share_log

GoDaddy 2023 Sustainability Report: Our Operations | Cybersecurity and Data Privacy

GoDaddy 2023 Sustainability Report: Our Operations | Cybersecurity and Data Privacy

godaddy 2023可持续性报告:我们的运营|网络安全概念与数据隐私
Accesswire ·  06/25 10:15

NORTHAMPTON, MA / ACCESSWIRE / June 25, 2024 / GoDaddy

2024年6月25日,GoDaddy公司总部位于MA的Northampton。

Originally published in GoDaddy's 2023 Sustainability Report

最初发表在godaddy的2023年可持续性报告中

Cybersecurity and Data Privacy

网络安全和数据隐私。

Cybersecurity and data privacy are a top priority for GoDaddy as an operator of large internet infrastructure. We take our commitment to cybersecurity and data privacy seriously. We maintain enterprise-wide cybersecurity and data privacy programs designed to manage the risks to GoDaddy's information systems, customer data, and personal information of our customers and employees from cyber threats, and to comply with our regulatory obligations.

作为大型互联网基础设施运营商,网络安全和数据隐私是GoDaddy的首要任务。我们认真履行对网络安全和数据隐私的承诺。我们保持全企业级别的网络安全和数据隐私计划,设计用于管理GoDaddy信息系统、顾客数据、客户和员工个人信息面临的网络威胁的风险,并遵守我们的监管义务。

Our approach to management of cybersecurity risk and data privacy obligations includes:

我们管理网络安全风险和数据隐私义务的方法包括:

  • Board Oversight: Our Board oversees the company's cybersecurity risk management program through its Audit and Finance Committee. The Audit and Finance Committee receives regular reports from GoDaddy's Chief Information Security Officer (CISO) regarding the state of the company's cybersecurity program. These reports are shared, at least quarterly, with the Board of Directors. In addition, our Corporate Audit Services team audits our privacy practices, and the results of those audits are presented to senior leadership and discussed with the Audit and Finance Committee. Updates on privacy and cybersecurity matters are also included as part of the Audit and Finance Committee's review of the Company's enterprise risk management efforts.
  • Cybersecurity Risk Management: Our management is responsible for identifying, assessing, and managing the company's material cybersecurity risks on an ongoing basis; establishing processes designed to help ensure that potential cybersecurity risk exposures are monitored; putting in place appropriate mitigation and remediation measures; and maintaining the company's cybersecurity programs. GoDaddy's CISO has primary responsibility for the company's programs for identifying, assessing, and managing the company's cybersecurity risks. The CISO reports directly to the company's Chief Technology Officer and regularly provides reports and updates to the company's Chief Executive Officer on significant cybersecurity-related matters relevant to the company's cybersecurity risk.
  • Privacy Program Management: Our Privacy Officer manages our Data Privacy Office and global privacy program. Our Data Privacy Office is responsible for day-to-day operations of our privacy program, including but not limited to conducting privacy impact assessments, providing training to employees, responding to data subject requests, and responding to inquiries from data protection authorities. Other personnel and departments at GoDaddy also assist the Data Privacy Office, including but not limited to the company's Legal and Information Security teams.
  • 董事会监督公司的网络安全风险管理计划,通过审计和财务委员会实施。审计和财务委员会定期接收GoDaddy的首席信息安全官(CISO)提交有关公司网络安全计划的报告。至少每季度向董事会共享这些报告。此外,我们的企业审计服务团队审计我们的隐私实践,这些审计结果会提交给高级领导层,并与审计和财务委员会进行讨论。作为企业风险管理的一部分,隐私和网络安全事项的更新也包含在审计和财务委员会对公司的审查中。
  • 网络安全风险管理:我们的管理层负责持续识别、评估和管理公司的重要网络安全风险,建立设计有助于监控潜在网络安全风险暴露的流程,制定适当的缓解和补救措施,并维护公司的网络安全计划。GoDaddy的CISO拥有掌控公司识别、评估和管理其网络安全风险的首要责任。CISO直接向公司的首席技术官汇报,并定期向公司的首席执行官提供有关公司网络安全风险相关事项的报告和更新。
  • 隐私计划管理:我们的隐私官管理我们的数据隐私办公室和全球隐私计划。我们的数据隐私办公室负责日常运营我们的隐私计划,包括但不限于进行隐私影响评估,为员工提供培训,回应数据主体请求,并回应数据保护机构的咨询。GoDaddy的其他员工和部门也协助数据隐私办公室,包括但不限于我们公司的法律和信息安全团队。

Cybersecurity

网络安全概念

We're committed to protecting customer information from cybersecurity threats. Our information security team uses a variety of controls to protect our systems and customer information from cybersecurity threats. Some of their efforts include:

我们致力于保护客户信息免受网络安全威胁。我们的信息安全团队使用各种控制措施来保护我们的系统和客户信息免受网络安全威胁。他们的一些工作包括:

  • Proactive Monitoring and Assessment: We use monitoring and detection tools designed to identify and mitigate threats before they impact GoDaddy or our customers. We also regularly scan our environment to identify potential vulnerabilities.
  • Security by Design: Our developers are encouraged to consider cybersecurity from the initial design phase of our products to completion. We also have designed and implemented risk-based processes and procedures to conduct security reviews on new or updated applications prior to launch.
  • Security Frameworks: Some parts of our business are required to align with specialized frameworks, such as the Payment Card Industry Data Security Standards (PCI-DSS) for handling payment card data. Where required by our customer or other agreements, we align our practices and controls with other recognized standards such as International Organization for Standardization (ISO) 27001.
  • Incident Response: We have a dedicated incident response team that works with our business units and other internal and external subject matter experts to respond to potential cybersecurity incidents. In 2023, we updated our policies and procedures for reporting cybersecurity threats internally to strengthen our overall response capabilities.
  • 积极监控和评估:我们使用监控和检测工具,旨在识别和减轻威胁,以防止其对GoDaddy或我们的客户造成影响。我们还定期扫描我们的环境,以识别潜在的漏洞。
  • 设计安全:我们的开发人员被鼓励从产品的初始设计阶段到完成时都要考虑网络安全问题。我们还设计并实施了基于风险的流程和程序,在新的或更新的应用程序启动之前对其进行安全审查。
  • 安全框架:我们的某些业务部门需要与专门的框架进行对接,例如用于处理支付卡数据的PCI-DSS(付款卡数据安全标准)。在我们的客户或其他协议要求的情况下,我们会将我们的实践和控制与其他认可的标准,例如国际标准化组织(ISO)27001保持一致。
  • 事件响应:我们配备了专门的事件响应团队,与业务部门和其他内部和外部专家合作,响应潜在的网络安全事件。在2023年,我们更新了内部报告网络安全威胁的政策和程序,以增强我们的总体响应能力。

Employee Training and Education

员工培训和教育

GoDaddy employees receive annual data security and privacy training through our Do The Right Thing (DTRT) compliance training. We also send alerts to employees to keep them updated on the latest security threats and host regular workshops for specific teams on privacy topics.

GoDaddy员工通过我们的DTRT合规培训每年接受数据安全和隐私培训。我们也向员工发送警报,使他们及时了解最新的安全威胁,并定期为特定团队举办有关隐私问题的研讨会。

Data Privacy

数据隐私

We take a proactive approach to managing our data privacy obligations. Some of our efforts include:

我们采取积极的方法管理数据隐私义务。我们的一些努力包括:

Establishing Core Data Privacy Practices: We empower our customers, employees, and individual data subjects to manage their privacy preferences and exercise their privacy rights when visiting our websites, using our services, communicating with us, or working with us. Our core privacy practices are set forth in our Global Privacy Notice and related privacy policies. We apply our core practices to all individuals with whom we interact.

建立核心数据隐私实践:我们赋予客户、员工和个人数据主体在访问我们的网站、使用我们的服务、与我们沟通或与我们合作时管理其隐私首选项和行使其隐私权利的权力。我们的核心隐私实践规定在我们的全球隐私通知和相关隐私政策中。我们将我们的核心实践应用于我们与之互动的所有个人。

Global Regulatory Compliance: While we maintain a global privacy program where we apply a core set of common principles to how we handle personal data, we are mindful of local requirements and restrictions in many of the jurisdictions where we do business and have developed jurisdiction specific data privacy notices for the United States, the United Kingdom, and the European Union. From time to time, we have also adjusted our privacy practices to meet local requirements in other jurisdictions where we do business. We also follow jurisdiction-specific privacy practices relating to handling of personal data relating to our employees and job applicants.

全球法规遵从:虽然我们维护全球隐私计划,将一套核心的常用原则应用于我们处理个人数据的方式,但我们也注意到我们的许多业务所在的各个管辖区的本地要求和限制,并为美国、英国和欧盟制定了特定于管辖区的数据隐私通知。我们不时根据业务所在的其他管辖区的本地要求调整我们的隐私实践。我们还遵循与员工和求职者的个人数据处理相关的特定于管辖区的隐私实践。

International Data Transfers: In 2023, the U.S. and E.U. reached agreement on a new framework to allow lawful transfers of personal data from Europe to the United States (the "U.S.-E.U. Data Privacy Framework"). GoDaddy certified its compliance with this framework, as well as its compliance with the U.S. and U.K. extension to the U.S.- E.U. Data Privacy Framework. Where the Data Privacy Framework does not apply to transfers from the U.K. and E.U., we use other recognized transfer mechanisms, including standard contractual clauses.

国际数据转移:2023年,美国与欧盟达成一项新的框架,允许从欧洲合法转移个人数据到美国(“美国-欧盟数据隐私框架”)。GoDaddy已经证明其符合该框架的法律和监管要求,以及其符合美国和英国向美国-欧盟数据隐私框架的扩展要求。在数据隐私框架不适用于从英国和欧盟转移数据的情况下,我们使用其他认可的转移机制,包括标准合同条款。

  • Data Processing Agreements: In addition to our responsibilities for handling the personal data of our customers, employees, and other data subjects with whom we interact directly, we also handle personal data on behalf of our customers. In this capacity, we act as a data processor, and our customers retain primary responsibility for safely and lawfully processing personal data. Where required by our agreements or applicable laws, we enter into data processing addendums that regulate our rights and responsibilities for processing personal data on behalf of our customers.
  • Service Providers: Whether acting as a data controller or processor, we use service providers to process personal data when necessary or appropriate to provide our services or conduct our business. When we provide personal data to a service provider or other third-party acting on our behalf, those service providers and third parties are required to comply with our instructions and contractual restrictions in processing personal information on our behalf.
  • GDPR Independent Assessment: In 2023, TRUSTe independently assessed GoDaddy's compliance with the EU General Data Protection Regulation (GDPR) and validated that GoDaddy provided evidence and other support showing that it implemented program-level measures that are designed to meet TRUSTe's 40 GDPR Privacy Program Validation Requirements.
  • Privacy by Design: Our Data Privacy Office also consults with our business teams on day-to-day privacy issues, ranging from conducting privacy impact assessments (PIAs) on new business practices to participating in the earliest phases of new product designs to ensure that privacy concerns are addressed during product development. In 2023, we rolled out a new technical solution to streamline the PIA review and more closely integrate privacy reviews with engineering reviews.
  • 数据处理协议:除了处理我们直接与之互动的客户、员工和其他数据主体的个人数据的责任外,我们还代表我们的客户处理个人数据。在这种情况下,我们充当数据处理者,我们的客户保留安全和合法处理个人数据的主要责任。在协议或适用法律要求的情况下,我们与客户签订数据处理补充协议,以规范我们在代表客户处理个人数据方面的权利和责任。
  • 服务提供商:无论是作为数据控制者还是处理者,我们在必要或适当时使用服务提供商处理个人数据,以提供服务或进行我们的业务。当我们向代表我们处理个人信息的服务提供商或其他第三方提供个人信息时,这些服务提供商和第三方需要遵守我们的指示和合同约束,对我们处理个人信息的权利和责任进行约束。
  • GDPR独立评估:2023年,TRUSTe独立评估了Godaddy对欧盟一般数据保护条例(GDPR)的合规性,并确认Godaddy提供了证据和其他支持文件,证明其实施的计划级措施旨在满足TRUSTe的40个GDPR隐私计划确认要求。
  • 隐私保护设计:我们的数据隐私办公室还就日常隐私问题与业务团队进行咨询,从开展新业务实践的隐私影响评估(PIA)到参与新产品设计的最早阶段,以确保在产品开发过程中解决隐私问题。2023年,我们推出了一种新的技术解决方案,以简化PIA审核,更紧密地将隐私审核与工程审核整合。

Ambitions for 2024

2024年愿景。

We saw significant changes in the global privacy and cybersecurity landscape in 2023, as many jurisdictions rolled out new rules and regulations that may affect our business in the coming year. We also have seen rapid technological change as new AI and ML tools have been deployed that allow processing of personal information in new ways. In 2024, we aim to continue to adapt our privacy program and cybersecurity practices to meet evolving legal requirements and business needs in this rapidly changing environment.

我们在2023年看到全球隐私和网络安全领域发生了重大变化,许多司法管辖区推出了可能影响我们业务的新规则和法规。随着新的人工智能和机器学习工具被部署,我们还看到了快速的技术变革,这些工具允许以新的方式处理个人信息。在2024年,我们的目标是继续调整我们的隐私计划和网络安全业务,以满足这个快速变化的环境中的不断变化的法律需求和业务需求。

To learn more, read our 2023 Sustainability Report.

欲了解更多信息,请阅读我们的2023年可持续发展报告。

###

###

About this Report

关于本报告

The GoDaddy 2023 Sustainability Report details our progress toward our corporate sustainability goals, strategies, and initiatives in support of our overarching corporate mission and values. Unless otherwise noted, this report reflects our corporate sustainability performance across our global operations covering the fiscal year period from January 1 to December 31, 2023. To demonstrate our commitment to transparent communication regarding our sustainability progress, we routinely share updates through our website and our annual Sustainability Report. We welcome your questions, comments, and feedback on this report by contacting ESG@GoDaddy.com.

GoDaddy 2023可持续发展报告详细说明了我们在支持公司使命和价值观方面实现企业可持续发展目标、战略和计划的进展情况。除非另有说明,本报告反映了2023年1月1日至12月31日财年期间全球业务的企业可持续发展表现。为了展示我们对可持续发展进展的透明沟通承诺,我们定期通过我们的网站和年度可持续性报告分享更新。欢迎通过联系ESG@GoDaddy.com与我们分享您对此报告的问题、意见和反馈。

This report references the Global Reporting Initiative (GRI) Standards and includes select Sustainability Accounting Standards Board (SASB) metrics for the Internet Media and Services sector. We also disclose our contributions and progress toward priority UN SDGs. For additional information on how we align with these frameworks and key indicators demonstrating our sustainability performance, please review the Frameworks and Metrics section.

本报告参考了全球报告倡议(GRI)标准,并包括了互联网媒体和服务行业的部分可持续发展会计准则委员会(SASB)指标。我们还披露了我们对优先联合国可持续发展目标的贡献和进展情况。有关我们如何与这些框架对齐以及展示我们可持续发展表现的关键指标的更多信息,请查看《框架和指标》部分。

View additional multimedia and more ESG storytelling from GoDaddy on 3blmedia.com.

在3blmedia.com上查看来自godaddy的更多环境,社会和治理的多媒体故事。

Contact Info:
Spokesperson: GoDaddy

联系信息:
发言人:godaddy

SOURCE: GoDaddy

来源:godaddy


声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发