As industry and government regulations are increasing, you are faced with the challenge of meeting them while battling a growing number of threats. To help, Trend Micro has invested in certifications, security documentation, and company assessments that can help you better understand how we secure our offerings and protect your data.
Certifications are part of our security commitment
Centro Criptológico Nacional (CCN)
CCN is the Spanish government certification body focused on ensuring strong security across the country’s government entities. Certification under this program reflects our commitment to delivering secure products for the Spanish government market.
Mandated by the BSI, C5 (Cloud Computing Compliance Controls Catalogue) attestation enables German federal and state government entities and other highly regulated organizations to confidently leverage Trend Micro’s powerful SaaS-based security capabilities across the enterprise.
Common Criteria (CC) is an international standard for computer security certification. It provides assurance that the process of specification, implementation, and evaluation of a computer security product has been conducted in a rigorous, standard, and repeatable manner at a level that is commensurate with the target environment for use. Both Trend Micro Deep Security and Trend Micro TippingPoint have been certified under Common Criteria at the EAL2+ level.
As the leader in cloud security, the CSA Star Level 2 certification is a reflection to our commitment to secure cloud deployments. The CSA STAR Certification is a rigorous third-party independent assessment of the security of a cloud service provider.
Trend Micro offers the leading cybersecurity solution to protect endpoints, servers, and cloud workloads. Deploy security across your endpoints and physical, virtual, and multi-cloud environments to gain unified visibility, management, detection, and prevention with Trend Cloud One for Government.
Trend Micro™ Deep Security™ and Trend Micro™ TippingPoint™ provide settings that enable cryptographic modules to run in a mode compliant with FIPS 140-2 standards. We have obtained certification for our Java crypto module, Native crypto module (OpenSSL), and Trend Micro TippingPoint.
HIPAA and HITECH impose requirements related to the use and disclosure of protected health information (PHI). HIPAA regulations require that covered entities enter into agreements with business associates to ensure that PHI is adequately protected.
Certified organizations demonstrate - through continuous independent third-party security testing performed by ICSA Labs - a high standard of security product quality. Trend Micro™ Deep Discovery™ has been tested and certified by ICSA Labs.
The Information System Security Management and Assessment Program (ISMAP) is a Japanese government system for assessing the security of cloud service providers. Trend Micro cloud-based security products are assessed and certified under ISMAP as shown on the official ISMAP cloud services list. Our products and services provide comprehensive compliance assurances to help your organization comply with national, regional, and industry-specific requirements.
Ensuring quality data through our threat discovery and response teams, Trend Micro is certified under ISO/IEC 20000-1:2018. It specifies requirements for organizations to establish, implement, maintain, and continually improve service management systems (SMS).
ISO/IEC 27001:2013 is a standard focused on having an information security management system (ISMS) and security controls in place to ensure the secure operation of an offering. There are 2 extensions of the standard – ISO/IEC 27014:2020, which focuses on security governance, and extends to many other aspects of the business, and ISO/IEC 27034-1:2011, which applies to application-level security controls. Trend Micro has certified our SaaS offerings and data centers under these global standards.
Committed to security and privacy in our cloud offerings, Trend Micro is certified under ISO/IEC 27017:2015, which provides guidelines for information security controls applicable to the provision and use of cloud services.
NetSecOPEN's transparent testing methodology allows organizations to understand performance under realistic conditions. This testing of Trend Micro TippingPoint provides organizations with the confidence needed for real-world deployments.
All organisations that have access to NHS patient data and systems must use the Data Security and Protection Toolkit to publish an assessment against the National Data Guardian’s 10 data security standards. Trend Micro has completed this assessment and details can be found on the NHS site.
The Payment Card Industry Data Security Standard (PCI DSS) stipulates that any organization that deals with credit card information must secure payment card data in accordance with PCI standards. Aligned to our commitment to data privacy and security, Trend Micro Cloud One™ is a certified PCI DSS Level 1 service provider.
The Supreme Council of National Defence of Romania approves IT and security vendors for their involvement in key public infrastructure projects. Trend Micro has completed this assessment and is authorized to participate.
SOC 2 Type II
As an example of transparency and security, Trend Micro has undergone a SOC 2 Type II audit, which outlines the internal controls we use to safeguard customer data and how well those controls are operating.
Waste Electrical and Electronic Equipment (WEEE) Directive
Trend Micro is committed to complying with the directive, which places responsibilities on producers and distributors of Electrical and Electronic Equipment (“EEE”) and batteries regarding the collection, treatment, recovery, and environmentally sound disposal of EEE and batteries at their end of life.