK](https://docs.aws.amazon.com/config/latest/developerguide/acm-certificate-expiration-check.html) <br />+  [API\_GW\_CACHE\_ENABLED\_AND\_ENCRYPTED](https://docs.aws.amazon.com/config/latest/developerguide/api-gw-cache-enabled-and-encrypted.html)  | 

GDPR 用の新しいカスタムコントロールを作成したら、それらをカスタム GDPR フレームワークに追加できます。その後、カスタム GDPR フレームワークから評価を作成できます。これにより、Audit Manager は追加したカスタムコントロールについての証拠を自動的に収集できます。

## 次の手順
<a name="next-steps-GDPR"></a>

含まれている標準コントロールのリストなど、このフレームワークに関する詳細情報を表示する方法については、「[でのフレームワークの確認 AWS Audit Manager](review-frameworks.md)」を参照してください。

このフレームワークを使用して評価を作成する方法については、「[での評価の作成 AWS Audit Manager](create-assessments.md)」を参照してください。

特定の要件をサポートするためにこのフレームワークをカスタマイズする方法については、「[で既存のフレームワークの編集可能なコピーを作成する AWS Audit Manager](create-custom-frameworks-from-existing.md)」を参照してください。

## その他のリソース
<a name="resources-GDPR"></a>
+ [一般データ保護規則 (GDPR) センター](https://aws.amazon.com/compliance/gdpr-center/)
+ [AWS GDPR ブログ投稿](https://aws.amazon.com/blogs/security/tag/gdpr/)