Application and Infrastructure Control |
- JFrog’s Cyber Incident Response Team (CIRT) constantly monitors our products, infrastructure operations and security solutions. JFrog’s security team has established a comprehensive strategy and policies to respond, notify, and remediate security incidents promptly and efficiently.
- JFrog’s CIRT continuously monitors our products’ logs, infrastructure operations and systems audit logs in our internal Security Information and Event Management (SIEM) to detect potential incidents promptly and efficiently. As part of this ongoing effort, the CIRT investigates and responds to reports from bug bounty programs, vulnerability disclosure programs, automated scanners, customer support portal and dedicated email inbox.
- To ensure prompt and efficient response time, our Security Operations Center (SOC) is staffed with highly qualified and experienced security experts, who work to fulfill our internal SLA policy.
|
Internal Controls |
- JFrog has defined access roles for each system and service based on least privilege principle. Access to all our applications is possible only via Single Sign-on (SSO) and 2-factor authentication (2FA) with strong password policies.
- JFrog requires that its employees use a password manager to ensure that they use unique and complex passwords and store them in a secure vault.
- JFrog uses a zero-trust solution to securely connect our employees, devices, and apps over JFrog’s internal network. Our zero-trust solution provides Web and URL filtering, sandboxing, cloud firewall, CASB and DLP.
- JFrog engineers connect to our production resources using an advanced 2FA and just-in-time access solution, which allows us to employ the principle of least privilege and conduct a full audit.
- JFrog laptops are equipped with encryption technology that is turned on by default, along with advanced anti-malware software.
- JFrog uses email protection solutions designed to prevent malware, zero-day attacks, phishing, Business Email Compromise (BEC), spam and N-days.
- JFrog employees receive mandatory data protection and cyber security awareness training as part of their onboarding, as well as ongoing training thereafter. Moreover, employees receive ongoing security education training about topics such as phishing, password management, secure development, and security best practices for operating cloud accounts.
|
Security Events |
- JFrog’s CIRT works with external incident response experts to assist us with emergency security incidents. As part of our comprehensive vulnerability management process, JFrog’s CIRT runs continuous and automated vulnerability scans of all our assets; prioritizes vulnerability fixes and releases patches quickly.
|
Standards |
- JFrog is certified under ISO 27001, the global standard for IT security management policies. ISO 27001 is a framework for Information Security Management Systems (ISMS) that enables the continued confidentiality, integrity and availability of information, which includes people, processes, and IT systems, its objective is to provide requirements for establishing, implementing, maintaining, and continuously improving an ISMS.
- JFrog is certified under ISO 27701, the data privacy extension to ISO 27001/2. This Privacy Information Management System (PIMS) outlines a framework for Personally Identifiable Information (PII) Controllers and PII Processors to manage privacy controls and to reduce the risk to the privacy rights of individuals.
- JFrog engages Ernst & Young to audit its system and organization controls report – SOC 2 Type II Report. This auditing procedure ensures we securely manage and protect our customer’s data. This Report is validated and updated annually and is a key document that outlines and certifies the ways in which JFrog achieves and maintains compliance and control objectives.
|