Infrastructure & Compliance
How do you continuously monitor and report the compliance of your infrastructure in accordance to industry best practices (OWASP, SANS, SOC, ISO 27001)?
How do you continuously monitor and report the compliance of your infrastructure in accordance to industry best practices (OWASP, SANS, SOC, ISO 27001)?
Are Cloud Hosting services (IaaS) provided?
Are Cloud Hosting services (IaaS) provided?
What is the service delivery model? (IaaS/PaaS/SaaS)
What is the service delivery model? (IaaS/PaaS/SaaS)
Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?
Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?
What Services/products are being/will be provided to the customer?
What Services/products are being/will be provided to the customer?
Do you offer an on-premise solution?
Do you offer an on-premise solution?
Describe in detail your product's architecture.
Describe in detail your product's architecture.
Describe the key differentiators of your technical architecture.
Describe the key differentiators of your technical architecture.
Describe the minimum and recommended system requirements for your solution.
Describe the minimum and recommended system requirements for your solution.
Describe your solution's networking requirements and capabilities.
Describe your solution's networking requirements and capabilities.
Is your solution available in a seamless manner to access as an app on different mobile devices and as web app on different desktop devices?
Is your solution available in a seamless manner to access as an app on different mobile devices and as web app on different desktop devices?
Mobile Device Availability? (Android and iOS)
Mobile Device Availability? (Android and iOS)
Tablet Device Availability? (Android and iOS)
Tablet Device Availability? (Android and iOS)
Browser compatibility? (MS Edge, Chrome, Safari, IE)
Browser compatibility? (MS Edge, Chrome, Safari, IE)
Technology Stack? (Infrastructure / Frontend / Backend / Database)
Technology Stack? (Infrastructure / Frontend / Backend / Database)
What technology languages/platforms/stacks/components are utilized in the scope of the application?
What technology languages/platforms/stacks/components are utilized in the scope of the application?
Is the application developed on the latest language framework?
Is the application developed on the latest language framework?
Is the application developed using secure libraries?
Is the application developed using secure libraries?
Where is the primary data center? Backup data center?
Where is the primary data center? Backup data center?
Describe the network topology.
Describe the network topology.
Describe your network configuration and how your sensitive data system is protected.
Describe your network configuration and how your sensitive data system is protected.
Backup, Recovery & Business Continuity
Have you implemented backup or recovery mechanisms to ensure compliance with regulatory, statutory, contractual or business requirements?
Have you implemented backup or recovery mechanisms to ensure compliance with regulatory, statutory, contractual or business requirements?
If using virtual infrastructure, does your cloud solution include independent hardware restore and recovery capabilities?
If using virtual infrastructure, does your cloud solution include independent hardware restore and recovery capabilities?
Does your infrastructure environment solution include software/provider independent restore and recovery capabilities?
Does your infrastructure environment solution include software/provider independent restore and recovery capabilities?
Do you test your backup or redundancy mechanisms at least annually?
Do you test your backup or redundancy mechanisms at least annually?
Does the RTO and RPO of CSP's contingency plan meet with vendor's customer requirements?
Does the RTO and RPO of CSP's contingency plan meet with vendor's customer requirements?
Has Supplier implemented data backup and recovery procedures to prevent data loss, unwanted overwrite and/or destruction?
Has Supplier implemented data backup and recovery procedures to prevent data loss, unwanted overwrite and/or destruction?
Does the organisation store backups offsite?
Does the organisation store backups offsite?
Are all systems, assets and information backed up based on a BIA which establishes RPO/RTO?
Are all systems, assets and information backed up based on a BIA which establishes RPO/RTO?
Shall a backup be taken before and after any major changes to hardware, OS, application or configuration?
Shall a backup be taken before and after any major changes to hardware, OS, application or configuration?
There shall be a detailed backup procedure based on the established RPO and RTO.
There shall be a detailed backup procedure based on the established RPO and RTO.
What backup and disaster recovery plans are in place to avoid data loss/service loss in the time of contingency?
What backup and disaster recovery plans are in place to avoid data loss/service loss in the time of contingency?
Have you applied a data backup mechanism? What is the frequency of backup?
Have you applied a data backup mechanism? What is the frequency of backup?
Is your backup mechanism tested at least annually?
Is your backup mechanism tested at least annually?
Are you able to restore user data upon loss through disk recovery mechanisms or stored backups?
Are you able to restore user data upon loss through disk recovery mechanisms or stored backups?
Do you possess ISO 22301 for Business Continuity?
Do you possess ISO 22301 for Business Continuity?
What type of DR options do you provide for my data within your offering?
What type of DR options do you provide for my data within your offering?
Application Development & SDLC
Do you test your applications before they are promoted into the Production environment? What types of testing do you perform?
Do you test your applications before they are promoted into the Production environment? What types of testing do you perform?
Do you have a defined quality change control and testing process in place?
Do you have a defined quality change control and testing process in place?
Do you have controls in place to ensure that standards of quality are being met for all software development?
Do you have controls in place to ensure that standards of quality are being met for all software development?
What controls do you have in place to detect source code security defects for any outsourced software development activities?
What controls do you have in place to detect source code security defects for any outsourced software development activities?
Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?
Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?
Do you use an automated source code analysis tool to detect security defects in code prior to production?
Do you use an automated source code analysis tool to detect security defects in code prior to production?
Privacy by Design is incorporated into all your developments and services.
Privacy by Design is incorporated into all your developments and services.
Does the software development lifecycle in the organisation specifically focus on security?
Does the software development lifecycle in the organisation specifically focus on security?
Are development, test and production environments separate?
Are development, test and production environments separate?
Is production data ever used in a test environment?
Is production data ever used in a test environment?
Is testing of applications done on a separate testing facility and not on production data?
Is testing of applications done on a separate testing facility and not on production data?
Are patches tested in a UAT instance before deployment on the production server?
Are patches tested in a UAT instance before deployment on the production server?
Are applications and operating system software implemented after extensive and successful security testing?
Are applications and operating system software implemented after extensive and successful security testing?
Do you do static code analysis?
Do you do static code analysis?
How do you ensure code is being developed securely?
How do you ensure code is being developed securely?
What percentage of your production code is covered by automated tests?
What percentage of your production code is covered by automated tests?
Is a staging/pre-production system used to validate build artifacts before promotion to production?
Is a staging/pre-production system used to validate build artifacts before promotion to production?
How is application security testing performed? Internal, third parties, or both? How often is it tested?
How is application security testing performed? Internal, third parties, or both? How often is it tested?
Any product pre-release security threat modeling, secure coding practice, security architecture review and penetration testing?
Any product pre-release security threat modeling, secure coding practice, security architecture review and penetration testing?
Is application development following secure coding standards such as OWASP?
Is application development following secure coding standards such as OWASP?
Is the code reviewed by peer or externally?
Is the code reviewed by peer or externally?
Please provide further information about your handling of security requirements during development.
Please provide further information about your handling of security requirements during development.
Describe the management system in place to fix vulnerabilities identified during control activities.
Describe the management system in place to fix vulnerabilities identified during control activities.
Do you have a managed process for approving new 3rd Party Libraries?
Do you have a managed process for approving new 3rd Party Libraries?
Develop applications based on secure coding guidelines.
Develop applications based on secure coding guidelines.
Implement controls to obfuscate application code prior to compilation.
Implement controls to obfuscate application code prior to compilation.
Configures web services in accordance with OWASP.
Configures web services in accordance with OWASP.
Configure web services to prevent sensitive information leakage in response headers.
Configure web services to prevent sensitive information leakage in response headers.
Configure web services to use secure HTTP headers.
Configure web services to use secure HTTP headers.
Impose file upload frequency restrictions in applications to prevent abuse or attack.
Impose file upload frequency restrictions in applications to prevent abuse or attack.
Access Control & Authentication
Do you have an identity management system (enabling classification of data for a customer) in place to enable both role-based and context-based entitlement to data?
Do you have an identity management system (enabling classification of data for a customer) in place to enable both role-based and context-based entitlement to data?
Do you provide customers with strong (multifactor) authentication options (e.g., digital certs, tokens, biometrics)?
Do you provide customers with strong (multifactor) authentication options (e.g., digital certs, tokens, biometrics)?
Does the SaaS support MFA such as OTP, security tokens, or biometrics?
Does the SaaS support MFA such as OTP, security tokens, or biometrics?
Do you allow customers to define password and account lockout policies for their accounts?
Do you allow customers to define password and account lockout policies for their accounts?
Do you restrict personnel access to all management functions or administrative access based on the principle of least privilege?
Do you restrict personnel access to all management functions or administrative access based on the principle of least privilege?
How do you verify password strength?
How do you verify password strength?
How are passwords stored (encrypted, hashed, algorithm or hashing methodology)?
How are passwords stored (encrypted, hashed, algorithm or hashing methodology)?
How are passwords hashed?
How are passwords hashed?
Does your solution follow any particular internationally accepted best practices or standards for password management?
Does your solution follow any particular internationally accepted best practices or standards for password management?
Does the solution force the new user to change the password for their first logon and on expiry?
Does the solution force the new user to change the password for their first logon and on expiry?
Can passwords be changed by the user at anytime?
Can passwords be changed by the user at anytime?
Can the solution alert the security administrator to delete a UserID if it has not been used for predefined days?
Can the solution alert the security administrator to delete a UserID if it has not been used for predefined days?
Can users be prevented from logging into multiple terminals simultaneously?
Can users be prevented from logging into multiple terminals simultaneously?
Does the solution have other options of logon inputs besides user ID and password?
Does the solution have other options of logon inputs besides user ID and password?
What is the idle session timeout and session expiration?
What is the idle session timeout and session expiration?
Is there account lockout functionality? What is the maximum number of failed login attempts before the account gets locked out?
Is there account lockout functionality? What is the maximum number of failed login attempts before the account gets locked out?
What is the account unlock process?
What is the account unlock process?
Does access provided to users and administrators follow Need to Know basis?
Does access provided to users and administrators follow Need to Know basis?
Is two-factor authentication enabled for end users and Administrators?
Is two-factor authentication enabled for end users and Administrators?
Does MFA apply while accessing cloud environment/applications remotely (VPN, VDI)?
Does MFA apply while accessing cloud environment/applications remotely (VPN, VDI)?
How is Segregation of Duties (SoD) implemented for various user access roles?
How is Segregation of Duties (SoD) implemented for various user access roles?
Detail out the organization password policy.
Detail out the organization password policy.
Supplier has internal processes for identity and access management.
Supplier has internal processes for identity and access management.
Control panel or administration console to the service is properly protected from abuse. Segregation of duties is implemented for privileged users.
Control panel or administration console to the service is properly protected from abuse. Segregation of duties is implemented for privileged users.
What kind of identity and access management services are provided?
What kind of identity and access management services are provided?
Are access to utility programs used to manage virtualized partitions appropriately restricted and monitored?
Are access to utility programs used to manage virtualized partitions appropriately restricted and monitored?
Do you have complexity or length requirements for passwords?
Do you have complexity or length requirements for passwords?
Do you review user access and rights at least annually?
Do you review user access and rights at least annually?
Network Security & Firewall
Do your network architecture diagrams clearly identify high-risk environments and data flows?
Do your network architecture diagrams clearly identify high-risk environments and data flows?
Are all non-internet facing systems placed behind a firewall?
Are all non-internet facing systems placed behind a firewall?
Does the vendor have a comprehensive network architecture diagram covering infrastructure used for customer operations?
Does the vendor have a comprehensive network architecture diagram covering infrastructure used for customer operations?
Is the internet access secure through a proxy/firewall?
Is the internet access secure through a proxy/firewall?
Are roles and responsibilities defined for Firewall configuration?
Are roles and responsibilities defined for Firewall configuration?
Is the firewall rule base reviewed at regular intervals?
Is the firewall rule base reviewed at regular intervals?
Does the firewall have real-time logging and alerting capability?
Does the firewall have real-time logging and alerting capability?
Are prior management approvals obtained and communication provided to the customer in case of any external connections to parties other than the customer?
Are prior management approvals obtained and communication provided to the customer in case of any external connections to parties other than the customer?
Are all servers, end user devices configured according to security standards as part of the build process?
Are all servers, end user devices configured according to security standards as part of the build process?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Is wireless access allowed in your organisation?
Is wireless access allowed in your organisation?
Are network boundaries protected by firewalls?
Are network boundaries protected by firewalls?
Is data import, data export, and service management conducted over secure, industry-accepted standardized network protocols?
Is data import, data export, and service management conducted over secure, industry-accepted standardized network protocols?
What type/model of Firewall is implemented to segregate security zones and protect the infrastructure from external attacks?
What type/model of Firewall is implemented to segregate security zones and protect the infrastructure from external attacks?
How are operating systems hardened to provide only the necessary ports, protocols and services to meet business needs?
How are operating systems hardened to provide only the necessary ports, protocols and services to meet business needs?
Is the network used for providing service to the customer logically and physically segregated? Is the server placed on a separate LAN?
Is the network used for providing service to the customer logically and physically segregated? Is the server placed on a separate LAN?
Are external access (e.g., remote, wireless, third party) to the network only permitted after a user has been identified and authenticated?
Are external access (e.g., remote, wireless, third party) to the network only permitted after a user has been identified and authenticated?
Whether Firewall, IPS/IDS, DLP, Anti APT, SIEM, AntiSpoofing and other security solutions have been implemented?
Whether Firewall, IPS/IDS, DLP, Anti APT, SIEM, AntiSpoofing and other security solutions have been implemented?
Are internal and external networks separated by firewalls with access policies and rules?
Are internal and external networks separated by firewalls with access policies and rules?
Any host-based IPS for critical systems? Any next generation firewall, IPS and web application firewall?
Any host-based IPS for critical systems? Any next generation firewall, IPS and web application firewall?
Are network components and computers password protected?
Are network components and computers password protected?
Is the production network segmented into different zones based on security levels?
Is the production network segmented into different zones based on security levels?
What is the process for making changes to network configuration?
What is the process for making changes to network configuration?
Describe how you protect against attacks that target virtual infrastructure directly (shimming, Blue Pill, Hyper jumping, etc.)
Describe how you protect against attacks that target virtual infrastructure directly (shimming, Blue Pill, Hyper jumping, etc.)
Is application deployed behind the firewall and IDS/IPS?
Is application deployed behind the firewall and IDS/IPS?
Does WAF protect from application attacks?
Does WAF protect from application attacks?
Service Provider should have solid application security controls such as WAF and RASP to detect and block web-based attacks such as XSS, SQL Injection, and CSRF.
Service Provider should have solid application security controls such as WAF and RASP to detect and block web-based attacks such as XSS, SQL Injection, and CSRF.
What cryptographic frameworks are used to secure data in transit over public networks?
What cryptographic frameworks are used to secure data in transit over public networks?
Describe the network protocols used to communicate between components of the system (e.g., HTTPs, LDAP, SSL).
Describe the network protocols used to communicate between components of the system (e.g., HTTPs, LDAP, SSL).
I cannot find anywhere in their documentation that they support IP address range restriction for the application API, could we get confirmation?
I cannot find anywhere in their documentation that they support IP address range restriction for the application API, could we get confirmation?
Logging, Monitoring & Audit
Do you monitor and log privileged access (e.g., administrator level) to information security management systems?
Do you monitor and log privileged access (e.g., administrator level) to information security management systems?
Does the organisation maintain audit logs of user activities, exceptions, and security events on all systems that store or process sensitive data?
Does the organisation maintain audit logs of user activities, exceptions, and security events on all systems that store or process sensitive data?
Do these audit logs contain details regarding the User ID, timestamp, and what actions were performed?
Do these audit logs contain details regarding the User ID, timestamp, and what actions were performed?
At what frequency are these logs reviewed?
At what frequency are these logs reviewed?
Is the ability to delete event logs restricted to only superadmin or host admin?
Is the ability to delete event logs restricted to only superadmin or host admin?
Are changes made to virtual machines or moving of an image made immediately available to customers through electronic methods?
Are changes made to virtual machines or moving of an image made immediately available to customers through electronic methods?
Are system administrator and system operator activities monitored and logged?
Are system administrator and system operator activities monitored and logged?
Are the system clocks of all information processing systems synchronized with an agreed accurate time source?
Are the system clocks of all information processing systems synchronized with an agreed accurate time source?
Do you use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference?
Do you use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference?
What is the log retention policy? Who has access to logs in your organization?
What is the log retention policy? Who has access to logs in your organization?
Who has access to Security logs?
Who has access to Security logs?
How long are security logs maintained by the provider?
How long are security logs maintained by the provider?
IS logging enabled for all components, such as network devices, servers, DBs, IAM, Cloud Services?
IS logging enabled for all components, such as network devices, servers, DBs, IAM, Cloud Services?
Do you have a SIEM for monitoring and maintaining logs over security incidents?
Do you have a SIEM for monitoring and maintaining logs over security incidents?
Provide the scope of data sources merged in your SIEM and confirm if configured for granular analysis and real-time alerting.
Provide the scope of data sources merged in your SIEM and confirm if configured for granular analysis and real-time alerting.
Is a SOC implemented to monitor the software solution? Can the customer gain access to the SOC alert and response reporting?
Is a SOC implemented to monitor the software solution? Can the customer gain access to the SOC alert and response reporting?
Does the Company run a Security Operations Center (or equivalent) which allows detection and response to Cyber Security Incidents?
Does the Company run a Security Operations Center (or equivalent) which allows detection and response to Cyber Security Incidents?
Are all security events (authentication events, SSH session commands, privilege elevations) in production logged?
Are all security events (authentication events, SSH session commands, privilege elevations) in production logged?
Can logs be integrated into a SIEM system?
Can logs be integrated into a SIEM system?
Is a service available for APIs to push the logs of our company's administrators' operations on the Vendor platform in real time?
Is a service available for APIs to push the logs of our company's administrators' operations on the Vendor platform in real time?
Is there a support for operation logs on the admin console? What operations do the audit logs monitor?
Is there a support for operation logs on the admin console? What operations do the audit logs monitor?
Logging and monitoring is in place for analysing activities of privileged users as well as for inspecting and analysing network traffic.
Logging and monitoring is in place for analysing activities of privileged users as well as for inspecting and analysing network traffic.
Logs are reviewed in a continuous manner to improve performance as well as detect potential security issues.
Logs are reviewed in a continuous manner to improve performance as well as detect potential security issues.
Do you monitor and log user, system and administrative access?
Do you monitor and log user, system and administrative access?
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently?
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently?
Does your internal security group carry out audits on your Information Security Management System?
Does your internal security group carry out audits on your Information Security Management System?
Will event logging/audit mechanisms be turned on at all times for the system?
Will event logging/audit mechanisms be turned on at all times for the system?
Will logs be regularly reviewed?
Will logs be regularly reviewed?
Are systems and networks monitored for security events?
Are systems and networks monitored for security events?
Do you have any monitoring tool in place to get timely alerts on when a device is going down, restarted, or resources are over utilized?
Do you have any monitoring tool in place to get timely alerts on when a device is going down, restarted, or resources are over utilized?
How do you monitor system integrity, logs, intrusion detection, and system access?
How do you monitor system integrity, logs, intrusion detection, and system access?
Are audit logs maintained that record user activities, exceptions, success and failure logons, policy changes, and information security events?
Are audit logs maintained that record user activities, exceptions, success and failure logons, policy changes, and information security events?
Are servers configured to capture who accessed a system and what changes were made?
Are servers configured to capture who accessed a system and what changes were made?
Detail out the process for security event logging and monitoring (including applicable correlation rules). Detail the log retention period and protection mechanisms to prevent log tampering.
Detail out the process for security event logging and monitoring (including applicable correlation rules). Detail the log retention period and protection mechanisms to prevent log tampering.
What alerts can be set in the system?
What alerts can be set in the system?
Data Protection & Encryption
Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific customer without freezing other customer data?
Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific customer without freezing other customer data?
Do you have the capability to recover data for a specific customer in the case of a failure or data loss?
Do you have the capability to recover data for a specific customer in the case of a failure or data loss?
What is the purpose for processing the Personal Data?
What is the purpose for processing the Personal Data?
Can Supplier provide a data map which includes all country locations where Personal Data would traverse, be stored or processed?
Can Supplier provide a data map which includes all country locations where Personal Data would traverse, be stored or processed?
Have you implemented measures for prevention of loss of PII data? (e.g., DLP, restricted access controls, log recording, encryption)
Have you implemented measures for prevention of loss of PII data? (e.g., DLP, restricted access controls, log recording, encryption)
Is data import, data export, and service management conducted over secure industry-accepted standardized network protocols?
Is data import, data export, and service management conducted over secure industry-accepted standardized network protocols?
Describe how you make sure the customer's data is properly segregated from other customers' in multi-tenant solutions.
Describe how you make sure the customer's data is properly segregated from other customers' in multi-tenant solutions.
Would you support encryption keys generated by our own PKI that would be used to encrypt data?
Would you support encryption keys generated by our own PKI that would be used to encrypt data?
What type of mechanisms do you implement to make sure Data Integrity is protected against errors, corruption or misuse?
What type of mechanisms do you implement to make sure Data Integrity is protected against errors, corruption or misuse?
Describe how you make sure the application is properly protected against exploitation of CVE vulnerabilities prior to allowing it to go to production.
Describe how you make sure the application is properly protected against exploitation of CVE vulnerabilities prior to allowing it to go to production.
Is data import and export conducted over secure, industry-accepted standardized network protocols?
Is data import and export conducted over secure, industry-accepted standardized network protocols?
Is sensitive information transferred to external recipients? If so, are controls in place to protect it?
Is sensitive information transferred to external recipients? If so, are controls in place to protect it?
Are there security procedures for the decommissioning of IT equipment and storage devices which contain sensitive information?
Are there security procedures for the decommissioning of IT equipment and storage devices which contain sensitive information?
Is the data classified top secret/confidential/PII stored separately from public data or data of other organizations residing on the same cloud?
Is the data classified top secret/confidential/PII stored separately from public data or data of other organizations residing on the same cloud?
How is data loss prevented and how is high availability ensured?
How is data loss prevented and how is high availability ensured?
If other tenants' information/data is compromised, how is the vendor making sure that the customer organization's data is not impacted?
If other tenants' information/data is compromised, how is the vendor making sure that the customer organization's data is not impacted?
What security measures are implemented by the Application Service Provider for guarding against data leakage/data corruption/data breach?
What security measures are implemented by the Application Service Provider for guarding against data leakage/data corruption/data breach?
Is the data for multiple customers co-mingled in the same database or schema?
Is the data for multiple customers co-mingled in the same database or schema?
Is any DLP solution in place? What is implemented to prevent data leaks?
Is any DLP solution in place? What is implemented to prevent data leaks?
Are rules pertaining to remote access monitoring configured on DLP solution?
Are rules pertaining to remote access monitoring configured on DLP solution?
Are policies configured to monitor and detect data leakage over different file types?
Are policies configured to monitor and detect data leakage over different file types?
Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from the corporate network?
Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from the corporate network?
Any centralized crypto materials and key management infrastructure in place?
Any centralized crypto materials and key management infrastructure in place?
Please describe your Key Management controls including key rotation, key generation, key storage.
Please describe your Key Management controls including key rotation, key generation, key storage.
Does your system support dynamic key for encryption? How to store the key?
Does your system support dynamic key for encryption? How to store the key?
Authentication mechanisms must not allow passwords to be sent in clear text, using a minimum of TLS 1.2, and an encryption algorithm and strength of AES-256.
Authentication mechanisms must not allow passwords to be sent in clear text, using a minimum of TLS 1.2, and an encryption algorithm and strength of AES-256.
Passwords must be Hashed while stored using a salted non-reversible hash.
Passwords must be Hashed while stored using a salted non-reversible hash.
Which groups of staff have access to personal and sensitive data?
Which groups of staff have access to personal and sensitive data?
Is sensitive data encrypted when stored on laptops, desktops, and server hard drives?
Is sensitive data encrypted when stored on laptops, desktops, and server hard drives?
Does the provider retain rights to the customer data even if data is removed from the provider?
Does the provider retain rights to the customer data even if data is removed from the provider?
CLOUD SERVICE PROVIDER must be able to ensure any data and/or system disposal in case of service termination and in case of data and/or system end of life.
CLOUD SERVICE PROVIDER must be able to ensure any data and/or system disposal in case of service termination and in case of data and/or system end of life.
Will the application collect and/or host any User Generated Content (UGC)?
Will the application collect and/or host any User Generated Content (UGC)?
Entities shall be responsible for defining and updating the information/data retention policy and procedure.
Entities shall be responsible for defining and updating the information/data retention policy and procedure.
Patch Management
Are system and security patches applied to workstations on a routine basis?
Are system and security patches applied to workstations on a routine basis?
Are system and security patches applied to servers on a routine basis?
Are system and security patches applied to servers on a routine basis?
Are system and security patches tested prior to implementation in the production environment?
Are system and security patches tested prior to implementation in the production environment?
Are all systems and applications patched regularly?
Are all systems and applications patched regularly?
How are security patches rated?
How are security patches rated?
Describe the patch management process including frequency and process to apply patches, and how rapidly you can patch vulnerabilities across all components of the solution.
Describe the patch management process including frequency and process to apply patches, and how rapidly you can patch vulnerabilities across all components of the solution.
Does the vendor have a patch management process for the operating systems and software on their PCs, servers and network infrastructure?
Does the vendor have a patch management process for the operating systems and software on their PCs, servers and network infrastructure?
Are all security patches tested before they are deployed? How is this accomplished?
Are all security patches tested before they are deployed? How is this accomplished?
Are security patches regularly reviewed and applied to network and security devices?
Are security patches regularly reviewed and applied to network and security devices?
Please outline your planned approach to security patching of operating systems and applications.
Please outline your planned approach to security patching of operating systems and applications.
Is there a process in place for tracking patch compliance in terms of patches successfully applied, unapplied patch ratio, and latency in rollout?
Is there a process in place for tracking patch compliance in terms of patches successfully applied, unapplied patch ratio, and latency in rollout?
Documented patch management procedures shall be developed, implemented and maintained.
Documented patch management procedures shall be developed, implemented and maintained.
In the event a patch is not approved for use by the system vendor, a reason and risk mitigating controls for that patch shall be documented.
In the event a patch is not approved for use by the system vendor, a reason and risk mitigating controls for that patch shall be documented.
In the event a patch cannot be implemented due to current operations, an official exception shall be raised.
In the event a patch cannot be implemented due to current operations, an official exception shall be raised.
All supporting systems used to develop or integrate systems shall be appropriately and timely patched.
All supporting systems used to develop or integrate systems shall be appropriately and timely patched.
Establish a dedicated patch management process for components.
Establish a dedicated patch management process for components.
Test patches and updates prior to deploying software in production environments.
Test patches and updates prior to deploying software in production environments.
Change Management
Does the organisation have a formal change control process for IT changes?
Does the organisation have a formal change control process for IT changes?
Are the vendor's change control procedures compliant with ISO 27002?
Are the vendor's change control procedures compliant with ISO 27002?
Do formal change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability patching activities?
Do formal change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability patching activities?
Are changes to the production environment reviewed by at least two engineers/operations staff?
Are changes to the production environment reviewed by at least two engineers/operations staff?
Does the requirement discussed and agreed that CSP notify vendor for major changes of infrastructure/security configuration in cloud environment?
Does the requirement discussed and agreed that CSP notify vendor for major changes of infrastructure/security configuration in cloud environment?
Is a communication channel established between Vendor and the customer to notify the customer on the scheduled downtime and in case of any data security breach?
Is a communication channel established between Vendor and the customer to notify the customer on the scheduled downtime and in case of any data security breach?
Antivirus & Endpoint Security
Is antivirus software installed on workstations?
Is antivirus software installed on workstations?
Are controls in place to prevent administrators and other staff from downloading customer data to removable storage (USB memory sticks, CD ROM, etc.)?
Are controls in place to prevent administrators and other staff from downloading customer data to removable storage (USB memory sticks, CD ROM, etc.)?
What processes does the vendor have to detect and prevent viruses and other malicious software?
What processes does the vendor have to detect and prevent viruses and other malicious software?
Please outline any anti-malware (antivirus, etc.) tools that will be used to protect the system.
Please outline any anti-malware (antivirus, etc.) tools that will be used to protect the system.
In case of any exceptions due to which anti-malware activities fail, are alternative controls implemented to reduce the exposure on remote endpoints?
In case of any exceptions due to which anti-malware activities fail, are alternative controls implemented to reduce the exposure on remote endpoints?
How are endpoint devices that are connected to the corporate network managed and secured?
How are endpoint devices that are connected to the corporate network managed and secured?
Ensure that all anti-malicious code protection is up-to-date based on entity-defined maintenance schedules.
Ensure that all anti-malicious code protection is up-to-date based on entity-defined maintenance schedules.
Detail Out the mechanism for Antivirus installation, monitoring and signature updates of infrastructure.
Detail Out the mechanism for Antivirus installation, monitoring and signature updates of infrastructure.
What are the procedures for configuration management, patch installation and malware prevention for all servers and PCs?
What are the procedures for configuration management, patch installation and malware prevention for all servers and PCs?
How are endpoint devices that are connected to the corporate network managed and secured?
How are endpoint devices that are connected to the corporate network managed and secured?
SSO, Authentication & Integration
Mandatory Active Directory (SSO) Integration preferably through ADFS.
Mandatory Active Directory (SSO) Integration preferably through ADFS.
Can your solution link to our Identity Federation Tool in order to authenticate users and retrieve their user profile using SAML or OAuth?
Can your solution link to our Identity Federation Tool in order to authenticate users and retrieve their user profile using SAML or OAuth?
Are there interactions between the proposed solution and third-party applications/middleware?
Are there interactions between the proposed solution and third-party applications/middleware?
Is API integration available?
Is API integration available?
Does the application have APIs available for user provisioning and deprovisioning?
Does the application have APIs available for user provisioning and deprovisioning?
Does the application support any APIs? How are they consumed internally and externally?
Does the application support any APIs? How are they consumed internally and externally?
How the security of the exposed APIs is managed?
How the security of the exposed APIs is managed?
Does the platform support typical Single Sign-On paradigms (e.g., Active Directory)?
Does the platform support typical Single Sign-On paradigms (e.g., Active Directory)?
Explain how the system supports single sign-on and an external roles-based access control system.
Explain how the system supports single sign-on and an external roles-based access control system.
How to Authentication/Single Sign On (SSO): products should support the SAML2 standard?
How to Authentication/Single Sign On (SSO): products should support the SAML2 standard?
Products should support the secure VPN standard.
Products should support the secure VPN standard.
Describe your SSO and Federated Identity Enablement integration options.
Describe your SSO and Federated Identity Enablement integration options.
Does your solution support modern authentication methods, e.g., SAML and OAuth/OIDC against Azure AD?
Does your solution support modern authentication methods, e.g., SAML and OAuth/OIDC against Azure AD?
Will the service/solution require integration with other customer solutions/data, either on-premise or in the cloud?
Will the service/solution require integration with other customer solutions/data, either on-premise or in the cloud?
Does your service include Standard Reporting and Analytics Functionalities?
Does your service include Standard Reporting and Analytics Functionalities?
Can your service, via standard or custom interfaces/APIs, integrate with third party analytics?
Can your service, via standard or custom interfaces/APIs, integrate with third party analytics?
Do you support a Pub Sub architecture model for data transfer?
Do you support a Pub Sub architecture model for data transfer?
Please describe user provisioning, on-boarding and off-boarding of end users to the platform.
Please describe user provisioning, on-boarding and off-boarding of end users to the platform.
Third Party & Vendor Management
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards?
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards?
Are you managing the offer from end to end or do you rely on suppliers and/or subcontractors?
Are you managing the offer from end to end or do you rely on suppliers and/or subcontractors?
Are incident reporting obligations passed on to all 3rd parties who are subcontracted by you?
Are incident reporting obligations passed on to all 3rd parties who are subcontracted by you?
Service, Support & Upgrades
Is application of patches and upgrades under the provider's responsibility or the customer's?
Is application of patches and upgrades under the provider's responsibility or the customer's?
How is the customer informed of application upgrades impacting the end user's client?
How is the customer informed of application upgrades impacting the end user's client?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
How often is the platform scheduled for software patches and updates?
How often is the platform scheduled for software patches and updates?
What is the process for upgrades? How often are new versions released?
What is the process for upgrades? How often are new versions released?
Support requirement (version updates, future enhancement etc.)
Support requirement (version updates, future enhancement etc.)
What SLAs apply to the product/service?
What SLAs apply to the product/service?
What support methods are available?
What support methods are available?
How would you service and support Union Pacific as a customer?
How would you service and support Union Pacific as a customer?
Is there an individual or group with responsibility for security within the organization?
Is there an individual or group with responsibility for security within the organization?
If your customer later finds and reports a security hole/issue in the solution, will you provide the patch/fix at no cost?
If your customer later finds and reports a security hole/issue in the solution, will you provide the patch/fix at no cost?
Confirm with CSP which technologies and processes are used to ensure high levels of performance, reliability and availability.
Confirm with CSP which technologies and processes are used to ensure high levels of performance, reliability and availability.
Please provide a high-level diagram of your Continuous Integration and Continuous Deployment (CI/CD) pipeline.
Please provide a high-level diagram of your Continuous Integration and Continuous Deployment (CI/CD) pipeline.
What are the digital infrastructure secure configuration, vulnerability management and patch management policies, procedures and processes?
What are the digital infrastructure secure configuration, vulnerability management and patch management policies, procedures and processes?
Do you provide customers with security administrative guides that detail configurable security settings, their interpretation and how to implement them?
Do you provide customers with security administrative guides that detail configurable security settings, their interpretation and how to implement them?
It seems they support credit card processing for adding funds, what is their PCI DSS compliance exposure and level achieved?
It seems they support credit card processing for adding funds, what is their PCI DSS compliance exposure and level achieved?
Estimate implementation duration from project start to go live in first market.
Estimate implementation duration from project start to go live in first market.
Please describe the typical installation time and resources required for your solution.
Please describe the typical installation time and resources required for your solution.
What are any prerequisites recommended to use or access the solution/services effectively?
What are any prerequisites recommended to use or access the solution/services effectively?
How do you limit data exfiltration from production endpoint devices?
How do you limit data exfiltration from production endpoint devices?
Do you have breach detection systems and/or anomaly detection with alerting?
Do you have breach detection systems and/or anomaly detection with alerting?
Are the hosts where the service is running uniformly configured?
Are the hosts where the service is running uniformly configured?
If hosted on public cloud (Amazon, Google, Azure etc.) — security configurations are aligned with public cloud vendor security requirements?
If hosted on public cloud (Amazon, Google, Azure etc.) — security configurations are aligned with public cloud vendor security requirements?
Is there a service that will be a separate test environment? Will this include the use of dummy or live data?
Is there a service that will be a separate test environment? Will this include the use of dummy or live data?
Which all locations is the vendor working from or are their offices located?
Which all locations is the vendor working from or are their offices located?
Compliance Statements
Mandatory Business ownership to be mapped for all applications on-boarded.
Mandatory Business ownership to be mapped for all applications on-boarded.
Logs should be sent to the customer SIEM for continuous monitoring of security events from the application.
Logs should be sent to the customer SIEM for continuous monitoring of security events from the application.
Vendor has network forensics capabilities in place, and when required, the customer is assisted by the Vendor in performing any investigations on suspicious activities.
Vendor has network forensics capabilities in place, and when required, the customer is assisted by the Vendor in performing any investigations on suspicious activities.
The concept of least privilege should be employed for specific duties to adequately mitigate risk.
The concept of least privilege should be employed for specific duties to adequately mitigate risk.
Passwords shall be changed at an agreed upon interval.
Passwords shall be changed at an agreed upon interval.
Implement network-based technical controls that monitor communications with external systems and with key internal systems for suspicious traffic.
Implement network-based technical controls that monitor communications with external systems and with key internal systems for suspicious traffic.
Secure log-off procedures shall be followed (maximum session times, termination of inactive sessions).
Secure log-off procedures shall be followed (maximum session times, termination of inactive sessions).
System logging and auditing features are enabled and configured.
System logging and auditing features are enabled and configured.
System architecture/interconnection diagrams showing data flows, and physical and logical segmentation shall be reviewed and updated at least quarterly.
System architecture/interconnection diagrams showing data flows, and physical and logical segmentation shall be reviewed and updated at least quarterly.
Segregation, physically and/or logically, shall be implemented ensuring that the required levels of control for data flows and users are met.
Segregation, physically and/or logically, shall be implemented ensuring that the required levels of control for data flows and users are met.
Unsecured protocols or protocols with known vulnerabilities shall not be used.
Unsecured protocols or protocols with known vulnerabilities shall not be used.
All critical applications shall be reviewed and tested after operating system changes or other major changes.
All critical applications shall be reviewed and tested after operating system changes or other major changes.
Development, test and production environments shall be segregated.
Development, test and production environments shall be segregated.
Performance and capacity monitoring, such as system and network utilisation, shall be practiced.
Performance and capacity monitoring, such as system and network utilisation, shall be practiced.
Network IDS may be provided where necessary.
Network IDS may be provided where necessary.
Performance improvement plans shall be outlined based on successive progression of security controls maturity and based on identified nonconformities.
Performance improvement plans shall be outlined based on successive progression of security controls maturity and based on identified nonconformities.
Service Provider shall have strict patching practice to ensure security patches are applied rapidly.
Service Provider shall have strict patching practice to ensure security patches are applied rapidly.
Service Provider should have capabilities to integrate security systems with the customer's Security monitoring solution (SIEM).
Service Provider should have capabilities to integrate security systems with the customer's Security monitoring solution (SIEM).
CLOUD SERVICE PROVIDER (CSP) must ensure CLIENT that its infrastructure is always using up-to-date systems.
CLOUD SERVICE PROVIDER (CSP) must ensure CLIENT that its infrastructure is always using up-to-date systems.
In multi-tenancy cloud environment, CLOUD SERVICE PROVIDER must ensure the CLIENT environment is segregated from other tenants' environment.
In multi-tenancy cloud environment, CLOUD SERVICE PROVIDER must ensure the CLIENT environment is segregated from other tenants' environment.
The solution is to be deployed and operationalized in a configuration where application and data storage components will reside and operate on separate physical or virtual servers.
The solution is to be deployed and operationalized in a configuration where application and data storage components will reside and operate on separate physical or virtual servers.
Configure REST/Web services to explicitly validate content types.
Configure REST/Web services to explicitly validate content types.
Applications must be designed in such a way that it captures evidence of any action taken by the user to protect itself from denying authenticity of the activity.
Applications must be designed in such a way that it captures evidence of any action taken by the user to protect itself from denying authenticity of the activity.
The hosted application's architecture must be configured in such a way that data stores containing confidential or regulated information are logically located in a secure network segment.
The hosted application's architecture must be configured in such a way that data stores containing confidential or regulated information are logically located in a secure network segment.
The hosted web application's architecture is to be deployed and configured with a web application firewall to protect the application.
The hosted web application's architecture is to be deployed and configured with a web application firewall to protect the application.
All application created sessions, windows, forms, pages, and pop-ups that display highly confidential information must be terminated or closed after the user logs out.
All application created sessions, windows, forms, pages, and pop-ups that display highly confidential information must be terminated or closed after the user logs out.
Implement controls to log TLS connection failures.
Implement controls to log TLS connection failures.
Implement processes to measure the availability, quality, and adequate capacity of resources to deliver the required system performance.
Implement processes to measure the availability, quality, and adequate capacity of resources to deliver the required system performance.
Infrastructure & Compliance
How do you continuously monitor and report the compliance of your infrastructure in accordance to industry best practices (OWASP, SANS, SOC, ISO 27001)?
How do you continuously monitor and report the compliance of your infrastructure in accordance to industry best practices (OWASP, SANS, SOC, ISO 27001)?
Are Cloud Hosting services (IaaS) provided?
Are Cloud Hosting services (IaaS) provided?
What is the service delivery model? (IaaS/PaaS/SaaS)
What is the service delivery model? (IaaS/PaaS/SaaS)
Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?
Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?
What Services/products are being/will be provided to the customer?
What Services/products are being/will be provided to the customer?
Do you offer an on-premise solution?
Do you offer an on-premise solution?
Describe in detail your product's architecture.
Describe in detail your product's architecture.
Describe the key differentiators of your technical architecture.
Describe the key differentiators of your technical architecture.
Describe the minimum and recommended system requirements for your solution.
Describe the minimum and recommended system requirements for your solution.
Describe your solution's networking requirements and capabilities.
Describe your solution's networking requirements and capabilities.
Is your solution available in a seamless manner to access as an app on different mobile devices and as web app on different desktop devices?
Is your solution available in a seamless manner to access as an app on different mobile devices and as web app on different desktop devices?
Mobile Device Availability? (Android and iOS)
Mobile Device Availability? (Android and iOS)
Tablet Device Availability? (Android and iOS)
Tablet Device Availability? (Android and iOS)
Browser compatibility? (MS Edge, Chrome, Safari, IE)
Browser compatibility? (MS Edge, Chrome, Safari, IE)
Technology Stack? (Infrastructure / Frontend / Backend / Database)
Technology Stack? (Infrastructure / Frontend / Backend / Database)
What technology languages/platforms/stacks/components are utilized in the scope of the application?
What technology languages/platforms/stacks/components are utilized in the scope of the application?
Is the application developed on the latest language framework?
Is the application developed on the latest language framework?
Is the application developed using secure libraries?
Is the application developed using secure libraries?
Where is the primary data center? Backup data center?
Where is the primary data center? Backup data center?
Describe the network topology.
Describe the network topology.
Describe your network configuration and how your sensitive data system is protected.
Describe your network configuration and how your sensitive data system is protected.
Backup, Recovery & Business Continuity
Have you implemented backup or recovery mechanisms to ensure compliance with regulatory, statutory, contractual or business requirements?
Have you implemented backup or recovery mechanisms to ensure compliance with regulatory, statutory, contractual or business requirements?
If using virtual infrastructure, does your cloud solution include independent hardware restore and recovery capabilities?
If using virtual infrastructure, does your cloud solution include independent hardware restore and recovery capabilities?
Does your infrastructure environment solution include software/provider independent restore and recovery capabilities?
Does your infrastructure environment solution include software/provider independent restore and recovery capabilities?
Do you test your backup or redundancy mechanisms at least annually?
Do you test your backup or redundancy mechanisms at least annually?
Does the RTO and RPO of CSP's contingency plan meet with vendor's customer requirements?
Does the RTO and RPO of CSP's contingency plan meet with vendor's customer requirements?
Has Supplier implemented data backup and recovery procedures to prevent data loss, unwanted overwrite and/or destruction?
Has Supplier implemented data backup and recovery procedures to prevent data loss, unwanted overwrite and/or destruction?
Does the organisation store backups offsite?
Does the organisation store backups offsite?
Are all systems, assets and information backed up based on a BIA which establishes RPO/RTO?
Are all systems, assets and information backed up based on a BIA which establishes RPO/RTO?
Shall a backup be taken before and after any major changes to hardware, OS, application or configuration?
Shall a backup be taken before and after any major changes to hardware, OS, application or configuration?
There shall be a detailed backup procedure based on the established RPO and RTO.
There shall be a detailed backup procedure based on the established RPO and RTO.
What backup and disaster recovery plans are in place to avoid data loss/service loss in the time of contingency?
What backup and disaster recovery plans are in place to avoid data loss/service loss in the time of contingency?
Have you applied a data backup mechanism? What is the frequency of backup?
Have you applied a data backup mechanism? What is the frequency of backup?
Is your backup mechanism tested at least annually?
Is your backup mechanism tested at least annually?
Are you able to restore user data upon loss through disk recovery mechanisms or stored backups?
Are you able to restore user data upon loss through disk recovery mechanisms or stored backups?
Do you possess ISO 22301 for Business Continuity?
Do you possess ISO 22301 for Business Continuity?
What type of DR options do you provide for my data within your offering?
What type of DR options do you provide for my data within your offering?
Application Development & SDLC
Do you test your applications before they are promoted into the Production environment? What types of testing do you perform?
Do you test your applications before they are promoted into the Production environment? What types of testing do you perform?
Do you have a defined quality change control and testing process in place?
Do you have a defined quality change control and testing process in place?
Do you have controls in place to ensure that standards of quality are being met for all software development?
Do you have controls in place to ensure that standards of quality are being met for all software development?
What controls do you have in place to detect source code security defects for any outsourced software development activities?
What controls do you have in place to detect source code security defects for any outsourced software development activities?
Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?
Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?
Do you use an automated source code analysis tool to detect security defects in code prior to production?
Do you use an automated source code analysis tool to detect security defects in code prior to production?
Privacy by Design is incorporated into all your developments and services.
Privacy by Design is incorporated into all your developments and services.
Does the software development lifecycle in the organisation specifically focus on security?
Does the software development lifecycle in the organisation specifically focus on security?
Are development, test and production environments separate?
Are development, test and production environments separate?
Is production data ever used in a test environment?
Is production data ever used in a test environment?
Is testing of applications done on a separate testing facility and not on production data?
Is testing of applications done on a separate testing facility and not on production data?
Are patches tested in a UAT instance before deployment on the production server?
Are patches tested in a UAT instance before deployment on the production server?
Are applications and operating system software implemented after extensive and successful security testing?
Are applications and operating system software implemented after extensive and successful security testing?
Do you do static code analysis?
Do you do static code analysis?
How do you ensure code is being developed securely?
How do you ensure code is being developed securely?
What percentage of your production code is covered by automated tests?
What percentage of your production code is covered by automated tests?
Is a staging/pre-production system used to validate build artifacts before promotion to production?
Is a staging/pre-production system used to validate build artifacts before promotion to production?
How is application security testing performed? Internal, third parties, or both? How often is it tested?
How is application security testing performed? Internal, third parties, or both? How often is it tested?
Any product pre-release security threat modeling, secure coding practice, security architecture review and penetration testing?
Any product pre-release security threat modeling, secure coding practice, security architecture review and penetration testing?
Is application development following secure coding standards such as OWASP?
Is application development following secure coding standards such as OWASP?
Is the code reviewed by peer or externally?
Is the code reviewed by peer or externally?
Please provide further information about your handling of security requirements during development.
Please provide further information about your handling of security requirements during development.
Describe the management system in place to fix vulnerabilities identified during control activities.
Describe the management system in place to fix vulnerabilities identified during control activities.
Do you have a managed process for approving new 3rd Party Libraries?
Do you have a managed process for approving new 3rd Party Libraries?
Develop applications based on secure coding guidelines.
Develop applications based on secure coding guidelines.
Implement controls to obfuscate application code prior to compilation.
Implement controls to obfuscate application code prior to compilation.
Configures web services in accordance with OWASP.
Configures web services in accordance with OWASP.
Configure web services to prevent sensitive information leakage in response headers.
Configure web services to prevent sensitive information leakage in response headers.
Configure web services to use secure HTTP headers.
Configure web services to use secure HTTP headers.
Impose file upload frequency restrictions in applications to prevent abuse or attack.
Impose file upload frequency restrictions in applications to prevent abuse or attack.
Access Control & Authentication
Do you have an identity management system (enabling classification of data for a customer) in place to enable both role-based and context-based entitlement to data?
Do you have an identity management system (enabling classification of data for a customer) in place to enable both role-based and context-based entitlement to data?
Do you provide customers with strong (multifactor) authentication options (e.g., digital certs, tokens, biometrics)?
Do you provide customers with strong (multifactor) authentication options (e.g., digital certs, tokens, biometrics)?
Does the SaaS support MFA such as OTP, security tokens, or biometrics?
Does the SaaS support MFA such as OTP, security tokens, or biometrics?
Do you allow customers to define password and account lockout policies for their accounts?
Do you allow customers to define password and account lockout policies for their accounts?
Do you restrict personnel access to all management functions or administrative access based on the principle of least privilege?
Do you restrict personnel access to all management functions or administrative access based on the principle of least privilege?
How do you verify password strength?
How do you verify password strength?
How are passwords stored (encrypted, hashed, algorithm or hashing methodology)?
How are passwords stored (encrypted, hashed, algorithm or hashing methodology)?
How are passwords hashed?
How are passwords hashed?
Does your solution follow any particular internationally accepted best practices or standards for password management?
Does your solution follow any particular internationally accepted best practices or standards for password management?
Does the solution force the new user to change the password for their first logon and on expiry?
Does the solution force the new user to change the password for their first logon and on expiry?
Can passwords be changed by the user at anytime?
Can passwords be changed by the user at anytime?
Can the solution alert the security administrator to delete a UserID if it has not been used for predefined days?
Can the solution alert the security administrator to delete a UserID if it has not been used for predefined days?
Can users be prevented from logging into multiple terminals simultaneously?
Can users be prevented from logging into multiple terminals simultaneously?
Does the solution have other options of logon inputs besides user ID and password?
Does the solution have other options of logon inputs besides user ID and password?
What is the idle session timeout and session expiration?
What is the idle session timeout and session expiration?
Is there account lockout functionality? What is the maximum number of failed login attempts before the account gets locked out?
Is there account lockout functionality? What is the maximum number of failed login attempts before the account gets locked out?
What is the account unlock process?
What is the account unlock process?
Does access provided to users and administrators follow Need to Know basis?
Does access provided to users and administrators follow Need to Know basis?
Is two-factor authentication enabled for end users and Administrators?
Is two-factor authentication enabled for end users and Administrators?
Does MFA apply while accessing cloud environment/applications remotely (VPN, VDI)?
Does MFA apply while accessing cloud environment/applications remotely (VPN, VDI)?
How is Segregation of Duties (SoD) implemented for various user access roles?
How is Segregation of Duties (SoD) implemented for various user access roles?
Detail out the organization password policy.
Detail out the organization password policy.
Supplier has internal processes for identity and access management.
Supplier has internal processes for identity and access management.
Control panel or administration console to the service is properly protected from abuse. Segregation of duties is implemented for privileged users.
Control panel or administration console to the service is properly protected from abuse. Segregation of duties is implemented for privileged users.
What kind of identity and access management services are provided?
What kind of identity and access management services are provided?
Are access to utility programs used to manage virtualized partitions appropriately restricted and monitored?
Are access to utility programs used to manage virtualized partitions appropriately restricted and monitored?
Do you have complexity or length requirements for passwords?
Do you have complexity or length requirements for passwords?
Do you review user access and rights at least annually?
Do you review user access and rights at least annually?
Network Security & Firewall
Do your network architecture diagrams clearly identify high-risk environments and data flows?
Do your network architecture diagrams clearly identify high-risk environments and data flows?
Are all non-internet facing systems placed behind a firewall?
Are all non-internet facing systems placed behind a firewall?
Does the vendor have a comprehensive network architecture diagram covering infrastructure used for customer operations?
Does the vendor have a comprehensive network architecture diagram covering infrastructure used for customer operations?
Is the internet access secure through a proxy/firewall?
Is the internet access secure through a proxy/firewall?
Are roles and responsibilities defined for Firewall configuration?
Are roles and responsibilities defined for Firewall configuration?
Is the firewall rule base reviewed at regular intervals?
Is the firewall rule base reviewed at regular intervals?
Does the firewall have real-time logging and alerting capability?
Does the firewall have real-time logging and alerting capability?
Are prior management approvals obtained and communication provided to the customer in case of any external connections to parties other than the customer?
Are prior management approvals obtained and communication provided to the customer in case of any external connections to parties other than the customer?
Are all servers, end user devices configured according to security standards as part of the build process?
Are all servers, end user devices configured according to security standards as part of the build process?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Is wireless access allowed in your organisation?
Is wireless access allowed in your organisation?
Are network boundaries protected by firewalls?
Are network boundaries protected by firewalls?
Is data import, data export, and service management conducted over secure, industry-accepted standardized network protocols?
Is data import, data export, and service management conducted over secure, industry-accepted standardized network protocols?
What type/model of Firewall is implemented to segregate security zones and protect the infrastructure from external attacks?
What type/model of Firewall is implemented to segregate security zones and protect the infrastructure from external attacks?
How are operating systems hardened to provide only the necessary ports, protocols and services to meet business needs?
How are operating systems hardened to provide only the necessary ports, protocols and services to meet business needs?
Is the network used for providing service to the customer logically and physically segregated? Is the server placed on a separate LAN?
Is the network used for providing service to the customer logically and physically segregated? Is the server placed on a separate LAN?
Are external access (e.g., remote, wireless, third party) to the network only permitted after a user has been identified and authenticated?
Are external access (e.g., remote, wireless, third party) to the network only permitted after a user has been identified and authenticated?
Whether Firewall, IPS/IDS, DLP, Anti APT, SIEM, AntiSpoofing and other security solutions have been implemented?
Whether Firewall, IPS/IDS, DLP, Anti APT, SIEM, AntiSpoofing and other security solutions have been implemented?
Are internal and external networks separated by firewalls with access policies and rules?
Are internal and external networks separated by firewalls with access policies and rules?
Any host-based IPS for critical systems? Any next generation firewall, IPS and web application firewall?
Any host-based IPS for critical systems? Any next generation firewall, IPS and web application firewall?
Are network components and computers password protected?
Are network components and computers password protected?
Is the production network segmented into different zones based on security levels?
Is the production network segmented into different zones based on security levels?
What is the process for making changes to network configuration?
What is the process for making changes to network configuration?
Describe how you protect against attacks that target virtual infrastructure directly (shimming, Blue Pill, Hyper jumping, etc.)
Describe how you protect against attacks that target virtual infrastructure directly (shimming, Blue Pill, Hyper jumping, etc.)
Is application deployed behind the firewall and IDS/IPS?
Is application deployed behind the firewall and IDS/IPS?
Does WAF protect from application attacks?
Does WAF protect from application attacks?
Service Provider should have solid application security controls such as WAF and RASP to detect and block web-based attacks such as XSS, SQL Injection, and CSRF.
Service Provider should have solid application security controls such as WAF and RASP to detect and block web-based attacks such as XSS, SQL Injection, and CSRF.
What cryptographic frameworks are used to secure data in transit over public networks?
What cryptographic frameworks are used to secure data in transit over public networks?
Describe the network protocols used to communicate between components of the system (e.g., HTTPs, LDAP, SSL).
Describe the network protocols used to communicate between components of the system (e.g., HTTPs, LDAP, SSL).
I cannot find anywhere in their documentation that they support IP address range restriction for the application API, could we get confirmation?
I cannot find anywhere in their documentation that they support IP address range restriction for the application API, could we get confirmation?
Logging, Monitoring & Audit
Do you monitor and log privileged access (e.g., administrator level) to information security management systems?
Do you monitor and log privileged access (e.g., administrator level) to information security management systems?
Does the organisation maintain audit logs of user activities, exceptions, and security events on all systems that store or process sensitive data?
Does the organisation maintain audit logs of user activities, exceptions, and security events on all systems that store or process sensitive data?
Do these audit logs contain details regarding the User ID, timestamp, and what actions were performed?
Do these audit logs contain details regarding the User ID, timestamp, and what actions were performed?
At what frequency are these logs reviewed?
At what frequency are these logs reviewed?
Is the ability to delete event logs restricted to only superadmin or host admin?
Is the ability to delete event logs restricted to only superadmin or host admin?
Are changes made to virtual machines or moving of an image made immediately available to customers through electronic methods?
Are changes made to virtual machines or moving of an image made immediately available to customers through electronic methods?
Are system administrator and system operator activities monitored and logged?
Are system administrator and system operator activities monitored and logged?
Are the system clocks of all information processing systems synchronized with an agreed accurate time source?
Are the system clocks of all information processing systems synchronized with an agreed accurate time source?
Do you use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference?
Do you use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference?
What is the log retention policy? Who has access to logs in your organization?
What is the log retention policy? Who has access to logs in your organization?
Who has access to Security logs?
Who has access to Security logs?
How long are security logs maintained by the provider?
How long are security logs maintained by the provider?
IS logging enabled for all components, such as network devices, servers, DBs, IAM, Cloud Services?
IS logging enabled for all components, such as network devices, servers, DBs, IAM, Cloud Services?
Do you have a SIEM for monitoring and maintaining logs over security incidents?
Do you have a SIEM for monitoring and maintaining logs over security incidents?
Provide the scope of data sources merged in your SIEM and confirm if configured for granular analysis and real-time alerting.
Provide the scope of data sources merged in your SIEM and confirm if configured for granular analysis and real-time alerting.
Is a SOC implemented to monitor the software solution? Can the customer gain access to the SOC alert and response reporting?
Is a SOC implemented to monitor the software solution? Can the customer gain access to the SOC alert and response reporting?
Does the Company run a Security Operations Center (or equivalent) which allows detection and response to Cyber Security Incidents?
Does the Company run a Security Operations Center (or equivalent) which allows detection and response to Cyber Security Incidents?
Are all security events (authentication events, SSH session commands, privilege elevations) in production logged?
Are all security events (authentication events, SSH session commands, privilege elevations) in production logged?
Can logs be integrated into a SIEM system?
Can logs be integrated into a SIEM system?
Is a service available for APIs to push the logs of our company's administrators' operations on the Vendor platform in real time?
Is a service available for APIs to push the logs of our company's administrators' operations on the Vendor platform in real time?
Is there a support for operation logs on the admin console? What operations do the audit logs monitor?
Is there a support for operation logs on the admin console? What operations do the audit logs monitor?
Logging and monitoring is in place for analysing activities of privileged users as well as for inspecting and analysing network traffic.
Logging and monitoring is in place for analysing activities of privileged users as well as for inspecting and analysing network traffic.
Logs are reviewed in a continuous manner to improve performance as well as detect potential security issues.
Logs are reviewed in a continuous manner to improve performance as well as detect potential security issues.
Do you monitor and log user, system and administrative access?
Do you monitor and log user, system and administrative access?
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently?
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently?
Does your internal security group carry out audits on your Information Security Management System?
Does your internal security group carry out audits on your Information Security Management System?
Will event logging/audit mechanisms be turned on at all times for the system?
Will event logging/audit mechanisms be turned on at all times for the system?
Will logs be regularly reviewed?
Will logs be regularly reviewed?
Are systems and networks monitored for security events?
Are systems and networks monitored for security events?
Do you have any monitoring tool in place to get timely alerts on when a device is going down, restarted, or resources are over utilized?
Do you have any monitoring tool in place to get timely alerts on when a device is going down, restarted, or resources are over utilized?
How do you monitor system integrity, logs, intrusion detection, and system access?
How do you monitor system integrity, logs, intrusion detection, and system access?
Are audit logs maintained that record user activities, exceptions, success and failure logons, policy changes, and information security events?
Are audit logs maintained that record user activities, exceptions, success and failure logons, policy changes, and information security events?
Are servers configured to capture who accessed a system and what changes were made?
Are servers configured to capture who accessed a system and what changes were made?
Detail out the process for security event logging and monitoring (including applicable correlation rules). Detail the log retention period and protection mechanisms to prevent log tampering.
Detail out the process for security event logging and monitoring (including applicable correlation rules). Detail the log retention period and protection mechanisms to prevent log tampering.
What alerts can be set in the system?
What alerts can be set in the system?
Data Protection & Encryption
Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific customer without freezing other customer data?
Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific customer without freezing other customer data?
Do you have the capability to recover data for a specific customer in the case of a failure or data loss?
Do you have the capability to recover data for a specific customer in the case of a failure or data loss?
What is the purpose for processing the Personal Data?
What is the purpose for processing the Personal Data?
Can Supplier provide a data map which includes all country locations where Personal Data would traverse, be stored or processed?
Can Supplier provide a data map which includes all country locations where Personal Data would traverse, be stored or processed?
Have you implemented measures for prevention of loss of PII data? (e.g., DLP, restricted access controls, log recording, encryption)
Have you implemented measures for prevention of loss of PII data? (e.g., DLP, restricted access controls, log recording, encryption)
Is data import, data export, and service management conducted over secure industry-accepted standardized network protocols?
Is data import, data export, and service management conducted over secure industry-accepted standardized network protocols?
Describe how you make sure the customer's data is properly segregated from other customers' in multi-tenant solutions.
Describe how you make sure the customer's data is properly segregated from other customers' in multi-tenant solutions.
Would you support encryption keys generated by our own PKI that would be used to encrypt data?
Would you support encryption keys generated by our own PKI that would be used to encrypt data?
What type of mechanisms do you implement to make sure Data Integrity is protected against errors, corruption or misuse?
What type of mechanisms do you implement to make sure Data Integrity is protected against errors, corruption or misuse?
Describe how you make sure the application is properly protected against exploitation of CVE vulnerabilities prior to allowing it to go to production.
Describe how you make sure the application is properly protected against exploitation of CVE vulnerabilities prior to allowing it to go to production.
Is data import and export conducted over secure, industry-accepted standardized network protocols?
Is data import and export conducted over secure, industry-accepted standardized network protocols?
Is sensitive information transferred to external recipients? If so, are controls in place to protect it?
Is sensitive information transferred to external recipients? If so, are controls in place to protect it?
Are there security procedures for the decommissioning of IT equipment and storage devices which contain sensitive information?
Are there security procedures for the decommissioning of IT equipment and storage devices which contain sensitive information?
Is the data classified top secret/confidential/PII stored separately from public data or data of other organizations residing on the same cloud?
Is the data classified top secret/confidential/PII stored separately from public data or data of other organizations residing on the same cloud?
How is data loss prevented and how is high availability ensured?
How is data loss prevented and how is high availability ensured?
If other tenants' information/data is compromised, how is the vendor making sure that the customer organization's data is not impacted?
If other tenants' information/data is compromised, how is the vendor making sure that the customer organization's data is not impacted?
What security measures are implemented by the Application Service Provider for guarding against data leakage/data corruption/data breach?
What security measures are implemented by the Application Service Provider for guarding against data leakage/data corruption/data breach?
Is the data for multiple customers co-mingled in the same database or schema?
Is the data for multiple customers co-mingled in the same database or schema?
Is any DLP solution in place? What is implemented to prevent data leaks?
Is any DLP solution in place? What is implemented to prevent data leaks?
Are rules pertaining to remote access monitoring configured on DLP solution?
Are rules pertaining to remote access monitoring configured on DLP solution?
Are policies configured to monitor and detect data leakage over different file types?
Are policies configured to monitor and detect data leakage over different file types?
Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from the corporate network?
Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from the corporate network?
Any centralized crypto materials and key management infrastructure in place?
Any centralized crypto materials and key management infrastructure in place?
Please describe your Key Management controls including key rotation, key generation, key storage.
Please describe your Key Management controls including key rotation, key generation, key storage.
Does your system support dynamic key for encryption? How to store the key?
Does your system support dynamic key for encryption? How to store the key?
Authentication mechanisms must not allow passwords to be sent in clear text, using a minimum of TLS 1.2, and an encryption algorithm and strength of AES-256.
Authentication mechanisms must not allow passwords to be sent in clear text, using a minimum of TLS 1.2, and an encryption algorithm and strength of AES-256.
Passwords must be Hashed while stored using a salted non-reversible hash.
Passwords must be Hashed while stored using a salted non-reversible hash.
Which groups of staff have access to personal and sensitive data?
Which groups of staff have access to personal and sensitive data?
Is sensitive data encrypted when stored on laptops, desktops, and server hard drives?
Is sensitive data encrypted when stored on laptops, desktops, and server hard drives?
Does the provider retain rights to the customer data even if data is removed from the provider?
Does the provider retain rights to the customer data even if data is removed from the provider?
CLOUD SERVICE PROVIDER must be able to ensure any data and/or system disposal in case of service termination and in case of data and/or system end of life.
CLOUD SERVICE PROVIDER must be able to ensure any data and/or system disposal in case of service termination and in case of data and/or system end of life.
Will the application collect and/or host any User Generated Content (UGC)?
Will the application collect and/or host any User Generated Content (UGC)?
Entities shall be responsible for defining and updating the information/data retention policy and procedure.
Entities shall be responsible for defining and updating the information/data retention policy and procedure.
Patch Management
Are system and security patches applied to workstations on a routine basis?
Are system and security patches applied to workstations on a routine basis?
Are system and security patches applied to servers on a routine basis?
Are system and security patches applied to servers on a routine basis?
Are system and security patches tested prior to implementation in the production environment?
Are system and security patches tested prior to implementation in the production environment?
Are all systems and applications patched regularly?
Are all systems and applications patched regularly?
How are security patches rated?
How are security patches rated?
Describe the patch management process including frequency and process to apply patches, and how rapidly you can patch vulnerabilities across all components of the solution.
Describe the patch management process including frequency and process to apply patches, and how rapidly you can patch vulnerabilities across all components of the solution.
Does the vendor have a patch management process for the operating systems and software on their PCs, servers and network infrastructure?
Does the vendor have a patch management process for the operating systems and software on their PCs, servers and network infrastructure?
Are all security patches tested before they are deployed? How is this accomplished?
Are all security patches tested before they are deployed? How is this accomplished?
Are security patches regularly reviewed and applied to network and security devices?
Are security patches regularly reviewed and applied to network and security devices?
Please outline your planned approach to security patching of operating systems and applications.
Please outline your planned approach to security patching of operating systems and applications.
Is there a process in place for tracking patch compliance in terms of patches successfully applied, unapplied patch ratio, and latency in rollout?
Is there a process in place for tracking patch compliance in terms of patches successfully applied, unapplied patch ratio, and latency in rollout?
Documented patch management procedures shall be developed, implemented and maintained.
Documented patch management procedures shall be developed, implemented and maintained.
In the event a patch is not approved for use by the system vendor, a reason and risk mitigating controls for that patch shall be documented.
In the event a patch is not approved for use by the system vendor, a reason and risk mitigating controls for that patch shall be documented.
In the event a patch cannot be implemented due to current operations, an official exception shall be raised.
In the event a patch cannot be implemented due to current operations, an official exception shall be raised.
All supporting systems used to develop or integrate systems shall be appropriately and timely patched.
All supporting systems used to develop or integrate systems shall be appropriately and timely patched.
Establish a dedicated patch management process for components.
Establish a dedicated patch management process for components.
Test patches and updates prior to deploying software in production environments.
Test patches and updates prior to deploying software in production environments.
Change Management
Does the organisation have a formal change control process for IT changes?
Does the organisation have a formal change control process for IT changes?
Are the vendor's change control procedures compliant with ISO 27002?
Are the vendor's change control procedures compliant with ISO 27002?
Do formal change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability patching activities?
Do formal change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability patching activities?
Are changes to the production environment reviewed by at least two engineers/operations staff?
Are changes to the production environment reviewed by at least two engineers/operations staff?
Does the requirement discussed and agreed that CSP notify vendor for major changes of infrastructure/security configuration in cloud environment?
Does the requirement discussed and agreed that CSP notify vendor for major changes of infrastructure/security configuration in cloud environment?
Is a communication channel established between Vendor and the customer to notify the customer on the scheduled downtime and in case of any data security breach?
Is a communication channel established between Vendor and the customer to notify the customer on the scheduled downtime and in case of any data security breach?
Antivirus & Endpoint Security
Is antivirus software installed on workstations?
Is antivirus software installed on workstations?
Are controls in place to prevent administrators and other staff from downloading customer data to removable storage (USB memory sticks, CD ROM, etc.)?
Are controls in place to prevent administrators and other staff from downloading customer data to removable storage (USB memory sticks, CD ROM, etc.)?
What processes does the vendor have to detect and prevent viruses and other malicious software?
What processes does the vendor have to detect and prevent viruses and other malicious software?
Please outline any anti-malware (antivirus, etc.) tools that will be used to protect the system.
Please outline any anti-malware (antivirus, etc.) tools that will be used to protect the system.
In case of any exceptions due to which anti-malware activities fail, are alternative controls implemented to reduce the exposure on remote endpoints?
In case of any exceptions due to which anti-malware activities fail, are alternative controls implemented to reduce the exposure on remote endpoints?
How are endpoint devices that are connected to the corporate network managed and secured?
How are endpoint devices that are connected to the corporate network managed and secured?
Ensure that all anti-malicious code protection is up-to-date based on entity-defined maintenance schedules.
Ensure that all anti-malicious code protection is up-to-date based on entity-defined maintenance schedules.
Detail Out the mechanism for Antivirus installation, monitoring and signature updates of infrastructure.
Detail Out the mechanism for Antivirus installation, monitoring and signature updates of infrastructure.
What are the procedures for configuration management, patch installation and malware prevention for all servers and PCs?
What are the procedures for configuration management, patch installation and malware prevention for all servers and PCs?
How are endpoint devices that are connected to the corporate network managed and secured?
How are endpoint devices that are connected to the corporate network managed and secured?
SSO, Authentication & Integration
Mandatory Active Directory (SSO) Integration preferably through ADFS.
Mandatory Active Directory (SSO) Integration preferably through ADFS.
Can your solution link to our Identity Federation Tool in order to authenticate users and retrieve their user profile using SAML or OAuth?
Can your solution link to our Identity Federation Tool in order to authenticate users and retrieve their user profile using SAML or OAuth?
Are there interactions between the proposed solution and third-party applications/middleware?
Are there interactions between the proposed solution and third-party applications/middleware?
Is API integration available?
Is API integration available?
Does the application have APIs available for user provisioning and deprovisioning?
Does the application have APIs available for user provisioning and deprovisioning?
Does the application support any APIs? How are they consumed internally and externally?
Does the application support any APIs? How are they consumed internally and externally?
How the security of the exposed APIs is managed?
How the security of the exposed APIs is managed?
Does the platform support typical Single Sign-On paradigms (e.g., Active Directory)?
Does the platform support typical Single Sign-On paradigms (e.g., Active Directory)?
Explain how the system supports single sign-on and an external roles-based access control system.
Explain how the system supports single sign-on and an external roles-based access control system.
How to Authentication/Single Sign On (SSO): products should support the SAML2 standard?
How to Authentication/Single Sign On (SSO): products should support the SAML2 standard?
Products should support the secure VPN standard.
Products should support the secure VPN standard.
Describe your SSO and Federated Identity Enablement integration options.
Describe your SSO and Federated Identity Enablement integration options.
Does your solution support modern authentication methods, e.g., SAML and OAuth/OIDC against Azure AD?
Does your solution support modern authentication methods, e.g., SAML and OAuth/OIDC against Azure AD?
Will the service/solution require integration with other customer solutions/data, either on-premise or in the cloud?
Will the service/solution require integration with other customer solutions/data, either on-premise or in the cloud?
Does your service include Standard Reporting and Analytics Functionalities?
Does your service include Standard Reporting and Analytics Functionalities?
Can your service, via standard or custom interfaces/APIs, integrate with third party analytics?
Can your service, via standard or custom interfaces/APIs, integrate with third party analytics?
Do you support a Pub Sub architecture model for data transfer?
Do you support a Pub Sub architecture model for data transfer?
Please describe user provisioning, on-boarding and off-boarding of end users to the platform.
Please describe user provisioning, on-boarding and off-boarding of end users to the platform.
Third Party & Vendor Management
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards?
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards?
Are you managing the offer from end to end or do you rely on suppliers and/or subcontractors?
Are you managing the offer from end to end or do you rely on suppliers and/or subcontractors?
Are incident reporting obligations passed on to all 3rd parties who are subcontracted by you?
Are incident reporting obligations passed on to all 3rd parties who are subcontracted by you?
Service, Support & Upgrades
Is application of patches and upgrades under the provider's responsibility or the customer's?
Is application of patches and upgrades under the provider's responsibility or the customer's?
How is the customer informed of application upgrades impacting the end user's client?
How is the customer informed of application upgrades impacting the end user's client?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
How often is the platform scheduled for software patches and updates?
How often is the platform scheduled for software patches and updates?
What is the process for upgrades? How often are new versions released?
What is the process for upgrades? How often are new versions released?
Support requirement (version updates, future enhancement etc.)
Support requirement (version updates, future enhancement etc.)
What SLAs apply to the product/service?
What SLAs apply to the product/service?
What support methods are available?
What support methods are available?
How would you service and support Union Pacific as a customer?
How would you service and support Union Pacific as a customer?
Is there an individual or group with responsibility for security within the organization?
Is there an individual or group with responsibility for security within the organization?
If your customer later finds and reports a security hole/issue in the solution, will you provide the patch/fix at no cost?
If your customer later finds and reports a security hole/issue in the solution, will you provide the patch/fix at no cost?
Confirm with CSP which technologies and processes are used to ensure high levels of performance, reliability and availability.
Confirm with CSP which technologies and processes are used to ensure high levels of performance, reliability and availability.
Please provide a high-level diagram of your Continuous Integration and Continuous Deployment (CI/CD) pipeline.
Please provide a high-level diagram of your Continuous Integration and Continuous Deployment (CI/CD) pipeline.
What are the digital infrastructure secure configuration, vulnerability management and patch management policies, procedures and processes?
What are the digital infrastructure secure configuration, vulnerability management and patch management policies, procedures and processes?
Do you provide customers with security administrative guides that detail configurable security settings, their interpretation and how to implement them?
Do you provide customers with security administrative guides that detail configurable security settings, their interpretation and how to implement them?
It seems they support credit card processing for adding funds, what is their PCI DSS compliance exposure and level achieved?
It seems they support credit card processing for adding funds, what is their PCI DSS compliance exposure and level achieved?
Estimate implementation duration from project start to go live in first market.
Estimate implementation duration from project start to go live in first market.
Please describe the typical installation time and resources required for your solution.
Please describe the typical installation time and resources required for your solution.
What are any prerequisites recommended to use or access the solution/services effectively?
What are any prerequisites recommended to use or access the solution/services effectively?
How do you limit data exfiltration from production endpoint devices?
How do you limit data exfiltration from production endpoint devices?
Do you have breach detection systems and/or anomaly detection with alerting?
Do you have breach detection systems and/or anomaly detection with alerting?
Are the hosts where the service is running uniformly configured?
Are the hosts where the service is running uniformly configured?
If hosted on public cloud (Amazon, Google, Azure etc.) — security configurations are aligned with public cloud vendor security requirements?
If hosted on public cloud (Amazon, Google, Azure etc.) — security configurations are aligned with public cloud vendor security requirements?
Is there a service that will be a separate test environment? Will this include the use of dummy or live data?
Is there a service that will be a separate test environment? Will this include the use of dummy or live data?
Which all locations is the vendor working from or are their offices located?
Which all locations is the vendor working from or are their offices located?
Compliance Statements
Mandatory Business ownership to be mapped for all applications on-boarded.
Mandatory Business ownership to be mapped for all applications on-boarded.
Logs should be sent to the customer SIEM for continuous monitoring of security events from the application.
Logs should be sent to the customer SIEM for continuous monitoring of security events from the application.
Vendor has network forensics capabilities in place, and when required, the customer is assisted by the Vendor in performing any investigations on suspicious activities.
Vendor has network forensics capabilities in place, and when required, the customer is assisted by the Vendor in performing any investigations on suspicious activities.
The concept of least privilege should be employed for specific duties to adequately mitigate risk.
The concept of least privilege should be employed for specific duties to adequately mitigate risk.
Passwords shall be changed at an agreed upon interval.
Passwords shall be changed at an agreed upon interval.
Implement network-based technical controls that monitor communications with external systems and with key internal systems for suspicious traffic.
Implement network-based technical controls that monitor communications with external systems and with key internal systems for suspicious traffic.
Secure log-off procedures shall be followed (maximum session times, termination of inactive sessions).
Secure log-off procedures shall be followed (maximum session times, termination of inactive sessions).
System logging and auditing features are enabled and configured.
System logging and auditing features are enabled and configured.
System architecture/interconnection diagrams showing data flows, and physical and logical segmentation shall be reviewed and updated at least quarterly.
System architecture/interconnection diagrams showing data flows, and physical and logical segmentation shall be reviewed and updated at least quarterly.
Segregation, physically and/or logically, shall be implemented ensuring that the required levels of control for data flows and users are met.
Segregation, physically and/or logically, shall be implemented ensuring that the required levels of control for data flows and users are met.
Unsecured protocols or protocols with known vulnerabilities shall not be used.
Unsecured protocols or protocols with known vulnerabilities shall not be used.
All critical applications shall be reviewed and tested after operating system changes or other major changes.
All critical applications shall be reviewed and tested after operating system changes or other major changes.
Development, test and production environments shall be segregated.
Development, test and production environments shall be segregated.
Performance and capacity monitoring, such as system and network utilisation, shall be practiced.
Performance and capacity monitoring, such as system and network utilisation, shall be practiced.
Network IDS may be provided where necessary.
Network IDS may be provided where necessary.
Performance improvement plans shall be outlined based on successive progression of security controls maturity and based on identified nonconformities.
Performance improvement plans shall be outlined based on successive progression of security controls maturity and based on identified nonconformities.
Service Provider shall have strict patching practice to ensure security patches are applied rapidly.
Service Provider shall have strict patching practice to ensure security patches are applied rapidly.
Service Provider should have capabilities to integrate security systems with the customer's Security monitoring solution (SIEM).
Service Provider should have capabilities to integrate security systems with the customer's Security monitoring solution (SIEM).
CLOUD SERVICE PROVIDER (CSP) must ensure CLIENT that its infrastructure is always using up-to-date systems.
CLOUD SERVICE PROVIDER (CSP) must ensure CLIENT that its infrastructure is always using up-to-date systems.
In multi-tenancy cloud environment, CLOUD SERVICE PROVIDER must ensure the CLIENT environment is segregated from other tenants' environment.
In multi-tenancy cloud environment, CLOUD SERVICE PROVIDER must ensure the CLIENT environment is segregated from other tenants' environment.
The solution is to be deployed and operationalized in a configuration where application and data storage components will reside and operate on separate physical or virtual servers.
The solution is to be deployed and operationalized in a configuration where application and data storage components will reside and operate on separate physical or virtual servers.
Configure REST/Web services to explicitly validate content types.
Configure REST/Web services to explicitly validate content types.
Applications must be designed in such a way that it captures evidence of any action taken by the user to protect itself from denying authenticity of the activity.
Applications must be designed in such a way that it captures evidence of any action taken by the user to protect itself from denying authenticity of the activity.
The hosted application's architecture must be configured in such a way that data stores containing confidential or regulated information are logically located in a secure network segment.
The hosted application's architecture must be configured in such a way that data stores containing confidential or regulated information are logically located in a secure network segment.
The hosted web application's architecture is to be deployed and configured with a web application firewall to protect the application.
The hosted web application's architecture is to be deployed and configured with a web application firewall to protect the application.
All application created sessions, windows, forms, pages, and pop-ups that display highly confidential information must be terminated or closed after the user logs out.
All application created sessions, windows, forms, pages, and pop-ups that display highly confidential information must be terminated or closed after the user logs out.
Implement controls to log TLS connection failures.
Implement controls to log TLS connection failures.
Implement processes to measure the availability, quality, and adequate capacity of resources to deliver the required system performance.
Implement processes to measure the availability, quality, and adequate capacity of resources to deliver the required system performance.
