Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Uncategorized

Android Enterprise Receives ISO 27001 Stamp

Google this week has revealed that Android Enterprise has received ISO 27001 security certification. 

Google this week has revealed that Android Enterprise has received ISO 27001 security certification. 

Designed to provide features that allow IT teams to keep corporate and personal data secure using flexible tools, Android Enterprise is tailored specifically for businesses. The program ensures that best practices and common requirements are followed, making Android ready for use within organizations.

The recently received ISO 27001 certification, Google says, proves that Android Enterprise information security practices and procedures, which target Android Management API, zero-touch enrollment and managed Google Play, are in line with industry standards for security and privacy.

“Sound privacy, data security, organizational policy and practices are essential to gaining user trust. The ISO 27001 certification and SOC 2 and 3 reports confirm Google’s information security practices so that IT admins, users and other stakeholders have confidence about Android Enterprise security practices,” the company notes

ISO 27001, which is granted by the International Organization for Standardization, describes the requirements for an information security management system, presenting best practices, along with a list of security controls regarding information risk management.

There are more than a dozen standards in the 27000 family, but “ISO/IEC 27001 is the best-known standard in the family providing requirements for an information security management system (ISMS),” the International Organization for Standardization says.

Based on American Institute of Certified Public Accountants (AICPA) Trust Services principles and criteria, the SOC 2 and 3 reports include assessments of the security, availability, processing integrity and confidentiality or privacy of an organization’s information systems. 

According to Google, the certification is only received after an independent assessor performs a thorough audit, reviewing the methodology of documentation and procedures for data management.

Advertisement. Scroll to continue reading.

“Android is invested in a wide range of protections and management tools to help companies secure their data. This external validation, together with our ongoing efforts, is a testament to how Android Enterprise meets the highest privacy and security needs of today’s businesses,” Google concludes. 

Related: Monthly Patches Are Recommended Best Practice for Android, Google Says

Related: Android Q Brings New Privacy and Security Features

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Management & Strategy

Anna Tutt, CMO of Oort, shares her experiences and perspectives on how we can accelerate growth of women in cybersecurity.

CISO Conversations

SecurityWeek talks to legal sector CISOs Alyssa Miller at Epiq and Mark Walmsley at Freshfields Bruckhaus Deringer

Ransomware

A new CISA pilot program to warn critical infrastructure organizations if their systems are unpatched against vulnerabilities exploited in ransomware attacks.

Cyberwarfare

The UK’s NCSC has issued a security advisory to warn about spearphishing campaigns conducted by two unrelated Russian and Iranian hacker groups.

Cybersecurity Funding

Silk Security raised $12.5 million in seed funding and is on a mission to break down the silos between security and development with an...

Uncategorized

Exploitation of a critical vulnerability (CVE-2023-46747) in F5’s  BIG-IP product started less than five days after public disclosure and PoC exploit code was published.

Cybersecurity Funding

B2B payment security provider NsKnox raised $17 million in a new funding round that brings the total raised by the company to $35.6 million.

Application Security

NSA has published guidance to help organizations incorporate SBOM to mitigate supply chain risks.