Workplace is now certified to ISO 27018 security standard

Workplace is now certified to the ISO/IEC 27018:2014 standard. Here's what that means for you and your organization.

BUSINESS COMMUNICATION | 10 MINUTE READ
iso 27018 certification - Workplace from Meta

Workplace is now certified to the ISO/IEC 27018:2014 standard. Here's what that means for you and your organization.

Workplace takes your security seriously. In fact, every decision we make involves understanding how a new product or process could affect information privacy and security for our customers. And although Workplace already exceeds the industry standard for protecting your data, we know there's always more to do.

That's why we're pleased to announce that Workplace by Facebook is now certified to ISO/IEC 27018:2014 security standard.

What is ISO 27018?

What is ISO 27018?

ISO 27018 is a privacy focused international standard that builds on information security management systems. It establishes commonly accepted controls and guidelines to protect Personally Identifiable Information (PII) in public cloud computing environments.

Here's an overview of some of the key ISO 27018 requirements:

• Providing customers the ability to access, correct, and erase their PII
• Ensuring data processing for its intended purpose only
• Implementing defined disclosure procedures
• Providing open, transparent notice when cloud service providers use sub-contractors
• Encouraging accountability via breach notification procedures
• More stringent information security requirements for cloud service providers

What does this mean for you?

What does this mean for you?

We achieved ISO 27001 accreditation in October 2017. This ensures the confidentiality, integrity, and availability of information that organizations control and process. ISO 27001 also applies a risk management process so organizations can manage risk.

With ISO 27018, we wanted to further improve how we align our security controls to match with the needs and expectations of customers.

All of which means that you now have more control over your PII and visibility on how we use it. The ISO 27018 certification also gives our customers more assurance about how we process their data according to the very highest industry standards.

By following the standards of ISO/IEC 27001 and the code of practice embodied in ISO/IEC 27018, Workplace demonstrates that our privacy policies and procedures are robust and in line with its high standards.

The audit process

The audit process

Our audit for compliance with ISO/IEC 27018 was completed by an accredited third party certification body. They provided independent validation that applicable security controls are in place and operating effectively. As part of this compliance verification process, the auditors validate that Workplace by Facebook has incorporated ISO/IEC 27018 controls for the protection of PII in Workplace.

And it's an ongoing process. We'll also have third-party reviews every year to remain certified.

Serious about security

Serious about security

We're very proud to serve millions of users and thousands of companies including Chevron, Vodafone, GSK, AstraZeneca, Walmart, Booking.com, and Kering. We continue to invest heavily in security and we're delighted to achieve this latest milestone. It's a certification we believe shows our commitment to protecting your information and that reinforces our focus on maintaining industry-leading security programs and practices.

To find out more about the levels of security you can expect from Workplace take a look at the website or view the ISO 27018 certificate .

Work tools that change everything. See for yourself and try Workplace free for 90 days.

Let's Stay Connected

Get the latest news and insights from the frontline of work.

By submitting this form, you agree to receive marketing-related electronic communications from Facebook, including news, events, updates and promotional emails. You may withdraw your consent and unsubscribe from such emails at any time. You also acknowledge that you have read and agree to the Workplace Privacy terms.

Was this article helpful?
သင့်သဘောထားမှတ်ချက်အတွက် ကျေးဇူးတင်ပါတယ်

Recent posts

Business Communication | 10 minute read

Netskope CEO Sanjay Beri: Why the best CIOs are brokers, not blockers

Netskope CEO Sanjay Beri talks technology, security, and why the words you’re most likely to hear from today's CIO are ‘yes – but’ rather than ‘no’.

Business Communication | 10 minute read

Why Workplace is empowering a new generation of CIOs

We speak to Facebook’s CIO, Atish Baerjea, to learn how the CIO role is changing and how Workplace can empower them.