What Standards and Regulations Does wolkvox Follow to Ensure Information Security?
Table of Contents
Description
wolkvox adopts a comprehensive approach to information security, based on international standards and industry-recognized frameworks. The company has an Information Security Management System (ISMS) certified under the ISO/IEC 27001 standard, which establishes the necessary controls to protect the confidentiality, integrity, and availability of information.
Additionally, wolkvox ensures compliance with the PCI-DSS standard for card payment processing environments, guaranteeing secure transactions. As part of its infrastructure, Google Cloud Platform (GCP)—its cloud service provider—also follows a compliance strategy aligned with the industry's most demanding frameworks and standards, reinforcing security at all levels.
Features
Key Standards and Certifications
- ISO/IEC 27001: Certification that validates wolkvox’s ISMS, ensuring that information security management meets the most rigorous international requirements.
- PCI-DSS: Full compliance for card payment processing environments, guaranteeing secure financial transactions and protection of sensitive data.
- GDPR: Although not a certification, wolkvox aligns its practices with the General Data Protection Regulation (GDPR) for clients in the European Union, ensuring proper handling of personal data.
Alignment with Google Cloud Platform (GCP)
-
GCP Compliance: Google Cloud Platform complies with a wide range of standards and certifications, including:
- SO 27001, SOC 2/3, HIPAA, FedRAMP, among others.
- More details at: https://cloud.google.com/compliance and https://cloud.google.com/security?hl=es-419
- Integrated security: GCP provides advanced security controls such as default encryption, identity and access management (IAM), and threat protection, which wolkvox leverages to strengthen its infrastructure.
Frameworks and Best Practices
- OWASP Top 10: wolkvox follows OWASP recommendations to mitigate common vulnerabilities in web applications.
- NIST (National Institute of Standards and Technology): Guidelines from NIST are adopted for risk management and implementation of security controls.
- CIS Benchmarks: Secure configurations based on CIS Benchmarks for servers, networks, and operating systems.