SOC 2 Type II audit confirms effectiveness of Kaspersky’s security controls
Source: Promo
Sunday, 26.10.2025.
11:39
Sunday, 26.10.2025.
11:39
(Photo: Pixabay / StartupStockPhotos)
The assessment covered the integrity and security of the company’s antivirus database development and deployment processes and confirmed the reliability of existing protection mechanisms against unauthorized changes.
As part of its ongoing efforts to independently verify the integrity of its solutions, Kaspersky has maintained compliance with the SOC 2 standard since 2019.
The SOC 2 framework, developed by the American Institute of Certified Public Accountants (AICPA), assesses security controls against five principles: security, availability, process integrity, confidentiality, and privacy.
The audit, which covered the period from August 2024 to July 2025, analyzed Kaspersky’s workflows related to the development and implementation of antivirus databases for Windows and Unix operating systems, including the supporting infrastructure, procedures, software, data, and employees involved in these processes.
To assess the effectiveness of existing controls, the following tests were conducted:
• in-depth interviews with relevant stakeholders;
• operational observations of implemented controls;
• analysis of relevant documentation;
• re-execution of manual controls and monitoring activities.
(Photo: Shutterstock)
The full audit report is available upon request.
“Kaspersky places great importance on external verification of its security practices to ensure compliance with global standards and stakeholder expectations,” said Alexander Liskin, Head of Threat Research at Kaspersky.
“The latest SOC 2 audit highlights the effectiveness of our controls and the integrity of the lifecycle of our antivirus database,” said Liskin.
These audits are a key part of Kaspersky’s Global Transparency Initiative, designed to build trust through accountability.
In addition to the SOC 2 standard, the company has also achieved ISO/IEC 27001 certification for its information security management system, as well as Common Criteria certifications for its leading business products – Kaspersky Endpoint Security and Kaspersky Security Center, a management console for corporate solutions.
Companies:
Kaspersky
Tags:
Kaspersky
Kaspersky Endpoint Security
Kaspersky Security Center
Windows
Unix
Service Organization Control for Service Organizations
SOC 2 Type II
Global Transparency Initiative
Alexander Liskin
cybersecurity
unauthorized changes
antivirus databases
protection
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora