Is your infrastructure in the cloud, SDDC, co-location, or on-premise? Please state provider name, unless it is on-prem.
Is your infrastructure in the cloud, SDDC, co-location, or on-premise? Please state provider name, unless it is on-prem.
Is your Data Security Architecture designed using an industry standard (e.g., CDSA, MULITSAFE, CSA Trusted Cloud Architectural Standard, FedRAMP, CAESARS)?
Is your Data Security Architecture designed using an industry standard (e.g., CDSA, MULITSAFE, CSA Trusted Cloud Architectural Standard, FedRAMP, CAESARS)?
Do you inventory, document, and maintain data flows for data that is resident (permanent or temporary) within the services' applications and infrastructure network and systems?
Do you inventory, document, and maintain data flows for data that is resident (permanent or temporary) within the services' applications and infrastructure network and systems?
Are file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation by root cause analysis, and response to incidents?
Are file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation by root cause analysis, and response to incidents?
Does the virtual machine management infrastructure include a tamper audit or software integrity function to detect changes to the build/configuration of the virtual machine?
Does the virtual machine management infrastructure include a tamper audit or software integrity function to detect changes to the build/configuration of the virtual machine?
Does your system's capacity requirements take into account current, projected, and anticipated capacity needs for all systems used to provide services to customers?
Does your system's capacity requirements take into account current, projected, and anticipated capacity needs for all systems used to provide services to customers?
Are system and network environments protected by a firewall or virtual firewall to ensure business and customer security requirements?
Are system and network environments protected by a firewall or virtual firewall to ensure business and customer security requirements?
Have you implemented the necessary measures for the appropriate isolation and segmentation of customers' access to infrastructure system and network components?
Have you implemented the necessary measures for the appropriate isolation and segmentation of customers' access to infrastructure system and network components?
Are system and network environments protected by a firewall or virtual firewall to ensure protection and isolation of sensitive data?
Are system and network environments protected by a firewall or virtual firewall to ensure protection and isolation of sensitive data?
Do you implement technical measures and apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns and/or DDoS attacks?
Do you implement technical measures and apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns and/or DDoS attacks?
Do you select and monitor outsourced providers in compliance with laws in the country where the data is processed, stored, and transmitted?
Do you select and monitor outsourced providers in compliance with laws in the country where the data is processed, stored, and transmitted?
Do you have the capability to restrict the storage of customer data to specific countries or geographic locations?
Do you have the capability to restrict the storage of customer data to specific countries or geographic locations?
Can you provide the physical location/geography of storage of a customer's data upon request?
Can you provide the physical location/geography of storage of a customer's data upon request?
Do you make standards-based information security metrics (CSA, CAMM, etc.) available to your customers?
Do you make standards-based information security metrics (CSA, CAMM, etc.) available to your customers?
Do you use industry standards (i.e. OWASP Software Assurance Maturity Model, ISO 27034) to incorporate security requirements into your Systems/Software Development Lifecycle (SDLC)?
Do you use industry standards (i.e. OWASP Software Assurance Maturity Model, ISO 27034) to incorporate security requirements into your Systems/Software Development Lifecycle (SDLC)?
What services are contracted for appropriate disposal of hardware? Please provide a sample certificate of physical destruction?
What services are contracted for appropriate disposal of hardware? Please provide a sample certificate of physical destruction?
What services are contracted for appropriate disposal of paper documents? Please provide a sample certificate of physical destruction?
What services are contracted for appropriate disposal of paper documents? Please provide a sample certificate of physical destruction?
Is physical access to data processing equipment (servers and network equipment) restricted?
Is physical access to data processing equipment (servers and network equipment) restricted?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Are computer systems (servers) backed up according to a regular schedule?
Are computer systems (servers) backed up according to a regular schedule?
Does the organisation replicate data in another region?
Does the organisation replicate data in another region?
Are the backup tested for restoration?
Are the backup tested for restoration?
Are default hardened base virtual images applied to virtualized operating systems?
Are default hardened base virtual images applied to virtualized operating systems?
In case any the customer information is stored on vendor corporate network/systems, is there access available to employees using remote access?
In case any the customer information is stored on vendor corporate network/systems, is there access available to employees using remote access?
Are necessary tools utilised to monitor environmental protection systems and alert personnel in the event of warnings or failures?
Are necessary tools utilised to monitor environmental protection systems and alert personnel in the event of warnings or failures?
Is an inventory maintained for hardware, software, information, physical assets, services and all other forms of media, where information is processed or stored? If so, how often is the inventory reviewed and updated?
Is an inventory maintained for hardware, software, information, physical assets, services and all other forms of media, where information is processed or stored? If so, how often is the inventory reviewed and updated?
Are all external facing / web facing servers placed in DMZ?
Are all external facing / web facing servers placed in DMZ?
Is there a dedicated infrastructure for collection, analysis and storage of logs?
Is there a dedicated infrastructure for collection, analysis and storage of logs?
Is access to Database systems used for the customer operations logged?
Is access to Database systems used for the customer operations logged?
Do systems and network devices utilize a common time synchronization service?
Do systems and network devices utilize a common time synchronization service?
Does the Isolation/segregation of the customer environment at vendor done by means of VLAN/ creation of zones on Firewall?
Does the Isolation/segregation of the customer environment at vendor done by means of VLAN/ creation of zones on Firewall?
Are the systems used for the customer operations hardened according to hardening document/ technical specification document?
Are the systems used for the customer operations hardened according to hardening document/ technical specification document?
Do you have controls to prevent storing of any confidential or highly confidential data on the desktop? Please describe any specific controls in place to prevent data leakage from your environment.
Do you have controls to prevent storing of any confidential or highly confidential data on the desktop? Please describe any specific controls in place to prevent data leakage from your environment.
Is there a backup and recovery document covering the customer processes? Is it communicated to employees working for the customer operations?
Is there a backup and recovery document covering the customer processes? Is it communicated to employees working for the customer operations?
Does the Backup and recovery procedure identify essential business information, servers, audit trail, frequency, logging, retention period, and roles and responsibilities?
Does the Backup and recovery procedure identify essential business information, servers, audit trail, frequency, logging, retention period, and roles and responsibilities?
Is there a secure process for onsite and offsite backup media protection during storage pertaining to the customer operations?
Is there a secure process for onsite and offsite backup media protection during storage pertaining to the customer operations?
Does the organization reuse, test and restore the customer backups on frequent basis?
Does the organization reuse, test and restore the customer backups on frequent basis?
What is the distance of the backup facility from the primary location?
What is the distance of the backup facility from the primary location?
Is there an alternate location facility and supporting facility to continue the customer operations?
Is there an alternate location facility and supporting facility to continue the customer operations?
Can the backed up data be restored and made available at the alternate site at any point in time? How can the critical data be restored and in what time frame?
Can the backed up data be restored and made available at the alternate site at any point in time? How can the critical data be restored and in what time frame?
Is your DR backup facility provided internally or externally? If external, please indicate the name of the service provider and the backup location.
Is your DR backup facility provided internally or externally? If external, please indicate the name of the service provider and the backup location.
Who is the Cloud Service Provider (CSP)?
Who is the Cloud Service Provider (CSP)?
What all services are being opted from CSP?
What all services are being opted from CSP?
Does the requirement discussed and agreed that CSP shall ensure data destruction upon request or post the retention timeframe, across all locations?
Does the requirement discussed and agreed that CSP shall ensure data destruction upon request or post the retention timeframe, across all locations?
Does the requirement has been discussed between vendor and the customer and agreed with CSP that core the customer data should remain within India? If not, please detail the plan for local hosting.
Does the requirement has been discussed between vendor and the customer and agreed with CSP that core the customer data should remain within India? If not, please detail the plan for local hosting.
Does Data Retrieval time from primary/ backup location for the customer specific data discussed and agreed with the customer?
Does Data Retrieval time from primary/ backup location for the customer specific data discussed and agreed with the customer?
What is the deployment model? (Private Cloud/Public Cloud/Hybrid Cloud/Community Cloud)
What is the deployment model? (Private Cloud/Public Cloud/Hybrid Cloud/Community Cloud)
How does Vendor ensure Incident management for the customer services in Cloud?
How does Vendor ensure Incident management for the customer services in Cloud?
How does vendor ensure Auditing, Logging and Monitoring requirements for the customer services on cloud?
How does vendor ensure Auditing, Logging and Monitoring requirements for the customer services on cloud?
How does vendor ensure Secure configurations of Web Server on cloud?
How does vendor ensure Secure configurations of Web Server on cloud?
How vendor will ensure capacity and demand management with respect to the customer services on cloud?
How vendor will ensure capacity and demand management with respect to the customer services on cloud?
Does the CSP is using appropriate Data Loss Prevention (DLP) solution to identify, monitor and protect sensitive data and manage the data risk for the customer?
Does the CSP is using appropriate Data Loss Prevention (DLP) solution to identify, monitor and protect sensitive data and manage the data risk for the customer?
How does vendor ensure Patch Management activity for components/ devices require to deliver the customer services?
How does vendor ensure Patch Management activity for components/ devices require to deliver the customer services?
Provide the details of types of data that will be Collected, Stored/Retained, and Processed.
Provide the details of types of data that will be Collected, Stored/Retained, and Processed.
What is the backup site physical address?
What is the backup site physical address?
Technological competence of the service provider.
Technological competence of the service provider.
Are redundant power supplies available for supplying power to critical equipment? Is there a UPS or DG set backup for computer systems?
Are redundant power supplies available for supplying power to critical equipment? Is there a UPS or DG set backup for computer systems?
Have you implemented data protection and privacy measures such DLP, IRM/DRM etc.? Have you deployed any encryption/protection mechanism (data at rest) on databases, file servers, desktops and laptops?
Have you implemented data protection and privacy measures such DLP, IRM/DRM etc.? Have you deployed any encryption/protection mechanism (data at rest) on databases, file servers, desktops and laptops?
Can the Cloud servers be configured to send their audit logs to a centralized log collector at the customer?
Can the Cloud servers be configured to send their audit logs to a centralized log collector at the customer?
All Application changes to be routed through the PMS system driven by IT Application Owner. Necessary approvals to be documented.
All Application changes to be routed through the PMS system driven by IT Application Owner. Necessary approvals to be documented.
Are critical transactions identified by function to be reviewed?
Are critical transactions identified by function to be reviewed?
Are critical transactions logged and made available as a report through front end?
Are critical transactions logged and made available as a report through front end?
Minimum Audit logging scenarios: Login successes and failures, Addition/deletion/modification of users, Changes to security settings, Privilege ID monitoring.
Minimum Audit logging scenarios: Login successes and failures, Addition/deletion/modification of users, Changes to security settings, Privilege ID monitoring.
Logs should be protected against overwriting by using mechanisms such as log rotation and the log files to be retained for minimum of 3 months on the server.
Logs should be protected against overwriting by using mechanisms such as log rotation and the log files to be retained for minimum of 3 months on the server.
Has your organisation evaluated pandemic preparedness of critical third-party suppliers?
Has your organisation evaluated pandemic preparedness of critical third-party suppliers?
Operational risk arising from technology failure covering from any of below means (including system downtimes issues also).
Operational risk arising from technology failure covering from any of below means (including system downtimes issues also).
Where are data subjects whose Personal Data is processed located?
Where are data subjects whose Personal Data is processed located?
How is Personal Data being processed by Supplier?
How is Personal Data being processed by Supplier?
Who at Supplier will have access to the Personal Data, and for what purpose?
Who at Supplier will have access to the Personal Data, and for what purpose?
What are the locations where Personal Data will be housed or accessed? Will Personal Data be stored on a Supplier Cloud or on prem environments?
What are the locations where Personal Data will be housed or accessed? Will Personal Data be stored on a Supplier Cloud or on prem environments?
Can Supplier provide country location(s) for all Supplier personnel or subcontractors that may have access to Personal Data or privileged access to servers hosting Personal Data?
Can Supplier provide country location(s) for all Supplier personnel or subcontractors that may have access to Personal Data or privileged access to servers hosting Personal Data?
Describe the type of solution proposed (public/private/hybrid cloud, IaaS/Paas/CaaS/Saas/ASP, single-tenant/multi-tenant, etc.)
Describe the type of solution proposed (public/private/hybrid cloud, IaaS/Paas/CaaS/Saas/ASP, single-tenant/multi-tenant, etc.)
Describe where the servers hosting the customer's data are located and, if the data is hosted on multiple locations, provide detailed information as to the transport of the data between the concerned locations.
Describe where the servers hosting the customer's data are located and, if the data is hosted on multiple locations, provide detailed information as to the transport of the data between the concerned locations.
Describe how you monitor changes to the regulatory requirements in relevant jurisdictions, adjust your security program for changes to legal requirements, and ensure compliance with relevant regulatory requirements.
Describe how you monitor changes to the regulatory requirements in relevant jurisdictions, adjust your security program for changes to legal requirements, and ensure compliance with relevant regulatory requirements.
Do you contractually guarantee that your data centers are not located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Do you contractually guarantee that your data centers are not located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Describe how you manage restoration of environment and/or data for a specific customer.
Describe how you manage restoration of environment and/or data for a specific customer.
Provide a description of the physical security of your Datacenter both inside and outside the DataCenter itself.
Provide a description of the physical security of your Datacenter both inside and outside the DataCenter itself.
Provide an overview of how capacity planning is managed to limit the risk of system overload.
Provide an overview of how capacity planning is managed to limit the risk of system overload.
Describe to procedure in place for responding to requests for tenant data or connection logs from governments or law enforcement bodies and how you ensure logs will be legally admissible.
Describe to procedure in place for responding to requests for tenant data or connection logs from governments or law enforcement bodies and how you ensure logs will be legally admissible.
Can logs be generated by the various components of the proposed solution be forwarded to the customer's log concentrator / SIEM / SOC?
Can logs be generated by the various components of the proposed solution be forwarded to the customer's log concentrator / SIEM / SOC?
Describe how you manage to isolate logs for a specific tenant.
Describe how you manage to isolate logs for a specific tenant.
Does the organisation outsource its data storage?
Does the organisation outsource its data storage?
Does the organisation have a Hot recovery site?
Does the organisation have a Hot recovery site?
Are Cloud Hosting services subcontracted?
Are Cloud Hosting services subcontracted?
Do employees/contingent workers who have remote access connect to the customer network?
Do employees/contingent workers who have remote access connect to the customer network?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Are environmental protections installed in your data centres including Cooling systems, Battery/UPS and generator backup, Redundant communications lines, Smoke/water detectors, Fire Suppression, Raised Flooring?
Are environmental protections installed in your data centres including Cooling systems, Battery/UPS and generator backup, Redundant communications lines, Smoke/water detectors, Fire Suppression, Raised Flooring?
Are actions taken to resolve alerts generated by the monitoring tools?
Are actions taken to resolve alerts generated by the monitoring tools?
If hosted on public cloud (Amazon, Google, Azure etc.) - security configurations are aligned with public cloud vendor security requirements?
If hosted on public cloud (Amazon, Google, Azure etc.) - security configurations are aligned with public cloud vendor security requirements?
Have you applied data backup mechanism? If yes what is the frequency of backup?
Have you applied data backup mechanism? If yes what is the frequency of backup?
Does MFA is applied while accessing cloud environment / applications remotely (VPN, VDI)?
Does MFA is applied while accessing cloud environment / applications remotely (VPN, VDI)?
Does access to privilege users / admin has MFA enabled?
Does access to privilege users / admin has MFA enabled?
Does the DR is setup in some other city in India?
Does the DR is setup in some other city in India?
Does the DR site also has the same level of security controls as the production site?
Does the DR site also has the same level of security controls as the production site?
Which all in-house or third party applications Vendor will use for the customer operations?
Which all in-house or third party applications Vendor will use for the customer operations?
Are there any Cloud services which is used by vendor for the customer process? Please confirm details.
Are there any Cloud services which is used by vendor for the customer process? Please confirm details.
Type of Cloud services and its use in the customer operations.
Type of Cloud services and its use in the customer operations.
Please confirm on Cloud License details and data storage location (domestic or International).
Please confirm on Cloud License details and data storage location (domestic or International).
Points of presence of supplier infrastructure is identified.
Points of presence of supplier infrastructure is identified.
It is possible for the customer data to be restricted to a geographical location, if required.
It is possible for the customer data to be restricted to a geographical location, if required.
Supplier has a multi-tiered firewall functionality in place, with network as well as application level protection (e.g. stateful network firewall, WAF, Network Intrusion Detection - NIPS, behavioral anomaly detection, cloud security gateways etc.).
Supplier has a multi-tiered firewall functionality in place, with network as well as application level protection (e.g. stateful network firewall, WAF, Network Intrusion Detection - NIPS, behavioral anomaly detection, cloud security gateways etc.).
Vendor has a detailed backup and restoration plan in place. Security controls are applied in the same fashion for all the customer data, be that data actively used (online) or data stored in backup space.
Vendor has a detailed backup and restoration plan in place. Security controls are applied in the same fashion for all the customer data, be that data actively used (online) or data stored in backup space.
Hardware decommissioning policies are in place (when hardware is controlled by the vendor).
Hardware decommissioning policies are in place (when hardware is controlled by the vendor).
There are security control mechanisms in place to counter denial of service attacks.
There are security control mechanisms in place to counter denial of service attacks.
There is a activity and security logging process in place, and these logs are synchronized with the same network time server (NTP).
There is a activity and security logging process in place, and these logs are synchronized with the same network time server (NTP).
There is data/log retention process in place.
There is data/log retention process in place.
Does the cloud provider deliver data back up and/or data mirroring?
Does the cloud provider deliver data back up and/or data mirroring?
Is the Cloud Provider Privacy Shield certified?
Is the Cloud Provider Privacy Shield certified?
Can customers define the transient and persistent points of their data (i.e. the legal jurisdiction in which their data is transported and stored)?
Can customers define the transient and persistent points of their data (i.e. the legal jurisdiction in which their data is transported and stored)?
Is there an ability to monitor user activities? (E.g.: all actions taken by admin users)
Is there an ability to monitor user activities? (E.g.: all actions taken by admin users)
What availability measures do you employ to guard against threats and errors?
What availability measures do you employ to guard against threats and errors?
Do you have DDoS protection, and if so, how?
Do you have DDoS protection, and if so, how?
What application security measures are used in the production environment (e.g., application-level firewall, database logging / auditing, etc.)?
What application security measures are used in the production environment (e.g., application-level firewall, database logging / auditing, etc.)?
Do you logically and physically segregate production and non-production environments?
Do you logically and physically segregate production and non-production environments?
Do you have a policy that requires endpoints (laptops, desktops, etc.) to perform backups of specified corporate data?
Do you have a policy that requires endpoints (laptops, desktops, etc.) to perform backups of specified corporate data?
Is there an audit log available which covers user/api actions?
Is there an audit log available which covers user/api actions?
If the application can be hosted in PwC's private cloud.
If the application can be hosted in PwC's private cloud.
Cost to host in PwC private cloud.
Cost to host in PwC private cloud.
NSE's data and information shall be stored in data centres within India.
NSE's data and information shall be stored in data centres within India.
The redundant site where NSE's data and information are replicated shall also be in India in a separate location from the primary site.
The redundant site where NSE's data and information are replicated shall also be in India in a separate location from the primary site.
All backup media (physical, logical and virtual) of NSE's data and information shall be stored securely in India.
All backup media (physical, logical and virtual) of NSE's data and information shall be stored securely in India.
The Cloud Service Provider shall provide visibility to NSE into its infrastructure and processes, and to allow NSE to check the integrity and security of the cloud computing services.
The Cloud Service Provider shall provide visibility to NSE into its infrastructure and processes, and to allow NSE to check the integrity and security of the cloud computing services.
Cloud Service Provider shall ensure no management ports / console shall be accessible over the internet.
Cloud Service Provider shall ensure no management ports / console shall be accessible over the internet.
NSE shall ensure that no insecure ports on the Cloud infrastructure are open to the internet.
NSE shall ensure that no insecure ports on the Cloud infrastructure are open to the internet.
Cloud Service Provider and NSE shall monitor the network and security devices, virtualization platforms, operating systems, databases, applications, web servers and associated infrastructure, for security alerts and known attack vectors.
Cloud Service Provider and NSE shall monitor the network and security devices, virtualization platforms, operating systems, databases, applications, web servers and associated infrastructure, for security alerts and known attack vectors.
Where will UP data be hosted (geographic location)?
Where will UP data be hosted (geographic location)?
What is the standard used for destroying data on retired or failed hardware?
What is the standard used for destroying data on retired or failed hardware?
What options are available to transfer data between UP and the Supplier?
What options are available to transfer data between UP and the Supplier?
How is uptime measured?
How is uptime measured?
Is your service run from your own (a) data center, (b) the cloud, or (c) deployed-on premise only?
Is your service run from your own (a) data center, (b) the cloud, or (c) deployed-on premise only?
Have you researched your cloud providers best security practices?
Have you researched your cloud providers best security practices?
What systems do you have in place that mitigate classes of web application vulnerabilities? (e.g.: WAF, proxies, etc.)
What systems do you have in place that mitigate classes of web application vulnerabilities? (e.g.: WAF, proxies, etc.)
How do you log and alert on relevant security events? (this includes the network and application layer)?
How do you log and alert on relevant security events? (this includes the network and application layer)?
What processes and methods will be put in place, to securely back-up the system? Where will the Back-up data be stored?
What processes and methods will be put in place, to securely back-up the system? Where will the Back-up data be stored?
Will any the customer data be held on removable media including Back-ups? If so, will it be encrypted?
Will any the customer data be held on removable media including Back-ups? If so, will it be encrypted?
What firewalls and network/host protection measures (e.g. IDS or IPS) will be in place to protect the customer data? Describe how you will configure, maintain the above and monitor alerts generated.
What firewalls and network/host protection measures (e.g. IDS or IPS) will be in place to protect the customer data? Describe how you will configure, maintain the above and monitor alerts generated.
What information will be contained within logs?
What information will be contained within logs?
AWS Provide physical security services to our data centre.
AWS Provide physical security services to our data centre.
Is this a Cloud Solution?
Is this a Cloud Solution?
All privileged and service system, network or application level passwords, required for correct operations of business units must be backed up and kept in secure location available for extraction to a specified number of people on specific circumstances.
All privileged and service system, network or application level passwords, required for correct operations of business units must be backed up and kept in secure location available for extraction to a specified number of people on specific circumstances.
System testing and commissioning ensures security capabilities of the system are appropriately configured and verified.
System testing and commissioning ensures security capabilities of the system are appropriately configured and verified.
Encryption for protection of information/data transported by carriers, tapes, removable media devices or across communication lines shall be employed.
Encryption for protection of information/data transported by carriers, tapes, removable media devices or across communication lines shall be employed.
Application logs shall be verified to ensure there are no known anomalies before system deployment.
Application logs shall be verified to ensure there are no known anomalies before system deployment.
Backup media shall be kept in a secured manner against tampering, theft, fire, flood or damage until retention period elapsed.
Backup media shall be kept in a secured manner against tampering, theft, fire, flood or damage until retention period elapsed.
Where technically feasible, and based on the criticality of the asset, backups shall be tested to ensure their availability and integrity for the customer recovery efforts and confirm compliance with established RPO/RTO.
Where technically feasible, and based on the criticality of the asset, backups shall be tested to ensure their availability and integrity for the customer recovery efforts and confirm compliance with established RPO/RTO.
To ensure effective testing, restoration procedures shall be fully documented and tested.
To ensure effective testing, restoration procedures shall be fully documented and tested.
Fault logging shall be enabled in equipment wherever technically feasible.
Fault logging shall be enabled in equipment wherever technically feasible.
In all instances where automated logging and monitoring is not feasible, compensating mechanisms to record and retrieve manual logs shall be provided.
In all instances where automated logging and monitoring is not feasible, compensating mechanisms to record and retrieve manual logs shall be provided.
Service Provider shall have solid high-availability infrastructure in line with the customer requirements.
Service Provider shall have solid high-availability infrastructure in line with the customer requirements.
The data centre is a purpose-built facility with environmental controls including: redundant power supply, redundant cooling, UPS, generator, fire suppressant, temperature and moisture monitors.
The data centre is a purpose-built facility with environmental controls including: redundant power supply, redundant cooling, UPS, generator, fire suppressant, temperature and moisture monitors.
What are the controls to prevent complete and permanent loss of customer data?
What are the controls to prevent complete and permanent loss of customer data?
Which databases are used in the backend? Which database optimization approaches are taken?
Which databases are used in the backend? Which database optimization approaches are taken?
What are security approaches along the architecture stack? Is end-to-end security ensured? Does the platform allow standardized security mechanism, e.g. Kerberos, LDAP?
What are security approaches along the architecture stack? Is end-to-end security ensured? Does the platform allow standardized security mechanism, e.g. Kerberos, LDAP?
Describe the hosting infrastructure.
Describe the hosting infrastructure.
How does the system scale to support growing user populations?
How does the system scale to support growing user populations?
Describe the data center power backup.
Describe the data center power backup.
Describe data backup and restore procedures.
Describe data backup and restore procedures.
Do you own the data centers?
Do you own the data centers?
Scale Up / Down capabilities? (Storage capacity, Computing Power)
Scale Up / Down capabilities? (Storage capacity, Computing Power)
Scale Out Capabilities? (Module / Feature addition / removal)
Scale Out Capabilities? (Module / Feature addition / removal)
What tools are used to monitor application availability? Expected availability is 99.999% monthly basis.
What tools are used to monitor application availability? Expected availability is 99.999% monthly basis.
Where are your DR sites located?
Where are your DR sites located?
Are there security controls (like log generation, access control) in place to store the PII downloaded from the application?
Are there security controls (like log generation, access control) in place to store the PII downloaded from the application?
Are there plans in place to handle/manage contingent events or circumstances (e.g. what if the person with the key to the server room is sick)?
Are there plans in place to handle/manage contingent events or circumstances (e.g. what if the person with the key to the server room is sick)?
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Have you employed sub processor(s) for processing TCS data?
Have you employed sub processor(s) for processing TCS data?
A list of your data center locations (primary, secondary, etc.) where services are provided from and all locations/countries where information may be processed.
A list of your data center locations (primary, secondary, etc.) where services are provided from and all locations/countries where information may be processed.
A list of third service providers utilized to conduct any aspect of the contracted service in scope.
A list of third service providers utilized to conduct any aspect of the contracted service in scope.
Describe your security architecture.
Describe your security architecture.
Does product have security mechanisms against intrusion?
Does product have security mechanisms against intrusion?
Please furnish historical data with reference to the solution proposed highlighting the errors /fixes/patches within security category and the resolutions undertaken to cater those.
Please furnish historical data with reference to the solution proposed highlighting the errors /fixes/patches within security category and the resolutions undertaken to cater those.
Do you provide free security patch to the customer at no additional cost?
Do you provide free security patch to the customer at no additional cost?
Do you have a specific R&D team that keep improving your solution security through patch release. Please elaborate (how, many, where)
Do you have a specific R&D team that keep improving your solution security through patch release. Please elaborate (how, many, where)
Is your system able to operate on hardened web services system? Please also provide ports required for your system to operate.
Is your system able to operate on hardened web services system? Please also provide ports required for your system to operate.
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
How easy and convenient is your solution authentication and security features for the customer.
How easy and convenient is your solution authentication and security features for the customer.
CLOUD SERVICE PROVIDER (CSP) must save access logs for any inbound and outbound access of CLIENT Cloud Infrastructure.
CLOUD SERVICE PROVIDER (CSP) must save access logs for any inbound and outbound access of CLIENT Cloud Infrastructure.
CLOUD SERVICE PROVIDER (CSP) must have security infrastructure for securing any inbound and outbound connection to any of their infrastructure where CLIENT system and/or data reside.
CLOUD SERVICE PROVIDER (CSP) must have security infrastructure for securing any inbound and outbound connection to any of their infrastructure where CLIENT system and/or data reside.
CLOUD SERVICE PROVIDER (CSP) must provide onsite security as a service as the first security line to CLIENT asset that resides on CSP premises.
CLOUD SERVICE PROVIDER (CSP) must provide onsite security as a service as the first security line to CLIENT asset that resides on CSP premises.
What types of controls are in place to mitigate the risk of malware infection and external hacking?
What types of controls are in place to mitigate the risk of malware infection and external hacking?
Will any data be hosted with, or accessed by a sub-contractor?
Will any data be hosted with, or accessed by a sub-contractor?
Do any sub-contractors reside in offshore jurisdictions?
Do any sub-contractors reside in offshore jurisdictions?
Do you have contracts with third party service providers who may have access to FINCARE data (controls such as - Confidentiality agreements, NDAs, review mechanism etc.)?
Do you have contracts with third party service providers who may have access to FINCARE data (controls such as - Confidentiality agreements, NDAs, review mechanism etc.)?
Is a process in place to regularly monitor your third party service providers to ensure compliance with security standards?
Is a process in place to regularly monitor your third party service providers to ensure compliance with security standards?
Do you have an independent audit performed on your dependent third parties who have access to your Company or clients data?
Do you have an independent audit performed on your dependent third parties who have access to your Company or clients data?
Please explain the data flow/information flow from source to destination, including all the components in the data processing lifecycle.
Please explain the data flow/information flow from source to destination, including all the components in the data processing lifecycle.
Applications must be deployed in PSJH Cloud environment, reviewed and approved by EIS. Development, test, and production environments must be segmented from each other.
Applications must be deployed in PSJH Cloud environment, reviewed and approved by EIS. Development, test, and production environments must be segmented from each other.
Application, network, infra and hosting teams shall establish an alternate storage and processing site including necessary agreements to permit the storage and retrieval of information from alternative site.
Application, network, infra and hosting teams shall establish an alternate storage and processing site including necessary agreements to permit the storage and retrieval of information from alternative site.
Application, network, infra and hosting teams shall conduct backups of user-level information, system-level information, and information system documentation at least once every 12 months.
Application, network, infra and hosting teams shall conduct backups of user-level information, system-level information, and information system documentation at least once every 12 months.
Configure event logging for all system components to audit access and activity to individual users, including proxy users of applications and databases.
Configure event logging for all system components to audit access and activity to individual users, including proxy users of applications and databases.
Centrally manage and audit event logs utilizing security monitoring tools (eg. Microsoft Sentinel SIEM, XSOAR, and ServiceNow solutions) where available.
Centrally manage and audit event logs utilizing security monitoring tools (eg. Microsoft Sentinel SIEM, XSOAR, and ServiceNow solutions) where available.
Use only secure and up to date third party or open source components that have been formally approved by EIS, Providence Legal, IT Contracting, and any other applicable Providence approval and governance groups.
Use only secure and up to date third party or open source components that have been formally approved by EIS, Providence Legal, IT Contracting, and any other applicable Providence approval and governance groups.
Developers must not have access to both the development/test and production environments. Use cases where developers need access must be reviewed by ISRA for approval.
Developers must not have access to both the development/test and production environments. Use cases where developers need access must be reviewed by ISRA for approval.
Employ controls to protect REST services against Cross-Site Request Forgery attacks.
Employ controls to protect REST services against Cross-Site Request Forgery attacks.
Implement controls to prevent log injection.
Implement controls to prevent log injection.
The solution is scalable to support the customer size and complexity: 170,000 co-workers, 10% new co-workers yearly, 40% co-workers turnover, Minimum 35 countries.
The solution is scalable to support the customer size and complexity: 170,000 co-workers, 10% new co-workers yearly, 40% co-workers turnover, Minimum 35 countries.
Security model of storage of data - Please describe shortly how data is stored, in relation to vendor's data, is protected at use, in transit and at rest.
Security model of storage of data - Please describe shortly how data is stored, in relation to vendor's data, is protected at use, in transit and at rest.
Are there any subcontractors involved (4th Parties to Infosys) in providing services to Infosys? If yes, detail out the current process in the organization for ensuring adequate security governance.
Are there any subcontractors involved (4th Parties to Infosys) in providing services to Infosys? If yes, detail out the current process in the organization for ensuring adequate security governance.
Do you process personal data as part of engagement with Infosys?
Do you process personal data as part of engagement with Infosys?
Is the logs maintained for login successful and failure attempts?
Is the logs maintained for login successful and failure attempts?
Is application configured for audit trails?
Is application configured for audit trails?
Is the code repository established and back-up are taken regularly?
Is the code repository established and back-up are taken regularly?
Is the application server have latest operating system, licensed and supported?
Is the application server have latest operating system, licensed and supported?
Is the database server are hardened for security and maintained?
Is the database server are hardened for security and maintained?
Is security audit logs and alerts are configured for application server?
Is security audit logs and alerts are configured for application server?
Does the provider use a third party to provide the required services? If so, explain the services to be provided by the third party and the type of relationship between the provider and the third party.
Does the provider use a third party to provide the required services? If so, explain the services to be provided by the third party and the type of relationship between the provider and the third party.
Are the services provided by the provider scalable? Are there any limits?
Are the services provided by the provider scalable? Are there any limits?
What is the process to restore data from the provider's back-up?
What is the process to restore data from the provider's back-up?
Till how long data backup will be retained?
Till how long data backup will be retained?
If using virtual infrastructure, does the solution include hardware independent restore and recovery capabilities?
If using virtual infrastructure, does the solution include hardware independent restore and recovery capabilities?
Is your infrastructure in the cloud, SDDC, co-location, or on-premise? Please state provider name, unless it is on-prem.
Is your infrastructure in the cloud, SDDC, co-location, or on-premise? Please state provider name, unless it is on-prem.
Is your Data Security Architecture designed using an industry standard (e.g., CDSA, MULITSAFE, CSA Trusted Cloud Architectural Standard, FedRAMP, CAESARS)?
Is your Data Security Architecture designed using an industry standard (e.g., CDSA, MULITSAFE, CSA Trusted Cloud Architectural Standard, FedRAMP, CAESARS)?
Do you inventory, document, and maintain data flows for data that is resident (permanent or temporary) within the services' applications and infrastructure network and systems?
Do you inventory, document, and maintain data flows for data that is resident (permanent or temporary) within the services' applications and infrastructure network and systems?
Are file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation by root cause analysis, and response to incidents?
Are file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation by root cause analysis, and response to incidents?
Does the virtual machine management infrastructure include a tamper audit or software integrity function to detect changes to the build/configuration of the virtual machine?
Does the virtual machine management infrastructure include a tamper audit or software integrity function to detect changes to the build/configuration of the virtual machine?
Does your system's capacity requirements take into account current, projected, and anticipated capacity needs for all systems used to provide services to customers?
Does your system's capacity requirements take into account current, projected, and anticipated capacity needs for all systems used to provide services to customers?
Are system and network environments protected by a firewall or virtual firewall to ensure business and customer security requirements?
Are system and network environments protected by a firewall or virtual firewall to ensure business and customer security requirements?
Have you implemented the necessary measures for the appropriate isolation and segmentation of customers' access to infrastructure system and network components?
Have you implemented the necessary measures for the appropriate isolation and segmentation of customers' access to infrastructure system and network components?
Are system and network environments protected by a firewall or virtual firewall to ensure protection and isolation of sensitive data?
Are system and network environments protected by a firewall or virtual firewall to ensure protection and isolation of sensitive data?
Do you implement technical measures and apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns and/or DDoS attacks?
Do you implement technical measures and apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns and/or DDoS attacks?
Do you select and monitor outsourced providers in compliance with laws in the country where the data is processed, stored, and transmitted?
Do you select and monitor outsourced providers in compliance with laws in the country where the data is processed, stored, and transmitted?
Do you have the capability to restrict the storage of customer data to specific countries or geographic locations?
Do you have the capability to restrict the storage of customer data to specific countries or geographic locations?
Can you provide the physical location/geography of storage of a customer's data upon request?
Can you provide the physical location/geography of storage of a customer's data upon request?
Do you make standards-based information security metrics (CSA, CAMM, etc.) available to your customers?
Do you make standards-based information security metrics (CSA, CAMM, etc.) available to your customers?
Do you use industry standards (i.e. OWASP Software Assurance Maturity Model, ISO 27034) to incorporate security requirements into your Systems/Software Development Lifecycle (SDLC)?
Do you use industry standards (i.e. OWASP Software Assurance Maturity Model, ISO 27034) to incorporate security requirements into your Systems/Software Development Lifecycle (SDLC)?
What services are contracted for appropriate disposal of hardware? Please provide a sample certificate of physical destruction?
What services are contracted for appropriate disposal of hardware? Please provide a sample certificate of physical destruction?
What services are contracted for appropriate disposal of paper documents? Please provide a sample certificate of physical destruction?
What services are contracted for appropriate disposal of paper documents? Please provide a sample certificate of physical destruction?
Is physical access to data processing equipment (servers and network equipment) restricted?
Is physical access to data processing equipment (servers and network equipment) restricted?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?
Are computer systems (servers) backed up according to a regular schedule?
Are computer systems (servers) backed up according to a regular schedule?
Does the organisation replicate data in another region?
Does the organisation replicate data in another region?
Are the backup tested for restoration?
Are the backup tested for restoration?
Are default hardened base virtual images applied to virtualized operating systems?
Are default hardened base virtual images applied to virtualized operating systems?
In case any the customer information is stored on vendor corporate network/systems, is there access available to employees using remote access?
In case any the customer information is stored on vendor corporate network/systems, is there access available to employees using remote access?
Are necessary tools utilised to monitor environmental protection systems and alert personnel in the event of warnings or failures?
Are necessary tools utilised to monitor environmental protection systems and alert personnel in the event of warnings or failures?
Is an inventory maintained for hardware, software, information, physical assets, services and all other forms of media, where information is processed or stored? If so, how often is the inventory reviewed and updated?
Is an inventory maintained for hardware, software, information, physical assets, services and all other forms of media, where information is processed or stored? If so, how often is the inventory reviewed and updated?
Are all external facing / web facing servers placed in DMZ?
Are all external facing / web facing servers placed in DMZ?
Is there a dedicated infrastructure for collection, analysis and storage of logs?
Is there a dedicated infrastructure for collection, analysis and storage of logs?
Is access to Database systems used for the customer operations logged?
Is access to Database systems used for the customer operations logged?
Do systems and network devices utilize a common time synchronization service?
Do systems and network devices utilize a common time synchronization service?
Does the Isolation/segregation of the customer environment at vendor done by means of VLAN/ creation of zones on Firewall?
Does the Isolation/segregation of the customer environment at vendor done by means of VLAN/ creation of zones on Firewall?
Are the systems used for the customer operations hardened according to hardening document/ technical specification document?
Are the systems used for the customer operations hardened according to hardening document/ technical specification document?
Do you have controls to prevent storing of any confidential or highly confidential data on the desktop? Please describe any specific controls in place to prevent data leakage from your environment.
Do you have controls to prevent storing of any confidential or highly confidential data on the desktop? Please describe any specific controls in place to prevent data leakage from your environment.
Is there a backup and recovery document covering the customer processes? Is it communicated to employees working for the customer operations?
Is there a backup and recovery document covering the customer processes? Is it communicated to employees working for the customer operations?
Does the Backup and recovery procedure identify essential business information, servers, audit trail, frequency, logging, retention period, and roles and responsibilities?
Does the Backup and recovery procedure identify essential business information, servers, audit trail, frequency, logging, retention period, and roles and responsibilities?
Is there a secure process for onsite and offsite backup media protection during storage pertaining to the customer operations?
Is there a secure process for onsite and offsite backup media protection during storage pertaining to the customer operations?
Does the organization reuse, test and restore the customer backups on frequent basis?
Does the organization reuse, test and restore the customer backups on frequent basis?
What is the distance of the backup facility from the primary location?
What is the distance of the backup facility from the primary location?
Is there an alternate location facility and supporting facility to continue the customer operations?
Is there an alternate location facility and supporting facility to continue the customer operations?
Can the backed up data be restored and made available at the alternate site at any point in time? How can the critical data be restored and in what time frame?
Can the backed up data be restored and made available at the alternate site at any point in time? How can the critical data be restored and in what time frame?
Is your DR backup facility provided internally or externally? If external, please indicate the name of the service provider and the backup location.
Is your DR backup facility provided internally or externally? If external, please indicate the name of the service provider and the backup location.
Who is the Cloud Service Provider (CSP)?
Who is the Cloud Service Provider (CSP)?
What all services are being opted from CSP?
What all services are being opted from CSP?
Does the requirement discussed and agreed that CSP shall ensure data destruction upon request or post the retention timeframe, across all locations?
Does the requirement discussed and agreed that CSP shall ensure data destruction upon request or post the retention timeframe, across all locations?
Does the requirement has been discussed between vendor and the customer and agreed with CSP that core the customer data should remain within India? If not, please detail the plan for local hosting.
Does the requirement has been discussed between vendor and the customer and agreed with CSP that core the customer data should remain within India? If not, please detail the plan for local hosting.
Does Data Retrieval time from primary/ backup location for the customer specific data discussed and agreed with the customer?
Does Data Retrieval time from primary/ backup location for the customer specific data discussed and agreed with the customer?
What is the deployment model? (Private Cloud/Public Cloud/Hybrid Cloud/Community Cloud)
What is the deployment model? (Private Cloud/Public Cloud/Hybrid Cloud/Community Cloud)
How does Vendor ensure Incident management for the customer services in Cloud?
How does Vendor ensure Incident management for the customer services in Cloud?
How does vendor ensure Auditing, Logging and Monitoring requirements for the customer services on cloud?
How does vendor ensure Auditing, Logging and Monitoring requirements for the customer services on cloud?
How does vendor ensure Secure configurations of Web Server on cloud?
How does vendor ensure Secure configurations of Web Server on cloud?
How vendor will ensure capacity and demand management with respect to the customer services on cloud?
How vendor will ensure capacity and demand management with respect to the customer services on cloud?
Does the CSP is using appropriate Data Loss Prevention (DLP) solution to identify, monitor and protect sensitive data and manage the data risk for the customer?
Does the CSP is using appropriate Data Loss Prevention (DLP) solution to identify, monitor and protect sensitive data and manage the data risk for the customer?
How does vendor ensure Patch Management activity for components/ devices require to deliver the customer services?
How does vendor ensure Patch Management activity for components/ devices require to deliver the customer services?
Provide the details of types of data that will be Collected, Stored/Retained, and Processed.
Provide the details of types of data that will be Collected, Stored/Retained, and Processed.
What is the backup site physical address?
What is the backup site physical address?
Technological competence of the service provider.
Technological competence of the service provider.
Are redundant power supplies available for supplying power to critical equipment? Is there a UPS or DG set backup for computer systems?
Are redundant power supplies available for supplying power to critical equipment? Is there a UPS or DG set backup for computer systems?
Have you implemented data protection and privacy measures such DLP, IRM/DRM etc.? Have you deployed any encryption/protection mechanism (data at rest) on databases, file servers, desktops and laptops?
Have you implemented data protection and privacy measures such DLP, IRM/DRM etc.? Have you deployed any encryption/protection mechanism (data at rest) on databases, file servers, desktops and laptops?
Can the Cloud servers be configured to send their audit logs to a centralized log collector at the customer?
Can the Cloud servers be configured to send their audit logs to a centralized log collector at the customer?
All Application changes to be routed through the PMS system driven by IT Application Owner. Necessary approvals to be documented.
All Application changes to be routed through the PMS system driven by IT Application Owner. Necessary approvals to be documented.
Are critical transactions identified by function to be reviewed?
Are critical transactions identified by function to be reviewed?
Are critical transactions logged and made available as a report through front end?
Are critical transactions logged and made available as a report through front end?
Minimum Audit logging scenarios: Login successes and failures, Addition/deletion/modification of users, Changes to security settings, Privilege ID monitoring.
Minimum Audit logging scenarios: Login successes and failures, Addition/deletion/modification of users, Changes to security settings, Privilege ID monitoring.
Logs should be protected against overwriting by using mechanisms such as log rotation and the log files to be retained for minimum of 3 months on the server.
Logs should be protected against overwriting by using mechanisms such as log rotation and the log files to be retained for minimum of 3 months on the server.
Has your organisation evaluated pandemic preparedness of critical third-party suppliers?
Has your organisation evaluated pandemic preparedness of critical third-party suppliers?
Operational risk arising from technology failure covering from any of below means (including system downtimes issues also).
Operational risk arising from technology failure covering from any of below means (including system downtimes issues also).
Where are data subjects whose Personal Data is processed located?
Where are data subjects whose Personal Data is processed located?
How is Personal Data being processed by Supplier?
How is Personal Data being processed by Supplier?
Who at Supplier will have access to the Personal Data, and for what purpose?
Who at Supplier will have access to the Personal Data, and for what purpose?
What are the locations where Personal Data will be housed or accessed? Will Personal Data be stored on a Supplier Cloud or on prem environments?
What are the locations where Personal Data will be housed or accessed? Will Personal Data be stored on a Supplier Cloud or on prem environments?
Can Supplier provide country location(s) for all Supplier personnel or subcontractors that may have access to Personal Data or privileged access to servers hosting Personal Data?
Can Supplier provide country location(s) for all Supplier personnel or subcontractors that may have access to Personal Data or privileged access to servers hosting Personal Data?
Describe the type of solution proposed (public/private/hybrid cloud, IaaS/Paas/CaaS/Saas/ASP, single-tenant/multi-tenant, etc.)
Describe the type of solution proposed (public/private/hybrid cloud, IaaS/Paas/CaaS/Saas/ASP, single-tenant/multi-tenant, etc.)
Describe where the servers hosting the customer's data are located and, if the data is hosted on multiple locations, provide detailed information as to the transport of the data between the concerned locations.
Describe where the servers hosting the customer's data are located and, if the data is hosted on multiple locations, provide detailed information as to the transport of the data between the concerned locations.
Describe how you monitor changes to the regulatory requirements in relevant jurisdictions, adjust your security program for changes to legal requirements, and ensure compliance with relevant regulatory requirements.
Describe how you monitor changes to the regulatory requirements in relevant jurisdictions, adjust your security program for changes to legal requirements, and ensure compliance with relevant regulatory requirements.
Do you contractually guarantee that your data centers are not located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Do you contractually guarantee that your data centers are not located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Describe how you manage restoration of environment and/or data for a specific customer.
Describe how you manage restoration of environment and/or data for a specific customer.
Provide a description of the physical security of your Datacenter both inside and outside the DataCenter itself.
Provide a description of the physical security of your Datacenter both inside and outside the DataCenter itself.
Provide an overview of how capacity planning is managed to limit the risk of system overload.
Provide an overview of how capacity planning is managed to limit the risk of system overload.
Describe to procedure in place for responding to requests for tenant data or connection logs from governments or law enforcement bodies and how you ensure logs will be legally admissible.
Describe to procedure in place for responding to requests for tenant data or connection logs from governments or law enforcement bodies and how you ensure logs will be legally admissible.
Can logs be generated by the various components of the proposed solution be forwarded to the customer's log concentrator / SIEM / SOC?
Can logs be generated by the various components of the proposed solution be forwarded to the customer's log concentrator / SIEM / SOC?
Describe how you manage to isolate logs for a specific tenant.
Describe how you manage to isolate logs for a specific tenant.
Does the organisation outsource its data storage?
Does the organisation outsource its data storage?
Does the organisation have a Hot recovery site?
Does the organisation have a Hot recovery site?
Are Cloud Hosting services subcontracted?
Are Cloud Hosting services subcontracted?
Do employees/contingent workers who have remote access connect to the customer network?
Do employees/contingent workers who have remote access connect to the customer network?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Are environmental protections installed in your data centres including Cooling systems, Battery/UPS and generator backup, Redundant communications lines, Smoke/water detectors, Fire Suppression, Raised Flooring?
Are environmental protections installed in your data centres including Cooling systems, Battery/UPS and generator backup, Redundant communications lines, Smoke/water detectors, Fire Suppression, Raised Flooring?
Are actions taken to resolve alerts generated by the monitoring tools?
Are actions taken to resolve alerts generated by the monitoring tools?
If hosted on public cloud (Amazon, Google, Azure etc.) - security configurations are aligned with public cloud vendor security requirements?
If hosted on public cloud (Amazon, Google, Azure etc.) - security configurations are aligned with public cloud vendor security requirements?
Have you applied data backup mechanism? If yes what is the frequency of backup?
Have you applied data backup mechanism? If yes what is the frequency of backup?
Does MFA is applied while accessing cloud environment / applications remotely (VPN, VDI)?
Does MFA is applied while accessing cloud environment / applications remotely (VPN, VDI)?
Does access to privilege users / admin has MFA enabled?
Does access to privilege users / admin has MFA enabled?
Does the DR is setup in some other city in India?
Does the DR is setup in some other city in India?
Does the DR site also has the same level of security controls as the production site?
Does the DR site also has the same level of security controls as the production site?
Which all in-house or third party applications Vendor will use for the customer operations?
Which all in-house or third party applications Vendor will use for the customer operations?
Are there any Cloud services which is used by vendor for the customer process? Please confirm details.
Are there any Cloud services which is used by vendor for the customer process? Please confirm details.
Type of Cloud services and its use in the customer operations.
Type of Cloud services and its use in the customer operations.
Please confirm on Cloud License details and data storage location (domestic or International).
Please confirm on Cloud License details and data storage location (domestic or International).
Points of presence of supplier infrastructure is identified.
Points of presence of supplier infrastructure is identified.
It is possible for the customer data to be restricted to a geographical location, if required.
It is possible for the customer data to be restricted to a geographical location, if required.
Supplier has a multi-tiered firewall functionality in place, with network as well as application level protection (e.g. stateful network firewall, WAF, Network Intrusion Detection - NIPS, behavioral anomaly detection, cloud security gateways etc.).
Supplier has a multi-tiered firewall functionality in place, with network as well as application level protection (e.g. stateful network firewall, WAF, Network Intrusion Detection - NIPS, behavioral anomaly detection, cloud security gateways etc.).
Vendor has a detailed backup and restoration plan in place. Security controls are applied in the same fashion for all the customer data, be that data actively used (online) or data stored in backup space.
Vendor has a detailed backup and restoration plan in place. Security controls are applied in the same fashion for all the customer data, be that data actively used (online) or data stored in backup space.
Hardware decommissioning policies are in place (when hardware is controlled by the vendor).
Hardware decommissioning policies are in place (when hardware is controlled by the vendor).
There are security control mechanisms in place to counter denial of service attacks.
There are security control mechanisms in place to counter denial of service attacks.
There is a activity and security logging process in place, and these logs are synchronized with the same network time server (NTP).
There is a activity and security logging process in place, and these logs are synchronized with the same network time server (NTP).
There is data/log retention process in place.
There is data/log retention process in place.
Does the cloud provider deliver data back up and/or data mirroring?
Does the cloud provider deliver data back up and/or data mirroring?
Is the Cloud Provider Privacy Shield certified?
Is the Cloud Provider Privacy Shield certified?
Can customers define the transient and persistent points of their data (i.e. the legal jurisdiction in which their data is transported and stored)?
Can customers define the transient and persistent points of their data (i.e. the legal jurisdiction in which their data is transported and stored)?
Is there an ability to monitor user activities? (E.g.: all actions taken by admin users)
Is there an ability to monitor user activities? (E.g.: all actions taken by admin users)
What availability measures do you employ to guard against threats and errors?
What availability measures do you employ to guard against threats and errors?
Do you have DDoS protection, and if so, how?
Do you have DDoS protection, and if so, how?
What application security measures are used in the production environment (e.g., application-level firewall, database logging / auditing, etc.)?
What application security measures are used in the production environment (e.g., application-level firewall, database logging / auditing, etc.)?
Do you logically and physically segregate production and non-production environments?
Do you logically and physically segregate production and non-production environments?
Do you have a policy that requires endpoints (laptops, desktops, etc.) to perform backups of specified corporate data?
Do you have a policy that requires endpoints (laptops, desktops, etc.) to perform backups of specified corporate data?
Is there an audit log available which covers user/api actions?
Is there an audit log available which covers user/api actions?
If the application can be hosted in PwC's private cloud.
If the application can be hosted in PwC's private cloud.
Cost to host in PwC private cloud.
Cost to host in PwC private cloud.
NSE's data and information shall be stored in data centres within India.
NSE's data and information shall be stored in data centres within India.
The redundant site where NSE's data and information are replicated shall also be in India in a separate location from the primary site.
The redundant site where NSE's data and information are replicated shall also be in India in a separate location from the primary site.
All backup media (physical, logical and virtual) of NSE's data and information shall be stored securely in India.
All backup media (physical, logical and virtual) of NSE's data and information shall be stored securely in India.
The Cloud Service Provider shall provide visibility to NSE into its infrastructure and processes, and to allow NSE to check the integrity and security of the cloud computing services.
The Cloud Service Provider shall provide visibility to NSE into its infrastructure and processes, and to allow NSE to check the integrity and security of the cloud computing services.
Cloud Service Provider shall ensure no management ports / console shall be accessible over the internet.
Cloud Service Provider shall ensure no management ports / console shall be accessible over the internet.
NSE shall ensure that no insecure ports on the Cloud infrastructure are open to the internet.
NSE shall ensure that no insecure ports on the Cloud infrastructure are open to the internet.
Cloud Service Provider and NSE shall monitor the network and security devices, virtualization platforms, operating systems, databases, applications, web servers and associated infrastructure, for security alerts and known attack vectors.
Cloud Service Provider and NSE shall monitor the network and security devices, virtualization platforms, operating systems, databases, applications, web servers and associated infrastructure, for security alerts and known attack vectors.
Where will UP data be hosted (geographic location)?
Where will UP data be hosted (geographic location)?
What is the standard used for destroying data on retired or failed hardware?
What is the standard used for destroying data on retired or failed hardware?
What options are available to transfer data between UP and the Supplier?
What options are available to transfer data between UP and the Supplier?
How is uptime measured?
How is uptime measured?
Is your service run from your own (a) data center, (b) the cloud, or (c) deployed-on premise only?
Is your service run from your own (a) data center, (b) the cloud, or (c) deployed-on premise only?
Have you researched your cloud providers best security practices?
Have you researched your cloud providers best security practices?
What systems do you have in place that mitigate classes of web application vulnerabilities? (e.g.: WAF, proxies, etc.)
What systems do you have in place that mitigate classes of web application vulnerabilities? (e.g.: WAF, proxies, etc.)
How do you log and alert on relevant security events? (this includes the network and application layer)?
How do you log and alert on relevant security events? (this includes the network and application layer)?
What processes and methods will be put in place, to securely back-up the system? Where will the Back-up data be stored?
What processes and methods will be put in place, to securely back-up the system? Where will the Back-up data be stored?
Will any the customer data be held on removable media including Back-ups? If so, will it be encrypted?
Will any the customer data be held on removable media including Back-ups? If so, will it be encrypted?
What firewalls and network/host protection measures (e.g. IDS or IPS) will be in place to protect the customer data? Describe how you will configure, maintain the above and monitor alerts generated.
What firewalls and network/host protection measures (e.g. IDS or IPS) will be in place to protect the customer data? Describe how you will configure, maintain the above and monitor alerts generated.
What information will be contained within logs?
What information will be contained within logs?
AWS Provide physical security services to our data centre.
AWS Provide physical security services to our data centre.
Is this a Cloud Solution?
Is this a Cloud Solution?
All privileged and service system, network or application level passwords, required for correct operations of business units must be backed up and kept in secure location available for extraction to a specified number of people on specific circumstances.
All privileged and service system, network or application level passwords, required for correct operations of business units must be backed up and kept in secure location available for extraction to a specified number of people on specific circumstances.
System testing and commissioning ensures security capabilities of the system are appropriately configured and verified.
System testing and commissioning ensures security capabilities of the system are appropriately configured and verified.
Encryption for protection of information/data transported by carriers, tapes, removable media devices or across communication lines shall be employed.
Encryption for protection of information/data transported by carriers, tapes, removable media devices or across communication lines shall be employed.
Application logs shall be verified to ensure there are no known anomalies before system deployment.
Application logs shall be verified to ensure there are no known anomalies before system deployment.
Backup media shall be kept in a secured manner against tampering, theft, fire, flood or damage until retention period elapsed.
Backup media shall be kept in a secured manner against tampering, theft, fire, flood or damage until retention period elapsed.
Where technically feasible, and based on the criticality of the asset, backups shall be tested to ensure their availability and integrity for the customer recovery efforts and confirm compliance with established RPO/RTO.
Where technically feasible, and based on the criticality of the asset, backups shall be tested to ensure their availability and integrity for the customer recovery efforts and confirm compliance with established RPO/RTO.
To ensure effective testing, restoration procedures shall be fully documented and tested.
To ensure effective testing, restoration procedures shall be fully documented and tested.
Fault logging shall be enabled in equipment wherever technically feasible.
Fault logging shall be enabled in equipment wherever technically feasible.
In all instances where automated logging and monitoring is not feasible, compensating mechanisms to record and retrieve manual logs shall be provided.
In all instances where automated logging and monitoring is not feasible, compensating mechanisms to record and retrieve manual logs shall be provided.
Service Provider shall have solid high-availability infrastructure in line with the customer requirements.
Service Provider shall have solid high-availability infrastructure in line with the customer requirements.
The data centre is a purpose-built facility with environmental controls including: redundant power supply, redundant cooling, UPS, generator, fire suppressant, temperature and moisture monitors.
The data centre is a purpose-built facility with environmental controls including: redundant power supply, redundant cooling, UPS, generator, fire suppressant, temperature and moisture monitors.
What are the controls to prevent complete and permanent loss of customer data?
What are the controls to prevent complete and permanent loss of customer data?
Which databases are used in the backend? Which database optimization approaches are taken?
Which databases are used in the backend? Which database optimization approaches are taken?
What are security approaches along the architecture stack? Is end-to-end security ensured? Does the platform allow standardized security mechanism, e.g. Kerberos, LDAP?
What are security approaches along the architecture stack? Is end-to-end security ensured? Does the platform allow standardized security mechanism, e.g. Kerberos, LDAP?
Describe the hosting infrastructure.
Describe the hosting infrastructure.
How does the system scale to support growing user populations?
How does the system scale to support growing user populations?
Describe the data center power backup.
Describe the data center power backup.
Describe data backup and restore procedures.
Describe data backup and restore procedures.
Do you own the data centers?
Do you own the data centers?
Scale Up / Down capabilities? (Storage capacity, Computing Power)
Scale Up / Down capabilities? (Storage capacity, Computing Power)
Scale Out Capabilities? (Module / Feature addition / removal)
Scale Out Capabilities? (Module / Feature addition / removal)
What tools are used to monitor application availability? Expected availability is 99.999% monthly basis.
What tools are used to monitor application availability? Expected availability is 99.999% monthly basis.
Where are your DR sites located?
Where are your DR sites located?
Are there security controls (like log generation, access control) in place to store the PII downloaded from the application?
Are there security controls (like log generation, access control) in place to store the PII downloaded from the application?
Are there plans in place to handle/manage contingent events or circumstances (e.g. what if the person with the key to the server room is sick)?
Are there plans in place to handle/manage contingent events or circumstances (e.g. what if the person with the key to the server room is sick)?
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Have you employed sub processor(s) for processing TCS data?
Have you employed sub processor(s) for processing TCS data?
A list of your data center locations (primary, secondary, etc.) where services are provided from and all locations/countries where information may be processed.
A list of your data center locations (primary, secondary, etc.) where services are provided from and all locations/countries where information may be processed.
A list of third service providers utilized to conduct any aspect of the contracted service in scope.
A list of third service providers utilized to conduct any aspect of the contracted service in scope.
Describe your security architecture.
Describe your security architecture.
Does product have security mechanisms against intrusion?
Does product have security mechanisms against intrusion?
Please furnish historical data with reference to the solution proposed highlighting the errors /fixes/patches within security category and the resolutions undertaken to cater those.
Please furnish historical data with reference to the solution proposed highlighting the errors /fixes/patches within security category and the resolutions undertaken to cater those.
Do you provide free security patch to the customer at no additional cost?
Do you provide free security patch to the customer at no additional cost?
Do you have a specific R&D team that keep improving your solution security through patch release. Please elaborate (how, many, where)
Do you have a specific R&D team that keep improving your solution security through patch release. Please elaborate (how, many, where)
Is your system able to operate on hardened web services system? Please also provide ports required for your system to operate.
Is your system able to operate on hardened web services system? Please also provide ports required for your system to operate.
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
How easy and convenient is your solution authentication and security features for the customer.
How easy and convenient is your solution authentication and security features for the customer.
CLOUD SERVICE PROVIDER (CSP) must save access logs for any inbound and outbound access of CLIENT Cloud Infrastructure.
CLOUD SERVICE PROVIDER (CSP) must save access logs for any inbound and outbound access of CLIENT Cloud Infrastructure.
CLOUD SERVICE PROVIDER (CSP) must have security infrastructure for securing any inbound and outbound connection to any of their infrastructure where CLIENT system and/or data reside.
CLOUD SERVICE PROVIDER (CSP) must have security infrastructure for securing any inbound and outbound connection to any of their infrastructure where CLIENT system and/or data reside.
CLOUD SERVICE PROVIDER (CSP) must provide onsite security as a service as the first security line to CLIENT asset that resides on CSP premises.
CLOUD SERVICE PROVIDER (CSP) must provide onsite security as a service as the first security line to CLIENT asset that resides on CSP premises.
What types of controls are in place to mitigate the risk of malware infection and external hacking?
What types of controls are in place to mitigate the risk of malware infection and external hacking?
Will any data be hosted with, or accessed by a sub-contractor?
Will any data be hosted with, or accessed by a sub-contractor?
Do any sub-contractors reside in offshore jurisdictions?
Do any sub-contractors reside in offshore jurisdictions?
Do you have contracts with third party service providers who may have access to FINCARE data (controls such as - Confidentiality agreements, NDAs, review mechanism etc.)?
Do you have contracts with third party service providers who may have access to FINCARE data (controls such as - Confidentiality agreements, NDAs, review mechanism etc.)?
Is a process in place to regularly monitor your third party service providers to ensure compliance with security standards?
Is a process in place to regularly monitor your third party service providers to ensure compliance with security standards?
Do you have an independent audit performed on your dependent third parties who have access to your Company or clients data?
Do you have an independent audit performed on your dependent third parties who have access to your Company or clients data?
Please explain the data flow/information flow from source to destination, including all the components in the data processing lifecycle.
Please explain the data flow/information flow from source to destination, including all the components in the data processing lifecycle.
Applications must be deployed in PSJH Cloud environment, reviewed and approved by EIS. Development, test, and production environments must be segmented from each other.
Applications must be deployed in PSJH Cloud environment, reviewed and approved by EIS. Development, test, and production environments must be segmented from each other.
Application, network, infra and hosting teams shall establish an alternate storage and processing site including necessary agreements to permit the storage and retrieval of information from alternative site.
Application, network, infra and hosting teams shall establish an alternate storage and processing site including necessary agreements to permit the storage and retrieval of information from alternative site.
Application, network, infra and hosting teams shall conduct backups of user-level information, system-level information, and information system documentation at least once every 12 months.
Application, network, infra and hosting teams shall conduct backups of user-level information, system-level information, and information system documentation at least once every 12 months.
Configure event logging for all system components to audit access and activity to individual users, including proxy users of applications and databases.
Configure event logging for all system components to audit access and activity to individual users, including proxy users of applications and databases.
Centrally manage and audit event logs utilizing security monitoring tools (eg. Microsoft Sentinel SIEM, XSOAR, and ServiceNow solutions) where available.
Centrally manage and audit event logs utilizing security monitoring tools (eg. Microsoft Sentinel SIEM, XSOAR, and ServiceNow solutions) where available.
Use only secure and up to date third party or open source components that have been formally approved by EIS, Providence Legal, IT Contracting, and any other applicable Providence approval and governance groups.
Use only secure and up to date third party or open source components that have been formally approved by EIS, Providence Legal, IT Contracting, and any other applicable Providence approval and governance groups.
Developers must not have access to both the development/test and production environments. Use cases where developers need access must be reviewed by ISRA for approval.
Developers must not have access to both the development/test and production environments. Use cases where developers need access must be reviewed by ISRA for approval.
Employ controls to protect REST services against Cross-Site Request Forgery attacks.
Employ controls to protect REST services against Cross-Site Request Forgery attacks.
Implement controls to prevent log injection.
Implement controls to prevent log injection.
The solution is scalable to support the customer size and complexity: 170,000 co-workers, 10% new co-workers yearly, 40% co-workers turnover, Minimum 35 countries.
The solution is scalable to support the customer size and complexity: 170,000 co-workers, 10% new co-workers yearly, 40% co-workers turnover, Minimum 35 countries.
Security model of storage of data - Please describe shortly how data is stored, in relation to vendor's data, is protected at use, in transit and at rest.
Security model of storage of data - Please describe shortly how data is stored, in relation to vendor's data, is protected at use, in transit and at rest.
Are there any subcontractors involved (4th Parties to Infosys) in providing services to Infosys? If yes, detail out the current process in the organization for ensuring adequate security governance.
Are there any subcontractors involved (4th Parties to Infosys) in providing services to Infosys? If yes, detail out the current process in the organization for ensuring adequate security governance.
Do you process personal data as part of engagement with Infosys?
Do you process personal data as part of engagement with Infosys?
Is the logs maintained for login successful and failure attempts?
Is the logs maintained for login successful and failure attempts?
Is application configured for audit trails?
Is application configured for audit trails?
Is the code repository established and back-up are taken regularly?
Is the code repository established and back-up are taken regularly?
Is the application server have latest operating system, licensed and supported?
Is the application server have latest operating system, licensed and supported?
Is the database server are hardened for security and maintained?
Is the database server are hardened for security and maintained?
Is security audit logs and alerts are configured for application server?
Is security audit logs and alerts are configured for application server?
Does the provider use a third party to provide the required services? If so, explain the services to be provided by the third party and the type of relationship between the provider and the third party.
Does the provider use a third party to provide the required services? If so, explain the services to be provided by the third party and the type of relationship between the provider and the third party.
Are the services provided by the provider scalable? Are there any limits?
Are the services provided by the provider scalable? Are there any limits?
What is the process to restore data from the provider's back-up?
What is the process to restore data from the provider's back-up?
Till how long data backup will be retained?
Till how long data backup will be retained?
If using virtual infrastructure, does the solution include hardware independent restore and recovery capabilities?
If using virtual infrastructure, does the solution include hardware independent restore and recovery capabilities?
