Aconex Data Security

Aconex Data Security

All the benefits of the cloud, reduced risk to your business.

Aconex Data Security

1 Data Sheet / Aconex Data Security/ Version 1.0

Copyright © 2023, Oracle and/or its affiliates / Public

Data Sheet

Aconex Data Security All the benefits of the cloud, reduced risk to your business.

As a global leader of information and project collaboration services to the construction, infrastructure and resource sectors, Oracle understands the changing information security landscape. Oracle continually invests in the uplift of compliance baselines of all Aconex environments, our internal processes and staff training to ensure your data is secure.

These uplifts include, but are not limited to:

• Organisational accounts on the Aconex platform are private and accessible only to authorised members of each organisation.

• Organisational firewalls are unable to be breached.

• All transactions are logged; nothing can be edited or deleted after transmission.

• All logins and uploads/downloads are encrypted via 128-bit SSL.

• Oracle staff cannot access readable project data for any reason. It is also technically not possible for Oracle staff to access client data for project archive production.

• Oracle support desk personnel are restricted (prohibited) from logging into a user’s account or operating as a user in the client’s organisation. Oracle staff will never ask a client to divulge their authentication and can only screen share with a user’s explicit consent.

• Oracle does not sell our services to organisations domiciled in Australian government-listed embargoed nations.

• Oracle is constantly monitoring, patching, and strengthening security controls to stay ahead of malicious players.

• The Oracle Aconex global user directory does not expose email addresses and users can choose not to show their mobile number.

• Oracle Sales and Customer Success staff have no access to member listings of projects to which they haven’t themselves been invited.

Key Facts:

� Aconex is certified to the ISO/IEC-27001 information security regime.

� Aconex is annually audited to the SOC2 security and controls framework.

� All logins, uploads and downloads are encrypted via 128-bit SSL.

� Optional 2 Factor Authentication

2 Data Sheet / Aconex Data Security/ Version 1.0

Copyright © 2023, Oracle and/or its affiliates / Public

Compliance with other Security Frameworks

Oracle Aconex Software-as-a-Service (SaaS) is available globally and therefore strives to comply with multiple security frameworks.

These include external frameworks such as ISO and SOC as well as stringent Oracle internal requirements. The requirements within these frameworks are applicable to not only the Oracle Aconex service, but also to the way in which it is managed to protect customer data:

• Oracle Internal Requirements: All Oracle services must meet stringent Oracle internal security requirements, including compliance with Oracle Corporate Security Practices. The Corporate Security Solution Assurance Process (CSSAP) is designed to ensure that all Oracle services meet Oracle security standards.

• ISO/IEC-27001: Oracle Aconex operates and is certified to the ISMS Framework.

• SOC2: Oracle Aconex is annually audited to this security and controls framework.

• Kitemark ISO 19650: Some modules within Aconex are certified to this framework, which focuses on functionality but also includes security requirements.

A formal statement describing Oracle Aconex security compliance is available here.

Copyright © 2023, Oracle and/or its affiliates. All rights reserved. This document is provided for information purposes only, and the contents hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. We specifically disclaim any liability with respect to this document, and no contractual obligations are formed either directly or indirectly by this document. This document may not be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without our prior written permission.

This device has not been authorized as required by the rules of the Federal Communications Commission. This device is not, and may not be, offered for sale or lease, or sold or leased, until authorization is obtained.

Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners.

Intel and Intel Xeon are trademarks or registered trademarks of Intel Corporation. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. AMD, Opteron, the AMD logo, and the AMD Opteron logo are trademarks or registered trademarks of Advanced Micro Devices. UNIX is a registered trademark of The Open Group. 0120

Disclaimer: If you are unsure whether your data sheet needs a disclaimer, read the revenue recognition policy. If you have further questions about your content and the disclaimer requirements, e- mail REVREC_US@oracle.com.

https://www.oracle.com/corporate/security-practices/corporate/ https://www.oracle.com/corporate/security-practices/corporate/ https://www.oracle.com/corporate/security-practices/corporate/governance/security-architecture.html https://www.oracle.com/corporate/security-practices/corporate/governance/security-architecture.html https://www.oracle.com/a/ocom/docs/aconex-consensus-assessment-initiative-questionnaire.pdf mailto:REVREC_US@oracle.com


Item Type: pdf