安全性

設定安全性標準

Dated audit confirmation methods don’t protect your clients' data and are susceptible to fraud. The Thomson Reuters® Confirmation digital platform is the only way to ensure the process is secure from start to finish, limiting risk for you and your clients.

Image for Setting the standard for security

設定安全性標準

  • To illustrate Confirmation’s commitment to effective operational controls and privacy and security best practices, we undergo Service Organization Control (SOC) examinations annually and have received an ISO 27001 certification for the service. Collectively, these provide assurance about the controls we implement to protect the privacy and confidentiality of our users’ data and the security, availability, and processing integrity of our system.

SOC 1 和 SOC 2 檢查

  • SOC 報告說明對服務機構所提供服務的控制。為了滿足客戶的不同需求,我們要完成兩次 SOC 檢查。
  • 二類 SOC 1 — 依據 SSAE 18 報告編寫,涉及與用戶實體財務報告內部控制相關的控制設計和運作有效性。
  • Type 2 SOC 2 – reports on the design and operating effectiveness of controls that affect the security, availability, and confidentiality of the information processed by the system.

ISO 27001 Certification

  • Confirmation.com 服務的 ISO 27001 認證 — 代表全球公認的資訊安全管理系統 (ISMS) 建立和認證標準。該標準規定了在組織的整體業務風險範圍內建立、實施、操作、監控、維護和改進記錄 ISMS 的要求。
  • Confirmation.com’s ISMS covers its online audit confirmation service and infrastructure including data and data environments, servers, source code, and internal networks.
  • 檢視我們的 ISO27001 證書。

資訊安全摘要

  • 保護客戶資訊是我們資訊安全策略的核心。Thomson Reuters 以各種方式提供可靠且值得信賴的資訊而享有盛譽,其中包括由廣泛的安全政策、標準和實作支援的全面資訊安全管理計劃。
  • 請造訪 Whistic 上的 Confirmation 簡介,以瞭解我們保障資訊安全和資料隱私的方法。