share_log

GoDaddy 2023 Sustainability Report: Our Operations | Cybersecurity and Data Privacy

GoDaddy 2023 Sustainability Report: Our Operations | Cybersecurity and Data Privacy

godaddy 2023可持續性報告:我們的運營|網絡安全概念與數據隱私
Accesswire ·  06/25 10:15

NORTHAMPTON, MA / ACCESSWIRE / June 25, 2024 / GoDaddy

馬薩諸塞州北安普敦/ACCESSWIRE /2024年6月25日/GoDaddy

Originally published in GoDaddy's 2023 Sustainability Report

最初發布在 GoDaddy 的 2023 年可持續發展報告中

Cybersecurity and Data Privacy

網絡安全和數據隱私

Cybersecurity and data privacy are a top priority for GoDaddy as an operator of large internet infrastructure. We take our commitment to cybersecurity and data privacy seriously. We maintain enterprise-wide cybersecurity and data privacy programs designed to manage the risks to GoDaddy's information systems, customer data, and personal information of our customers and employees from cyber threats, and to comply with our regulatory obligations.

作爲大型互聯網基礎設施運營商,網絡安全和數據隱私是GoDaddy的重中之重。我們認真對待我們對網絡安全和數據隱私的承諾。我們維護企業範圍內的網絡安全和數據隱私計劃,旨在管理 GoDaddy 的信息系統、客戶數據以及客戶和員工的個人信息遭受網絡威脅的風險,並遵守我們的監管義務。

Our approach to management of cybersecurity risk and data privacy obligations includes:

我們的網絡安全風險和數據隱私義務管理方法包括:

  • Board Oversight: Our Board oversees the company's cybersecurity risk management program through its Audit and Finance Committee. The Audit and Finance Committee receives regular reports from GoDaddy's Chief Information Security Officer (CISO) regarding the state of the company's cybersecurity program. These reports are shared, at least quarterly, with the Board of Directors. In addition, our Corporate Audit Services team audits our privacy practices, and the results of those audits are presented to senior leadership and discussed with the Audit and Finance Committee. Updates on privacy and cybersecurity matters are also included as part of the Audit and Finance Committee's review of the Company's enterprise risk management efforts.
  • Cybersecurity Risk Management: Our management is responsible for identifying, assessing, and managing the company's material cybersecurity risks on an ongoing basis; establishing processes designed to help ensure that potential cybersecurity risk exposures are monitored; putting in place appropriate mitigation and remediation measures; and maintaining the company's cybersecurity programs. GoDaddy's CISO has primary responsibility for the company's programs for identifying, assessing, and managing the company's cybersecurity risks. The CISO reports directly to the company's Chief Technology Officer and regularly provides reports and updates to the company's Chief Executive Officer on significant cybersecurity-related matters relevant to the company's cybersecurity risk.
  • Privacy Program Management: Our Privacy Officer manages our Data Privacy Office and global privacy program. Our Data Privacy Office is responsible for day-to-day operations of our privacy program, including but not limited to conducting privacy impact assessments, providing training to employees, responding to data subject requests, and responding to inquiries from data protection authorities. Other personnel and departments at GoDaddy also assist the Data Privacy Office, including but not limited to the company's Legal and Information Security teams.
  • 董事會監督:我們的董事會通過其審計和財務委員會監督公司的網絡安全風險管理計劃。審計和財務委員會定期收到 GoDaddy 首席信息安全官 (CISO) 關於公司網絡安全計劃狀況的報告。這些報告至少每季度與董事會共享一次。此外,我們的企業審計服務團隊會審核我們的隱私慣例,並將這些審計的結果提交給高級領導層,並與審計和財務委員會進行討論。作爲審計和財務委員會對公司企業風險管理工作的審查的一部分,隱私和網絡安全問題的最新情況也包括在內。
  • 網絡安全風險管理:我們的管理層負責識別、評估和持續管理公司的重大網絡安全風險;建立旨在幫助確保監控潛在網絡安全風險暴露的流程;制定適當的緩解和補救措施;維護公司的網絡安全計劃。GoDaddy 的首席信息安全官主要負責公司識別、評估和管理公司網絡安全風險的計劃。首席信息安全官直接向公司首席技術官報告,並定期向公司首席執行官提供與公司網絡安全風險相關的重大網絡安全相關事項的報告和最新情況。
  • 隱私計劃管理:我們的隱私官管理我們的數據隱私辦公室和全球隱私計劃。我們的數據隱私辦公室負責我們隱私計劃的日常運營,包括但不限於進行隱私影響評估、爲員工提供培訓、回應數據主體請求以及回應數據保護機構的詢問。GoDaddy的其他人員和部門也爲數據隱私辦公室提供協助,包括但不限於公司的法律和信息安全團隊。

Cybersecurity

網絡安全

We're committed to protecting customer information from cybersecurity threats. Our information security team uses a variety of controls to protect our systems and customer information from cybersecurity threats. Some of their efforts include:

我們致力於保護客戶信息免受網絡安全威脅。我們的信息安全團隊使用各種控制措施來保護我們的系統和客戶信息免受網絡安全威脅。他們的一些努力包括:

  • Proactive Monitoring and Assessment: We use monitoring and detection tools designed to identify and mitigate threats before they impact GoDaddy or our customers. We also regularly scan our environment to identify potential vulnerabilities.
  • Security by Design: Our developers are encouraged to consider cybersecurity from the initial design phase of our products to completion. We also have designed and implemented risk-based processes and procedures to conduct security reviews on new or updated applications prior to launch.
  • Security Frameworks: Some parts of our business are required to align with specialized frameworks, such as the Payment Card Industry Data Security Standards (PCI-DSS) for handling payment card data. Where required by our customer or other agreements, we align our practices and controls with other recognized standards such as International Organization for Standardization (ISO) 27001.
  • Incident Response: We have a dedicated incident response team that works with our business units and other internal and external subject matter experts to respond to potential cybersecurity incidents. In 2023, we updated our policies and procedures for reporting cybersecurity threats internally to strengthen our overall response capabilities.
  • 主動監控和評估:我們使用監控和檢測工具,旨在在威脅影響 GoDaddy 或我們的客戶之前識別和緩解威脅。我們還定期掃描我們的環境以識別潛在的漏洞。
  • 安全源於設計:鼓勵我們的開發人員從產品的初始設計階段到完成階段都考慮網絡安全。我們還設計並實施了基於風險的流程和程序,以便在發佈之前對新的或更新的應用程序進行安全審查。
  • 安全框架:我們業務的某些部分需要與專門的框架保持一致,例如用於處理支付卡數據的支付卡行業數據安全標準 (PCI-DSS)。根據客戶或其他協議的要求,我們會使我們的做法和控制措施與國際標準化組織 (ISO) 27001 等其他公認標準保持一致。
  • 事件響應:我們有一個專門的事件響應小組,與我們的業務部門和其他內部和外部主題專家合作,應對潛在的網絡安全事件。2023 年,我們更新了內部報告網絡安全威脅的政策和程序,以加強我們的整體應對能力。

Employee Training and Education

員工培訓和教育

GoDaddy employees receive annual data security and privacy training through our Do The Right Thing (DTRT) compliance training. We also send alerts to employees to keep them updated on the latest security threats and host regular workshops for specific teams on privacy topics.

GoDaddy 員工通過我們的 “做正確的事” (DTRT) 合規性培訓每年接受數據安全和隱私培訓。我們還向員工發送警報,讓他們隨時了解最新的安全威脅,並定期爲特定團隊舉辦有關隱私主題的研討會。

Data Privacy

數據隱私

We take a proactive approach to managing our data privacy obligations. Some of our efforts include:

我們採取積極的方法來管理我們的數據隱私義務。我們的一些努力包括:

Establishing Core Data Privacy Practices: We empower our customers, employees, and individual data subjects to manage their privacy preferences and exercise their privacy rights when visiting our websites, using our services, communicating with us, or working with us. Our core privacy practices are set forth in our Global Privacy Notice and related privacy policies. We apply our core practices to all individuals with whom we interact.

制定核心數據隱私慣例:我們授權客戶、員工和個人數據主體在訪問我們的網站、使用我們的服務、與我們通信或與我們合作時管理他們的隱私偏好並行使他們的隱私權。我們的核心隱私慣例載於我們的全球隱私聲明和相關的隱私政策。我們將我們的核心實踐應用於與之互動的所有個人。

Global Regulatory Compliance: While we maintain a global privacy program where we apply a core set of common principles to how we handle personal data, we are mindful of local requirements and restrictions in many of the jurisdictions where we do business and have developed jurisdiction specific data privacy notices for the United States, the United Kingdom, and the European Union. From time to time, we have also adjusted our privacy practices to meet local requirements in other jurisdictions where we do business. We also follow jurisdiction-specific privacy practices relating to handling of personal data relating to our employees and job applicants.

全球監管合規:雖然我們維持全球隱私計劃,在處理個人數據時運用一套核心的共同原則,但我們會注意我們開展業務的許多司法管轄區的當地要求和限制,並針對美國、英國和歐盟制定了針對特定司法管轄區的數據隱私聲明。我們還不時調整我們的隱私慣例,以滿足我們開展業務的其他司法管轄區的當地要求。在處理與員工和求職者相關的個人數據方面,我們還遵循特定司法管轄區的隱私慣例。

International Data Transfers: In 2023, the U.S. and E.U. reached agreement on a new framework to allow lawful transfers of personal data from Europe to the United States (the "U.S.-E.U. Data Privacy Framework"). GoDaddy certified its compliance with this framework, as well as its compliance with the U.S. and U.K. extension to the U.S.- E.U. Data Privacy Framework. Where the Data Privacy Framework does not apply to transfers from the U.K. and E.U., we use other recognized transfer mechanisms, including standard contractual clauses.

國際數據傳輸:2023年,美國和歐盟就新框架達成協議,允許將個人數據從歐洲合法傳輸到美國(“U.S-EU.數據隱私框架”)。GoDaddy 認證其符合該框架,並符合美國和英國對美歐數據隱私框架的擴展。如果數據隱私框架不適用於來自英國和歐盟的轉賬,我們會使用其他公認的傳輸機制,包括標準合同條款。

  • Data Processing Agreements: In addition to our responsibilities for handling the personal data of our customers, employees, and other data subjects with whom we interact directly, we also handle personal data on behalf of our customers. In this capacity, we act as a data processor, and our customers retain primary responsibility for safely and lawfully processing personal data. Where required by our agreements or applicable laws, we enter into data processing addendums that regulate our rights and responsibilities for processing personal data on behalf of our customers.
  • Service Providers: Whether acting as a data controller or processor, we use service providers to process personal data when necessary or appropriate to provide our services or conduct our business. When we provide personal data to a service provider or other third-party acting on our behalf, those service providers and third parties are required to comply with our instructions and contractual restrictions in processing personal information on our behalf.
  • GDPR Independent Assessment: In 2023, TRUSTe independently assessed GoDaddy's compliance with the EU General Data Protection Regulation (GDPR) and validated that GoDaddy provided evidence and other support showing that it implemented program-level measures that are designed to meet TRUSTe's 40 GDPR Privacy Program Validation Requirements.
  • Privacy by Design: Our Data Privacy Office also consults with our business teams on day-to-day privacy issues, ranging from conducting privacy impact assessments (PIAs) on new business practices to participating in the earliest phases of new product designs to ensure that privacy concerns are addressed during product development. In 2023, we rolled out a new technical solution to streamline the PIA review and more closely integrate privacy reviews with engineering reviews.
  • 數據處理協議:除了我們負責處理客戶、員工和與我們直接互動的其他數據主體的個人數據外,我們還代表客戶處理個人數據。以這種身份,我們充當數據處理者,我們的客戶對安全和合法地處理個人數據負有主要責任。根據我們的協議或適用法律的要求,我們會訂立數據處理附錄,規範我們代表客戶處理個人數據的權利和責任。
  • 服務提供商:無論是作爲數據控制者還是處理者,我們都會在必要或適當時使用服務提供商來處理個人數據,以提供我們的服務或開展我們的業務。當我們向服務提供商或其他代表我們行事的第三方提供個人數據時,這些服務提供商和第三方在代表我們處理個人信息時必須遵守我們的指示和合同限制。
  • GDPR 獨立評估:2023 年,TRUSTe 獨立評估了 GoDaddy 對歐盟《通用數據保護條例》(GDPR) 的遵守情況,並驗證了 GoDaddy 提供的證據和其他支持,表明其實施了旨在滿足 TRUSTe 的 40 項 GDPR 隱私計劃驗證要求的計劃級措施。
  • 通過設計保護隱私:我們的數據隱私辦公室還就日常隱私問題與我們的業務團隊進行磋商,從對新業務實踐進行隱私影響評估(PIA)到參與新產品設計的最初階段,以確保在產品開發期間解決隱私問題。2023 年,我們推出了一項新的技術解決方案,以簡化 PIA 審查,並將隱私審查與工程審查更緊密地結合在一起。

Ambitions for 2024

2024 年的雄心壯志

We saw significant changes in the global privacy and cybersecurity landscape in 2023, as many jurisdictions rolled out new rules and regulations that may affect our business in the coming year. We also have seen rapid technological change as new AI and ML tools have been deployed that allow processing of personal information in new ways. In 2024, we aim to continue to adapt our privacy program and cybersecurity practices to meet evolving legal requirements and business needs in this rapidly changing environment.

我們看到了2023年全球隱私和網絡安全格局的重大變化,因爲許多司法管轄區推出了新的規章制度,這些規章制度可能會在來年影響我們的業務。隨着新的人工智能和機器學習工具的部署,我們也看到了快速的技術變革,這些工具允許以新的方式處理個人信息。2024年,我們的目標是繼續調整我們的隱私計劃和網絡安全慣例,以滿足這個瞬息萬變的環境中不斷變化的法律要求和業務需求。

To learn more, read our 2023 Sustainability Report.

要了解更多信息,請閱讀我們的 2023 年可持續發展報告。

###

###

About this Report

關於本報告

The GoDaddy 2023 Sustainability Report details our progress toward our corporate sustainability goals, strategies, and initiatives in support of our overarching corporate mission and values. Unless otherwise noted, this report reflects our corporate sustainability performance across our global operations covering the fiscal year period from January 1 to December 31, 2023. To demonstrate our commitment to transparent communication regarding our sustainability progress, we routinely share updates through our website and our annual Sustainability Report. We welcome your questions, comments, and feedback on this report by contacting ESG@GoDaddy.com.

GoDaddy 2023 年可持續發展報告詳細介紹了我們在實現企業可持續發展目標、戰略和舉措方面取得的進展,以支持我們的總體企業使命和價值觀。除非另有說明,否則本報告反映了我們在2023年1月1日至12月31日財年期間全球業務中的企業可持續發展表現。爲了表明我們致力於就可持續發展進展進行透明的溝通,我們定期通過我們的網站和年度可持續發展報告分享最新情況。歡迎您聯繫 ESG@GoDaddy.com 對本報告提出問題、評論和反饋。

This report references the Global Reporting Initiative (GRI) Standards and includes select Sustainability Accounting Standards Board (SASB) metrics for the Internet Media and Services sector. We also disclose our contributions and progress toward priority UN SDGs. For additional information on how we align with these frameworks and key indicators demonstrating our sustainability performance, please review the Frameworks and Metrics section.

本報告引用了全球報告倡議(GRI)標準,幷包括可持續發展會計準則委員會(SASB)針對互聯網媒體和服務領域的特定指標。我們還披露了我們在聯合國優先可持續發展目標方面的貢獻和進展。有關我們如何與這些框架保持一致的更多信息,以及證明我們可持續發展績效的關鍵指標,請查看 “框架和指標” 部分。

View additional multimedia and more ESG storytelling from GoDaddy on 3blmedia.com.

在 3blmedia.com 上查看 GoDaddy 提供的更多多媒體和更多 ESG 故事。

Contact Info:
Spokesperson: GoDaddy

聯繫信息:
發言人:GoDaddy

SOURCE: GoDaddy

資料來源:GoDaddy


声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論