Dexcom’s Security Practices
General Guidelines: Security Practices Implemented
Security Practices Implemented at Dexcom (Dexcom Controls)
Secure Communication Protocols
- Use secure versions of TLS (Transport Layer Security) for web and API communications.
- Implement secure pairing and encryption for Bluetooth Low Energy (BLE) communications.
Critical Function Protection
- Monitor and restrict unauthorized code execution with runtime protection.
- Validate application integrity to ensure they haven’t been altered or corrupted.
Data Protection Measures
- Apply strong encryption algorithms to secure stored and transmitted data.
- Use tamper detection mechanisms to identify unauthorized changes.
Software Update Procedures
- Schedule regular updates for operating systems, applications, and firmware.
- Validate updates before deployment and ensure rollback options are available
Threat Detection and Response Protocols
- Monitor systems for suspicious activity using threat intelligence tools.
- Define clear escalation paths and response procedures for identified threats.
Authentication and Access Control Guidelines
- Use multi-factor authentication (MFA) for sensitive systems where feasible.
- Apply role-based access controls (RBAC) to limit permissions based on job function.
User Awareness Resources
- Offer accessible resources such as FAQs, quick guides, and helpdesk support.