投影片放映

保護個人資料

對我們而言至關重要,我們在每個環節都確保安全與保障。

摘要

Withings Security Insurance Plan relates exclusively to Withings' activities with professionals. Please refer to our privacy policy for information on security measures designed to secure individual user data.

資料安全

Withings 致力於維護安全的環境,讓您能夠使用我們的產品和服務。我們透過遵循多項標準(ISO 27001:2022、ISO 27701:2019 及 HDS)來保護您的個人資料。

認證與標準

為將資料隱私納入我們的產品和服務,我們致力於達到個人資料保護的最高標準。

HDS

Health Data Hosting — version 1.1 final - May 2018 for activities 1 to 6 in accordance with the certification reference system provided by ASIP Santé.

Includes all systems, people and processes involved in the design, development, operations, validation and support of applications and services hosted by Withings which include the processing or disclosure of personal health data.

The certification referential includes: NF ISO/IEC 27001:2017, ISO/IEC 27018:2014, NF ISO/IEC 20000-1:2011, as well as additional requirements.

In accordance with the HDS reference system, you can consult the table of representations of guarantees concerning our activities as a subcontractor via this link.

Download certificate

ISO 27001:2022

Withings provides the service of a hosting provider in accordance with the requirements of the International Organization for Standardization 27001:2022 standards.

It includes all systems, people and processes involved in the design, development, operations, validation and support of applications and services hosted by Withings and especially the processing of personal health data.

In accordance with the HDS reference system, you can consult the table of representations of guarantees concerning our activities as a subcontractor via this link.

Download certificate

ISO 27701:2019

Withings demonstrates its capacity to follow the state of the art in terms of Privacy protection worldwide (such as GDPR). In order to do so, internal processes are continuously audited to ensure that Privacy protection is taken into account at each step of activities (internal or external) conducted by Withings.

Download certificate

服務與應用程式安全

我們在應用程式、服務和產品的整個生命週期各階段,提供、維護並管理資料保護。

框架安全控制

Withings 採用現代安全控制技術,以限制對 OWASP 十大安全風險的暴露。這些內建控制措施降低了我們對 SQL 注入(SQLi)、跨站腳本攻擊(XSS)及跨站請求偽造(CSRF)等威脅的暴露風險。

敏捷組織、程式碼審查與測試

所有開發活動均採用敏捷方法組織,與產品管理團隊共同建立衝刺並確定任務優先順序。所有衝刺均留有歷史紀錄。開發人員將執行單元測試、功能整合測試及安全測試。功能在部署前須經安全團隊審查,並透過同儕審查進行評估。

軟體品質保證

軟體品質保證部門在投入生產前對服務和應用程式進行測試(手動及自動測試)。

環境隔離與測試資料

開發和測試環境在邏輯上與生產環境分離。我們的開發或測試環境中不使用任何個人生產資料。

基礎設施保護

由於資料保護是我們照顧用戶的一部分,我們採用最優質的安全解決方案來保護個人資料。

實體設施

針對歐洲的 B2C 及 B2B 業務,Withings 透過 BSO 將伺服器託管於位於法國的資料中心。為確保全天候 24/7 運作及服務持續可用,BSO 資料中心配備了備援電力系統並實施環境管控。

針對美國的 B2B 業務,Withings 透過 GCP 將伺服器託管於位於美國的資料中心。為確保全天候 24/7 運作及服務持續可用,Google 資料中心配備了備援電力系統並實施環境管控。

現場安全

BSO 與 GCP 資料中心採用多層安全模型設計,包括客製化電子門禁卡、警報系統、車輛進出管制閘、安全圍欄、金屬探測器及生物辨識技術。每個資料中心還配備雷射光束入侵偵測系統。資料中心全天候 24 小時、每週 7 天透過高解析度室內外攝影機進行監控,可偵測並追蹤入侵者。

資料託管位置

應客戶要求,客戶可要求將其資料處理區域化至 MED·PRO 服務的可用位置。Withings 尊重客戶的選擇,並在一項或多項服務無法區域化時通知客戶。

人力資源安全

負責處理 Withings Cloud 中資料的少數員工須接受定期審查,並持續接受如何降低個人資料處理風險的培訓。-

背景與能力查核

Withings 依據當地法律對所有新進員工進行背景調查,此調查同樣適用於承包商。背景調查可能包括技術與一般技能、過往工作經歷,以及在必要時的犯罪紀錄查核。

保密協議

所有員工必須簽署保密協議。該保密協議在勞動合約終止後仍然有效。

角色與職責定義

Withings 確保所有角色和職責均有明確定義,並為相關負責人員所理解。

紀律處分程序

Withings 已依據內部規定中的懲戒等級,針對違反受託職責的情形制定紀律處分程序。

持續改進

作為一家創新的物聯網公司,我們確保始終領先於當前的資料保護標準一步。這得益於定期的內部和外部稽核支持。

內部稽核計劃

所有流程均由內部稽核團隊或外部服務提供商進行稽核。

管理層審查

管理層審查確保管理層系統性地審視 ISMS,評估改進機會,並決定確保 ISMS 相關性、適當性和有效性所需的措施。