{"id":49409,"date":"2022-05-24T12:05:27","date_gmt":"2022-05-24T04:05:27","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=49409"},"modified":"2022-05-24T12:05:29","modified_gmt":"2022-05-24T04:05:29","slug":"kaspersky-renews-soc-2-audit-by-big-four-firm","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/05\/24\/kaspersky-renews-soc-2-audit-by-big-four-firm\/","title":{"rendered":"Kaspersky renews SOC 2 audit by Big Four firm"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Committed to the highest security principles, Kaspersky has once again completed a Service Organization Control for Service Organizations (SOC 2) Type 1 audit, conducted by an international Big Four accounting firm. The independent assessment reaffirmed that the development and release process of Kaspersky\u2019s antivirus bases are protected against unauthorized changes by security controls.\u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Developed by the American Institute of Certified Public Accountants (AICPA), the Service Organization Controls (SOC) Reporting Framework is a globally recognized report that confirms that the organization\u2019s security controls are in conformity with AICPA\u2019s&nbsp;Trust Services Criteria (TSC), namely security, availability, processing integrity, confidentiality and privacy. Kaspersky first <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/compliance-soc2\">completed<\/a> the SOC 2 Type 1 examination in 2019 as part of the company\u2019s <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/transparency-center\">Global Transparency Initiative (GTI).<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reassessment, launched in late January 2022, was successfully completed in late April. During the examination, Big Four auditors among other things scrutinized the company\u2019s policies and procedures related to the development and release of antivirus (AV) bases, the network and physical security of the infrastructure involved in this process and the monitoring tools used by the Kaspersky team. The examination also covered how the company communicates the terms and conditions of the AV bases release process to its employees and users and customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result of the audit, it was concluded that Kaspersky\u2019s internal controls for protecting the development and release process of antivirus bases for Windows and Unix OS systems are suitably designed to meet all five trust categories covered by the TSC. The scope of the current audit has been expanded compared to the 2019 assessment, as Kaspersky has since introduced new security tools and controls. The full report can be provided to our customers upon <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/about\/compliance-soc2\">request<\/a>.<br><br>\u201cWe are proud to once again reaffirm the integrity and security of our engineering practices delivering high-class cybersecurity solutions. The security and trust of our customers and partners are a key priority for us. This new independent assessment provides the necessary assurance and verifies the trustworthiness of the solutions and services we offer. The SOC 2 assessment gives a rigorous and, at the same time, useful description of our safeguards to customers and partners about how Kaspersky\u2019s AV bases are developed and distributed. The report is a confirmation of Kaspersky\u2019s commitment to proactively protecting its infrastructure and guaranteeing the security of its customers and partners,\u201d&nbsp;comments Anton Ivanov, Chief Technology Officer at Kaspersky.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The renewal of the SOC 2 Type 1 report falls within a broader range of activities that are part of Kaspersky\u2019s GTI, demonstrating the company\u2019s ongoing commitment to accountability. Kaspersky is among the first in the industry to start operating Transparency Centers, in which the company\u2019s stakeholders can review Kaspersky\u2019s source code, software updates and threat detection rules. It regularly seeks independent third-party assessments of the company\u2019s engineering practices, data services and compliance with existing industry standards. Earlier this year, the company renewed its <a rel=\"noreferrer noopener\" href=\"https:\/\/media.kaspersky.com\/en\/recertification_IS0_27001.pdf\" target=\"_blank\">ISO 27001 certification<\/a>, an internationally recognized applicable security standard, which was issued by independent certification body T\u00dcV AUSTRIA.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky has once again completed a Service Organization Control for Service Organizations (SOC 2) Type 1 audit, conducted by an international Big Four accounting firm. The independent assessment reaffirmed that the development and release process of Kaspersky\u2019s antivirus bases are protected against unauthorized changes by security controls.\u00a0<\/p>\n","protected":false},"author":6,"featured_media":45724,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-49409","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/49409","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=49409"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/49409\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/45724"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=49409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=49409"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=49409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}