Compliance & Certifications
Our dedicated Information Security and Privacy teams are responsible for maintaining McAfee's compliance to a variety of laws, standards, and frameworks, including:
ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in ISO/IEC 27001:2013 are generic and are intended to be applicable to all organizations, regardless of type, size or nature.
To verify our certification, please visit:
https://www.schellman.com/certificate-directory
ISO 27701 specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS) in the form of an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management within the context of the organization.
ISO 27701 specifies PIMS-related requirements and provides guidance for PII controllers and PII processors holding responsibility and accountability for PII processing.
To verify our certification, please visit:
https://www.schellman.com/certificate-directory
ISO/IEC 27017 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:
To verify our certification, please visit:
https://www.schellman.com/certificate-directory
This document establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect Personally Identifiable Information (PII) in line with the privacy principles in ISO/IEC 29100 for the public cloud computing environment. In particular, this document specifies guidelines based on ISO/IEC 27002, taking into consideration the regulatory requirements for the protection of PII which can be applicable within the context of the information security risk environment(s) of a provider of public cloud services.
To verify our certification, please visit:
https://www.schellman.com/certificate-directory
The Payment Card Industry Data Security Standard (PCI DSS) was developed to encourage and enhance cardholder data security and facilitate the broad adoption of consistent data security measures globally. PCI DSS provides a baseline of technical and operational requirements designed to protect account data. PCI DSS applies to all entities involved in payment card processing - including merchants, processors, acquirers, issuers, and service providers. PCI DSS also applies to all other entities that store, process or transmit cardholder data (CHD) and/or sensitive authentication data (SAD).
McAfee shall publish this data twice per year (covering a reporting period of either January-to-June or July-to-December). Said reports are published six months after the end of a given reporting period in compliance with restrictions on the timing of such reports.