Security culture
Our company-wide organizational security policies and procedures include:
- Regular and mandatory training for all employees in security awareness and data privacy
- All employees must adhere to Datasite's Code of Conduct and Confidentiality Agreements, and affirm these annually
- Software Engineering staff must also complete annual training in secure coding
- Annual testing of our security incident response—this includes external and internal notifications, escalation procedures and communications criteria
- Program to allow security researchers to find and inform us of vulnerabilities
- An Access Management Standard, based on roles and responsibilities, requires quarterly review and documented approval—in the event of termination, access is removed within 24 hours
- Infrastructure and application penetration testing conducted by an industry-recognized third party