Q&A on Company Information System Security

We receive more and more questions from our customers and partners about Dassault Systèmes company Information System Security. That is not an easy topic and we have several persons inside the company to address this topic with different perspectives: internal audit, external business customers; for 3DS employee, they can be accessed in People 360° apps.

Here is a set of questions from a customer and answers from Wilberth BURG, EMEA IT Director about this security topic:

1. Does your company have a security program?

Yes we have a security program build by our security organization. See Dassault Systèmes’ website on security and compliancy:

2. Is your security program and practices evaluated by a 3rd party auditor?

Yes we use external organizations for security audits and certifications.

3. Do you have a 3rd party attestation of security practices, either SOC2 Type II or ISO27000?

Depending on location, brand or service, Dassault Systèmes is ISO27001 and TISAX certified. All our policies and guidelines are based on ISO27001.

4. Has your company or the solution it offers, been exposed or been a victim of data exfiltration or malicious encryption (security hack/ransomware, etc)?

No.

5. How frequently do you conduct pen-test (ethical hack) of the application/service we are looking at subscribing to?

Full test is performed at least on a yearly base. Besides we run daily vulnerability scans on our public IP and services.

6. Do you have a data privacy program compliant with GDPR, CCPA, etc, and what is your current data processing practice?

Dassault Systèmes is GDPR compliant: https://www.3ds.com/general-data-protection-regulation.

Hope that helps, JP



Materials_Compliance_Management ​​​​​​​Tips_and_Tricks ​​​​​​​