Cloudera Powers the Agentic AI Era with Cloudera Anywhere Cloud™

Read the press release

Our commitment to security compliance

We build a secure, compliant environment for your business by:


Standardizing: Maintaining certifications against the industry’s most rigorous standards.


Governing: Enforcing policies built on global best practices and regulatory requirements.


Validating: Conducting continuous audits and risk assessments to proactively address emerging threats.

Certifications

We validate our security posture through independent third-party audits and certifications. This approach ensures proactive threat management and helps you meet critical security and privacy requirements.

SOC2
SOC2

SOC 2, developed by AICPA, assesses the information security controls of service providers to manage risks in outsourced services handling customer data. The SOC 2 Attestation may be requested here.

ISO
ISO/IEC 27001:2022

ISO/IEC 27001 outlines requirements for creating, maintaining, and improving an ISMS to help organizations secure their information assets. The ISO Certification may be requested here.

PCI DSS Compliant
PCI 4.0

Payment Card Industry (PCI) provides standards to protect cardholder data. Companies that accept, store, transmit, or affect the security of the cardholder environment must comply with PCI standards. The PCI DSS Attestation of Compliance (AOC) may be requested here.

FedRAMP
FedRAMP 

FedRAMP sets security standards for cloud products used by U.S. government agencies. Cloudera maintains a FedRAMP Moderate authorization for its Cloudera for Government offering. You can find us on the FedRAMP Market Place here.

CyberEssentials
CyberEssentials+ 

CyberEssentials+ provides a strong baseline for cybersecurity for organizations in the UK. The CyberEssentials certificate may be requested here

 

GovRAMP
GovRAMP

GovRAMP establishes security standards for cloud solutions used by state and local governments. You can find us on the GovRAMP Authorized Product List here.

ENS Esquema Nacional de Sequridad
ENS

The ENS (Esquema Nacional de Seguridad) defines the mandatory security standards for cloud services utilized by Spanish public administrations. The ENS Certificate may be requested here.

Tisax

TISAX

TISAX is an assessment and exchange mechanism established by the German Association of the Automotive Industry (VDA) for evaluating information security against the VDA Information Security Assessment (ISA). More information may be found here.

 

Regulatory  Compliance

Cloudera maintains industry-standard measures to comply with applicable global laws, rules and regulations, including GDPR. Our products and services are designed with features that help customers meet their own legal and compliance obligations. For information about Cloudera’s data practices, see our Privacy Statement and Product & Service Data Policy.

 

Risk management

By implementing risk management processes, organizations can mitigate potential risks by addressing them before they escalate into significant issues.

Cloudera risk management program:
A proactive approach

Cloudera’s comprehensive risk management program is designed to effectively manage risks to our organization’s valuable assets. This program enables us to ensure business continuity despite the potential threats facing us. We use an integrated control and risk framework to provide a structured approach to our risk management process and to provide awareness about risk management across the organization. More information on our risk management process can be found within our Risk Management Policy.

Key benefits


Asset  protection.  Ensuring the integrity of our systems and security of sensitive data.


Customer  trust. Building confidence in our organization through our security focus.


Regulatory  compliance. Adhering to regulatory requirements to build trust and reliability.


Organizational  resilience. Adapting quickly to the changes in the threat landscape.


Enhanced  risk  awareness. Promoting engagement with teams across the organization.


Continuous  improvement. Enhancing current risk strategies on an ongoing basis.

Cloudera risk management process overview

Cloudera’s risk management process contains several steps from the identification of risks to the continuous monitoring of the risks within the organization.

Risk Management Process

 The steps include:

1. Risk identification: Noting any internal or external risks that could potentially impact Cloudera is the first step of the risk management process. Identified risks are documented in a centralized risk register.
 

2. Risk assessment/analysis: Using qualitative and quantitative analysis, Cloudera reviews each risk found during the risk identification phase to determine the likelihood that the risk will be realized and the severity of impact. Risks are prioritized based on the outcome of this analysis.

Intake criteria includes:

  • Probability of occurrence

  • Financial impact

  • Reputational impact

  • Legal / regulatory impact

  • Customers in scope

  • Operational impact

3. Risk mitigation: During the mitigation phase, Cloudera teams develop strategies to reduce the probability of risks and their impacts.  Risk mitigation involves introducing or modifying security controls.
 

4. Implementation/treating the risk: Risk Treatment strategy is used for those risks that are above the acceptable risk threshold. A risk treatment plan is created which includes assigning responsibilities and allocating resources to ensure effective execution of these strategies.
 

5. Monitoring and review: Regular monitoring and review of the risks is an ongoing process in which Cloudera evaluates the effectiveness of the risk management methods that have been established. Ultimately, the goal is to ensure that the risk management plan remains relevant despite changes to internal and external factors.

Using your phone to for extra security

Third-party risk management

A key component to our risk management program is our risk assessment of third-party vendors. Cloudera provides:

  • Fourth-party monitoring for critical vendors

  • Continuous security score monitoring in accordance with NIST 800-53 rev. 5

  • Annual screening / vendor reviews, and confirmation prior to renewal

     

Legal

Cloudera ensures customer privacy by complying with legal compliance regulations.

GDPR


The European Union General Data Protection Regulation (GDPR) is a comprehensive data  privacy and security law that protects personal data of individuals in the European Union (EU) or European Economic Area (EEA). Substantial fines are issued against those who violate its privacy and security standards.

CCPA


California Consumer Privacy Act (CCPA) is a set of regulations that protect the data privacy rights of California residents.

Ready to Get Started?

Your form submission has failed.

This may have been caused by one of the following:

  • Your request timed out
  • A plugin/browser extension blocked the submission. If you have an ad blocking plugin please disable it and close this message to reload the page.