Security & Compliance
Fiserv's Electronic Document Delivery solution provides comprehensive risk management for our clients in many industries. Our levels of certification and compliance include:
- SAS 70 Type II Examination and Audit
- PCI Level 1 Security Certification
- CyberTrust Perimeter certification
- Adherence to HIPAA standards for compliance with personal health information
- Adherence to GLBA standards for compliance with financial information privacy
- Regulated by the FFIEC
Best Practices
Fiserv's EDD solution is guided by comprehensive policies and procedures
that ensure repeatable, manageable, measurable operations and results.
We use CMMI methodology for our process improvements and performance
measurements, allowing us to serve our clients with industry-leading
best practices.
Our policies and procedures include, but are not limited to:
- Security policy
- Logical and physical security policy
- Facility security management policy
- Remote access policy
- User policy
- Incident management policy
- Disaster recovery procedures
- HR policy
- Security awareness training program
- Risk management program
- Department and Operational processes
Physical and Environmental Security
Fiserv's EDD headquarters in Austin, Texas protects our associates
and our client data with multiple levels of security. We have multiple
secure-area zones with multi-factor access points, utilizing key cards
and biometric scanners. Video cameras monitor every office entry point
and our data center. In addition, we have an intrusion protection system
monitored by ADT.
Environmental protection equipment including; fire suppression, fireproofing,
water flooding, heat/air conditioning and power supply are installed,
tested, and monitored around the clock. The data center temperature
and humidity control systems are separate from the rest of the facility.
Policies and procedures are in place for protecting and monitoring the
equipment for security threats or environmental hazards.
Business Continuity
Fiserv will work with you to create a comprehensive plan to maintain
your business integrity, including data back-up at an additional disaster
recovery facility, crisis management and security incident management.
|