Certificate Number: ISO********
Information Security Management System - ISO/IEC 27001:2013
Certificate of Registration
Cadence Assurance, LLC has performed a certification examination to assess GitHub’s conformity with the defined requirements in the standard ISO/IEC 27001:2013 over its information security management system
(ISMS).
The scope of this certificate includes GitHub’s products, teams, and ISMS managed at its HQ location in San Francisco, CA, USA. The in-scope people, processes, technology, and locations are defined within the GitHub ISMS Scope, dated February 16, 2022, and the Statement of Applicability, dated February 11, 2022.
Awarded to:
GitHub
with its HQ location at
88 Colin P Kelly Jr St
San Francisco, CA 94107
USA
Bryan Schader, Partner, Cadence Assurance, LLC
Authorized by:
Registration date:
May 06, 2022
This certificate was issued electronically and remains the property of Cadence Assurance, LLC and is bound by the conditions of contract. The content must not be altered and any promotion by employing this certificate or certification body quality mark must adhere to the scope and nature of certification and to the conditions of contract. Given the nature and inherent limitations of sample-based certification assessments, this certificate is not meant to express any form of assurance on the performance of the organization being certified to the referred ISO standard. The certificate does not grant immunity from any legal/ regulatory obligations. Questions about this certificate can be made by visiting www.cadenceassurance.com. Issue date of certificate:
May 06, 2022
Expiration date of certificate:
May 05, 2025
Certificate Number: ISO20220501
GitHub
Scope for certificate
The scope of the ISO/IEC 27001:2013 certificate is limited to the ISMS supporting the provisioning, monitoring, and ongoing management of GitHub in accordance with the Statement of Applicability. GitHub ISMS Scope includes the following elements: Products:
• GitHub.com
o GitHub Enterprise Cloud (GHEC)
§ Audit log API
§ GitHub Connect
§ SSO
§ LDAP
§ IP allow list
o GitHub Advanced Security (GHAS)
§ Code Scanning
§ Secret Scanning
o GitHub Actions
§ Machine Management Service
Locations:
• GitHub Headquarters – 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA Registration date:
May 06, 2022
This certificate was issued electronically and remains the property of Cadence Assurance, LLC and is bound by the conditions of contract. The content must not be altered and any promotion by employing this certificate or certification body quality mark must adhere to the scope and nature of certification and to the conditions of contract. Given the nature and inherent limitations of sample-based certification assessments, this certificate is not meant to express any form of assurance on the performance of the organization being certified to the referred ISO standard. The certificate does not grant immunity from any legal/ regulatory obligations. Questions about this certificate can be made by visiting www.cadenceassurance.com. Issue date of certificate:
May 06, 2022
Expiration date of certificate:
May 05, 2025