For data in transit, do you leverage encryption to protect data during transport across and between networks instances including services like SSH, HTTPS, etc.?
For data in transit, do you leverage encryption to protect data during transport across and between networks instances including services like SSH, HTTPS, etc.?
Do you encrypt data at rest?
Do you encrypt data at rest?
Do you segregate multi-tenant data using encryption?
Do you segregate multi-tenant data using encryption?
Do you provide native encryption capability for sensitive data fields? If so, are there any limits on the number of fields?
Do you provide native encryption capability for sensitive data fields? If so, are there any limits on the number of fields?
Do you have controls in place to ensure User IDs and passwords are transmitted in an encrypted format?
Do you have controls in place to ensure User IDs and passwords are transmitted in an encrypted format?
Are passwords stored in an encrypted or a single, one-way hash?
Are passwords stored in an encrypted or a single, one-way hash?
Do you support secure deletion (e.g., degaussing/cryptographic wiping) of archived and backed-up data as determined by the tenant?
Do you support secure deletion (e.g., degaussing/cryptographic wiping) of archived and backed-up data as determined by the tenant?
Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of tenant data once a customer has exited your environment or has vacated a resource?
Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of tenant data once a customer has exited your environment or has vacated a resource?
- Storage Period would be as per regulatory conditions.
- Personal data can be deleted based on a formal written request, with justification.
- Xoxoday would delete the data within 30 days of receiving the request.
Do you allow tenants to use their own certificates?
Do you allow tenants to use their own certificates?
Do you utilize open encryption methodologies any time your infrastructure components need to communicate with each other via public networks (e.g., Internet-based replication of data from one environment to another)?
Do you utilize open encryption methodologies any time your infrastructure components need to communicate with each other via public networks (e.g., Internet-based replication of data from one environment to another)?
Are TCCC-approved technologies used to transfer personal data? (Other than e-mail)
Are TCCC-approved technologies used to transfer personal data? (Other than e-mail)
Do you support end-to-end encryption of tenants' data in transit across all security zones?
Do you support end-to-end encryption of tenants' data in transit across all security zones?
Do you allow your tenant to manage all cryptographic keys (e.g., data encryption, SSL certificates) for sensitive data?
Do you allow your tenant to manage all cryptographic keys (e.g., data encryption, SSL certificates) for sensitive data?
Do you provide standardized (e.g. ISO/IEC) non-proprietary encryption algorithms (3DES, AES, etc.) to customers in order for them to protect their data if it is required to move through public networks (e.g., the Internet)?
Do you provide standardized (e.g. ISO/IEC) non-proprietary encryption algorithms (3DES, AES, etc.) to customers in order for them to protect their data if it is required to move through public networks (e.g., the Internet)?
Are policies and procedures established for data labeling and handling in order to ensure the security of data and objects that contain data?
Are policies and procedures established for data labeling and handling in order to ensure the security of data and objects that contain data?
Do you have key management policies binding keys to identifiable owners?
Do you have key management policies binding keys to identifiable owners?
Do you have a capability to allow creation of unique encryption keys per customer?
Do you have a capability to allow creation of unique encryption keys per customer?
Do you have documented ownership for each stage of the lifecycle of encryption keys?
Do you have documented ownership for each stage of the lifecycle of encryption keys?
Do you leverage encryption to protect data and virtual machine images during transport across and between networks and hypervisor instances?
Do you leverage encryption to protect data and virtual machine images during transport across and between networks and hypervisor instances?
Do you store encryption keys in the cloud?
Do you store encryption keys in the cloud?
Does the organisation encrypt its backups?
Does the organisation encrypt its backups?
Is the customer data always encrypted in transit?
Is the customer data always encrypted in transit?
Are attachments sent being encrypted or password protected before sending? If yes, describe the encryption method.
Are attachments sent being encrypted or password protected before sending? If yes, describe the encryption method.
Are the user access passwords displayed / stored / transmitted in clear text over the network?
Are the user access passwords displayed / stored / transmitted in clear text over the network?
Is the connectivity between the vendor and the customer with strong encryption? What is the organizations minimum standard for the protection of sensitive information? (DES, 3DES, AES-128, AES-256, etc)
Is the connectivity between the vendor and the customer with strong encryption? What is the organizations minimum standard for the protection of sensitive information? (DES, 3DES, AES-128, AES-256, etc)
Is the back up media password protected or encrypted as per requirement of vendor policy or as per the customer requirement?
Is the back up media password protected or encrypted as per requirement of vendor policy or as per the customer requirement?
What control measures are in place at CSP end to prevent, detect and react to breaches including data leakage and how CSP will demonstrate the same?
What control measures are in place at CSP end to prevent, detect and react to breaches including data leakage and how CSP will demonstrate the same?
Are the customer's data encrypted while stored and transmitted? And what encryption protocol or keys are currently being used?
Are the customer's data encrypted while stored and transmitted? And what encryption protocol or keys are currently being used?
Have you deployed any encryption mechanism (data in transit) to secure data in motion on communication links?
Have you deployed any encryption mechanism (data in transit) to secure data in motion on communication links?
Are Systems handling BSLI data on a separate Network segment segregated from other clients?
Are Systems handling BSLI data on a separate Network segment segregated from other clients?
For all critical applications, application should have TLS implemented for protection of Data in transit.
For all critical applications, application should have TLS implemented for protection of Data in transit.
Does Supplier have the ability to encrypt or pseudonymize Personal Data? Please explain.
Does Supplier have the ability to encrypt or pseudonymize Personal Data? Please explain.
What type of encryption do you propose (algorithms, protocols, key lengths) for data in transit and data at rest?
What type of encryption do you propose (algorithms, protocols, key lengths) for data in transit and data at rest?
Describe how you manage unique encryption keys (process, storage, usage, RACI, SOD) for your own use and for each of your tenants.
Describe how you manage unique encryption keys (process, storage, usage, RACI, SOD) for your own use and for each of your tenants.
Are the backup tested for restoration?
Are the backup tested for restoration?
If so, does the application always require encryption? If response is YES, please submit the type of encryption protocol and algorithm.
If so, does the application always require encryption? If response is YES, please submit the type of encryption protocol and algorithm.
What protocols or technologies are used for applying encryption on data at rest and data in transit (on cloud and on premises)?
What protocols or technologies are used for applying encryption on data at rest and data in transit (on cloud and on premises)?
Is the communication within the cloud and external to the cloud on end to end encryption? Explain.
Is the communication within the cloud and external to the cloud on end to end encryption? Explain.
How data is stored and handled at Vendor location (whether the customer data is encrypted, kept in logical segregation location etc)?
How data is stored and handled at Vendor location (whether the customer data is encrypted, kept in logical segregation location etc)?
What are the regulations around indemnity / liability for data privacy breaches?
What are the regulations around indemnity / liability for data privacy breaches?
Will the solution protect data from malware and commodity cyber-attack whilst at rest and in transit?
Will the solution protect data from malware and commodity cyber-attack whilst at rest and in transit?
How do you separate one customer's data from other customers' data?
How do you separate one customer's data from other customers' data?
The PII protection standards met by the cloud service provider.
The PII protection standards met by the cloud service provider.
How do you prevent other clients from accessing our data?
How do you prevent other clients from accessing our data?
How and where are user IDs and Passwords stored? How are they secured?
How and where are user IDs and Passwords stored? How are they secured?
Do you employ any mechanisms that facilitate secure data exchange?
Do you employ any mechanisms that facilitate secure data exchange?
Is our company's data stored on the Vendor platform encrypted?
Is our company's data stored on the Vendor platform encrypted?
What is the key management technique?
What is the key management technique?
Does the data transmitted by our company to Vendor involve user privacy?
Does the data transmitted by our company to Vendor involve user privacy?
According to the Cloud computing mode adopted, the Cloud Service Provider or NSE itself, shall implement encryption for data in transit and for data at rest for all NSE's sensitive data and information as per the Cryptography Policy of NSE.
According to the Cloud computing mode adopted, the Cloud Service Provider or NSE itself, shall implement encryption for data in transit and for data at rest for all NSE's sensitive data and information as per the Cryptography Policy of NSE.
The Cloud Service Provider shall enable NSE to back up its data and information as per the Backup Policy of NSE.
The Cloud Service Provider shall enable NSE to back up its data and information as per the Backup Policy of NSE.
How would you ensure that UP data was isolated and safeguarded from other customers?
How would you ensure that UP data was isolated and safeguarded from other customers?
Will UP data be encrypted by the Supplier when In transit?
Will UP data be encrypted by the Supplier when In transit?
Will UP data be encrypted by the Supplier when At Rest?
Will UP data be encrypted by the Supplier when At Rest?
If so, how is data anonymization implemented?
If so, how is data anonymization implemented?
If data anonymization is implemented, how is the anonymized data used within your organization?
If data anonymization is implemented, how is the anonymized data used within your organization?
Please describe your general rules management in relation to role provisioning, deprovisioning, and recertification.
Please describe your general rules management in relation to role provisioning, deprovisioning, and recertification.
Describe your secrets management strategy: (auth tokens, passwords, API credentials, certificates)
Describe your secrets management strategy: (auth tokens, passwords, API credentials, certificates)
Please describe, how the customer data will be kept logically and/or physically separated from other users' data?
Please describe, how the customer data will be kept logically and/or physically separated from other users' data?
Will any, or all the customer data be encrypted at rest within the system? If so to what standard its encrypted to?
Will any, or all the customer data be encrypted at rest within the system? If so to what standard its encrypted to?
Software packages from vendors and third parties should not be modified. However, if modification is necessary, it shall be limited to necessary changes and all changes shall be strictly controlled and documented.
Software packages from vendors and third parties should not be modified. However, if modification is necessary, it shall be limited to necessary changes and all changes shall be strictly controlled and documented.
A Cryptographic Key Management programme shall be established for Key Management through their whole lifecycle, including generating, storing, archiving, retrieving, distributing, retiring and destroying keys.
A Cryptographic Key Management programme shall be established for Key Management through their whole lifecycle, including generating, storing, archiving, retrieving, distributing, retiring and destroying keys.
Account credentials, sensitive information on databases and backups that require confidentiality and/or integrity shall be encrypted using strong encryption algorithms.
Account credentials, sensitive information on databases and backups that require confidentiality and/or integrity shall be encrypted using strong encryption algorithms.
Enable the use of encryption for administration of network devices within the customer environment.
Enable the use of encryption for administration of network devices within the customer environment.
Proper security controls (e.g. hashing, digital signatures and cryptography) shall be adopted to ensure authenticity and/or integrity of messages during their transmission.
Proper security controls (e.g. hashing, digital signatures and cryptography) shall be adopted to ensure authenticity and/or integrity of messages during their transmission.
Multiple layer strategy involving two, or more, different overlapping security mechanisms, a technique known as defence-in-depth shall be followed so that the impact of a failure in any one mechanism is minimised.
Multiple layer strategy involving two, or more, different overlapping security mechanisms, a technique known as defence-in-depth shall be followed so that the impact of a failure in any one mechanism is minimised.
Backups shall be encrypted and securely (physically and logically) retained at a centralised location in addition to two site local copies.
Backups shall be encrypted and securely (physically and logically) retained at a centralised location in addition to two site local copies.
The customer data or systems shall be segregated securely from other customers on infrastructure (network devices, server or database, etc.).
The customer data or systems shall be segregated securely from other customers on infrastructure (network devices, server or database, etc.).
Can evidence be provided of the processes that are implemented to guarantee the confidentiality of information, including a description of how our data is separated from other customer's data, and what controls are in place to prevent other customers from viewing our data?
Can evidence be provided of the processes that are implemented to guarantee the confidentiality of information, including a description of how our data is separated from other customer's data, and what controls are in place to prevent other customers from viewing our data?
Does a process exist to identify new laws and regulations with IT security implications? (e.g., new state breach notification requirements)
Does a process exist to identify new laws and regulations with IT security implications? (e.g., new state breach notification requirements)
Is there multiple choices of secure communications protocols/methods supported by the solution (front and back office data communication)? List them.
Is there multiple choices of secure communications protocols/methods supported by the solution (front and back office data communication)? List them.
Please specify other Encryption/Decryption Algorithms?
Please specify other Encryption/Decryption Algorithms?
Does solution provide/support data transformation (between different data formats)?
Does solution provide/support data transformation (between different data formats)?
Does your solution provide the Triple DES algorithms (provided by security module)?
Does your solution provide the Triple DES algorithms (provided by security module)?
Does your solution provide the RC4 algorithms (provided by security module)?
Does your solution provide the RC4 algorithms (provided by security module)?
Is the data hosted in a multi-tenanted environment? Can corporate data be accessed by other clients of the service provider? How is our data segregated from other tenants' data?
Is the data hosted in a multi-tenanted environment? Can corporate data be accessed by other clients of the service provider? How is our data segregated from other tenants' data?
Is our data encrypted during transmission, at rest (database and storage), and at backup or off-line storage?
Is our data encrypted during transmission, at rest (database and storage), and at backup or off-line storage?
Do you have the ability to logically segment or encrypt customer data such that, in the event of subpoena, data may be produced for a single tenant only, without inadvertently accessing another tenant's data?
Do you have the ability to logically segment or encrypt customer data such that, in the event of subpoena, data may be produced for a single tenant only, without inadvertently accessing another tenant's data?
Type of encryption (field-level, disk-level, etc.)
Type of encryption (field-level, disk-level, etc.)
Prevent applications from storing sensitive data in log files.
Prevent applications from storing sensitive data in log files.
Cryptographic keys in memory must be protected by best possible options available in the development framework.
Cryptographic keys in memory must be protected by best possible options available in the development framework.
Cryptographic keys must be managed by Providence and stored in a centralized location (eg., Azure Key Vault managed by Providence).
Cryptographic keys must be managed by Providence and stored in a centralized location (eg., Azure Key Vault managed by Providence).
Leverage Tokenization: A special form of data masking where the algorithm used to mask the data is maintained so the information can be later restored to its original value.
Leverage Tokenization: A special form of data masking where the algorithm used to mask the data is maintained so the information can be later restored to its original value.
System backups are to be encrypted.
System backups are to be encrypted.
Message encryption and digital signing must be configured to ensure the message confidentiality and integrity are maintained during transit.
Message encryption and digital signing must be configured to ensure the message confidentiality and integrity are maintained during transit.
All default test, sample or backup files including scripts, configuration files and web pages, etc. must be removed from the production server prior opening up the production application for consumption.
All default test, sample or backup files including scripts, configuration files and web pages, etc. must be removed from the production server prior opening up the production application for consumption.
Detail out the application workflow describing the communication happening between all the components including the protocols involved w.r.t. the services being provided to Infosys.
Detail out the application workflow describing the communication happening between all the components including the protocols involved w.r.t. the services being provided to Infosys.
How is cryptographic key management performed within the organization? Please elaborate the security controls implemented around this process.
How is cryptographic key management performed within the organization? Please elaborate the security controls implemented around this process.
Is database encrypted as per the encryption policy?
Is database encrypted as per the encryption policy?
Is sensitive data masked where required?
Is sensitive data masked where required?
