Our ESG Program

Cybersecurity

We strive to preserve the confidentiality, integrity, and availability of all physical, electronic, and informational assets as they relate to our enterprise networks, cloud solutions, and services.

Cybersecurity

At UKG,
we are committed to protecting our products and services from security threats, whether internal or external, deliberate, or accidental.

Our Commitment to Our Customers

As part of our commitment, we evidence these safeguards by providing our customers with independent third-party audit reports, such as SOC 2, as well as certifications of ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018.

SOC 2 — ISAE3402/SSAE 18 Audit Reports

UKG complies with ISAE3402/SSAE 18 AICPA Trust Principles for Security, Confidentiality, and Availability (and, where in scope, Privacy and Processing Integrity), and undergoes an audit each year to examine the relevant controls. These audits are performed by an independent, certified third party and the resulting reports are provided to our customers upon request within our UKG due diligence package.

The SOC 2 report demonstrates controls in place to meet the AICPA’s SOC 2 Trust Services Criteria (TSC) for the following principles:

  • Privacy: personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity’s privacy notice and with criteria outlined in the Generally Accepted Privacy Principles issued by the AICPA.
  • Confidentiality: information that is designated “confidential” is protected according to policy or agreement.
  • Security: the system is protected against unauthorized access, both physical and logical.
  • Availability: the system is available for operation and use in accordance with UKG’s commitments.
  • Processing Integrity: system processing is complete, accurate, and authorized.

ISO 27001, 27017, and 27018

ISO 27001 is an information security standard originally published in 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). ISO 27001 is a globally recognized, standards-based approach to security that outlines requirements for an organization’s information security management system (ISMS).

ISO 27017, published in 2015, is a complementary standard to ISO 27001. This standard provides controls and implementation guidance for information security applicable to the provision and use of cloud services.

ISO 27018 is a complementary standard, published by ISO/IEC in 2014, that contains guidelines applicable to cloud service providers that process personal data.

UKG ensures compliance with ISO 27001, 27017, and 27018 as outlined below. UKG also ensures our data centers maintain a recognized security program such as ISO 27001 or a comparable industry-standard security framework. The audits are carried out by an independent, certified third party, and, upon request, UKG provides the certificates to our customers.

BELOW IS A DETAILED SUMMARY OF UKG SOLUTIONS AND RELATED ISO CERTIFICATIONS:

 

ISO 27001
 Original Certification DateCurrent Certificate DateCurrent Certificate Expiry Date
UKG ProJanuary 3, 2008January 3, 2023October 31, 2025
UKG HRSDMarch 10, 2017January 3, 2023October 31, 2025
UKG Pro Workforce ManagementJune 20, 2019June 15, 2022June 19, 2025
UKG ReadyJune 15, 2022June 15, 2022June 19, 2025

 

ISO 27017
 Original Certification DateCurrent Certificate DateCurrent Certificate Expiry Date
UKG ProJune 14, 2021January 3, 2023January 2, 2026
UKG HRSDJune 14, 2021January 3, 2023January 2, 2026
UKG Pro Workforce ManagementJune 19, 2020June 15, 2022June 19, 2025
UKG ReadyJune 15, 2022June 15, 2022June 19, 2025

 

ISO 27018
 Original Certification DateCurrent Certificate DateCurrent Certificate Expiry Date
UKG ProDecember 13, 2016January 3, 2023January 2, 2026
UKG HRSDJanuary 3, 2020January 3, 2023January 2, 2026
UKG Pro Workforce ManagementJune 20, 2019June 15, 2022June 19, 2025
UKG ReadyJune 15, 2022June 15, 2022June 19, 2025

 

UKG Enterprise Security

The Enterprise Security team integrates all security activities within UKG to provide for the security of entrusted information and data, and the effective operation of our enterprise networks. The Enterprise Security team manages the UKG Security Policy, which describes the management of security of its information assets, responsibilities of various teams in securing information assets, and the various administrative, physical, and technical safeguards which are put in place to protect information assets. This policy applies to all UKG information assets, personnel (including contractors), and technology systems and environments, including the UKG private and public cloud environments.

Get the latest Global Impact Report from UKG

Get a more detailed look at our comprehensive ESG program, policies, and practices, as well as our progress from the past year.