Secure development lifecycle
To ensure secure development of its platform, Dynatrace has implemented controls and practices that cover the full development lifecycle starting with defining the requirements and design, through development, continuous integration hardening to production.
Learn about the security controls that are included in the Dynatrace Security Development Lifecycle (SDLC) in our Documentation.
Business practices & organizational security controls
Business continuity
We have built resiliency, failover, and rapid recoverability into our solutions, infrastructure, and business systems. Our global cloud focus and operational model allow us to limit vulnerability to regional technology outages.
Vendor management
We utilize an extensive vendor management evaluation process to evaluate the cyber risk of all our vendors. Vendors are evaluated prior to onboarding, and reviewed on a periodic basis or whenever there’s a significant change in their cyber risk rating. Risk ownership is clearly defined and regularly reviewed.
Employee security awareness
All Dynatrace employees and contractors must complete a Security Awareness Training course at their time of hire as well as on a yearly basis, covering topics like ransomware, social media, credential management, impersonation attack, data handling, fraud, phishing, identity theft, etc.
Additionally, employees may undergo training focused around the nature of their job or role. As well, employees are tested quarterly for phishing identification. Remedial training is required for all failed tests.