Logo
Trust Center
Compliance Reporting Schedule

We maintain transparency through regular internal and external/third-party audits and assessments.

Compliance Standards

At Koch, we comply with a wide range of internationally recognized security standards. Proactive, risk-based controls protect the confidentiality, integrity, and availability of our customer and user data. Koch’s security program aligns with the following leading industry standards to support effective risk management, continuous improvement, and regulatory compliance across the enterprise: ISO/IEC 27001:2022 and NIST Cybersecurity Framework (CSF) 2.0. Alignment reflects adherence to industry best practices and principles. Each Koch company may pursue formal certification based on their specific business, customer, or regulatory requirements. Certifications with key regulatory agencies that are specific to their operations are maintained at the sub-company level.

Our Security Framework

Koch maintains a cyber security framework designed to support cyber security, compliance, and risk management. The basis of our security framework is a standard known as International Standards Organization (ISO) 27001/2: Information Technology Security Techniques, Information Security Management Systems (ISMS); commonly referred to as ISO27001/2. Though the basis of the Framework is ISO27001/2, principles also reflect requirements influenced by the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF). ISO27001/2 was chosen as the authoritative source due to its widespread applicability across industries and developed countries world-wide, including the United States. Our cyber security framework provides a foundation for managing security and risk across the organization while supporting the operational autonomy of Koch companies. This security framework is reviewed and refined on an ongoing basis to adapt to changes in business operations, technology, and the evolving threat landscape. The framework is built on the following principles:

  • Establishes security and governance expectations
  • Supports a federated model with local ownership and accountability
  • Ensures compliance with regulatory standards and contractual requirements
  • Enables risk-based decision making across the organization
  • Promotes transparency, oversight, and continuous improvement
Koch Cyber Security Statement

Koch is committed to protecting its employees, partners, clients, and Koch from damaging acts that are intentional or unintentional. Effective security is a team effort involving the participation and support of every entity that interacts with Koch data and systems, applications, and services. Therefore, it is the responsibility of both Koch personnel and third parties to be aware of and adhere to Koch cyber security requirements. Protecting Koch data and the systems that collect, process, and maintain this data is of critical importance. Commensurate with risk, security and privacy measures must be implemented to guard against unauthorized access to, alteration, disclosure or destruction of data and systems, applications, and services. This also includes protection against accidental loss or destruction. The security of systems, applications and services include controls and safeguards to offset possible threats, as well as controls to ensure confidentiality, integrity, availability, and safety.

Overview

Koch's Security Trust Center is a centralized location for key information and resources on Koch's security posture, compliance and security documentation. The Koch Security Trust Center is used by organizations in these distinct ways:

  • Organizations can access comprehensive documentation about Koch's security controls, compliance certifications, and attestation reports, enabling them to conduct thorough vendor security assessments and maintain their own compliance requirements.
  • Security and compliance teams can review detailed information about Koch's security practices, infrastructure security, data protection measures, and privacy policies through an intuitive portal, providing transparency into how Koch safeguards customer data and maintains its security posture.
Policies
  • ✅ Asset Management
  • ✅ Artificial Intelligence & Autonomous Technologies
  • ✅ Business Continuity & Disaster Recovery
  • ✅ Capacity & Performance Planning
  • ✅ Change Management
  • ✅ Cloud Security
  • ✅ Compliance
  • ✅ Configuration Management
  • ✅ Continuous Monitoring
  • ✅ Cryptographic Protections
  • ✅ Data Classification and Handling
  • ✅ Electronic Device Disposal
  • ✅ Embedded Technology
  • ✅ Endpoint Security
  • ✅ Human Resources Security
  • ✅ Identification & Authentication
  • ✅ Incident Response
  • ✅ Information Assurance
  • ✅ Maintenance Operations
  • ✅ Mobile Device Management
  • ✅ Network Security
  • ✅ Physical & Environmental Security
  • ✅ Data Privacy
  • ✅ Project & Resource Management
  • ✅ Risk Management
  • ✅ Secure Engineering and Architecture
  • ✅ Security Operations
  • ✅ Security Awareness & Training
  • ✅ Security & Privacy Governance
  • ✅ Technology Development & Acquisition
  • ✅ Third-Party Management
  • ✅ Threat Management
  • ✅ Vulnerability & Patch Management
  • ✅ Web Security

Powered By

ZenGRC

Copyright © 2026