How do you protect digital identities and credentials and use them in cloud applications?
How do you protect digital identities and credentials and use them in cloud applications?
What data do you collect about the tenant (logs, etc.)? How is it stored? How is the data used? How long will it be stored?
What data do you collect about the tenant (logs, etc.)? How is it stored? How is the data used? How long will it be stored?
Under what conditions might third parties, including government agencies, have access to my data?
Under what conditions might third parties, including government agencies, have access to my data?
Do you have data-integrity monitoring / change-detection software?
Do you have data-integrity monitoring / change-detection software?
Do you have data loss prevention (DLP) solutions implemented for web, email, and end-point getaway?
Do you have data loss prevention (DLP) solutions implemented for web, email, and end-point getaway?
Do you have technical controls capable of enforcing customer data retention policies?
Do you have technical controls capable of enforcing customer data retention policies?
Will you use other companies whose infrastructure is located outside that of owned premise/Data Center?
Will you use other companies whose infrastructure is located outside that of owned premise/Data Center?
Can you provide details about policies and procedures for backup? This should include procedures for the management of removable media and methods for securely destroying media no longer required.
Can you provide details about policies and procedures for backup? This should include procedures for the management of removable media and methods for securely destroying media no longer required.
Can you specify the steps taken to ensure that data which has been deleted is completely wiped and cannot be accessed by other service users?
Can you specify the steps taken to ensure that data which has been deleted is completely wiped and cannot be accessed by other service users?
What checks are made on the identity of users with privileged access?
What checks are made on the identity of users with privileged access?
Are there different levels of identity checks based on the resources accessed?
Are there different levels of identity checks based on the resources accessed?
What processes are in place for de-provisioning privileged credentials?
What processes are in place for de-provisioning privileged credentials?
How are the accounts with the highest level of privilege authenticated and managed?
How are the accounts with the highest level of privilege authenticated and managed?
Are any high-privilege roles allocated to the same person? Does this allocation break the segregation of duties or least privilege rules?
Are any high-privilege roles allocated to the same person? Does this allocation break the segregation of duties or least privilege rules?
How do you allow for extraordinary privileged access in the event of an emergency?
How do you allow for extraordinary privileged access in the event of an emergency?
How are privileged actions monitored and logged? Is there a way to check and protect the integrity of such audit logs?
How are privileged actions monitored and logged? Is there a way to check and protect the integrity of such audit logs?
Is there mutual authentication? How could strong authentication be used? For example RSA SecurID? Is there any limitation?
Is there mutual authentication? How could strong authentication be used? For example RSA SecurID? Is there any limitation?
Please provide detail about what information is recorded within audit logs and for how long this is retained.
Please provide detail about what information is recorded within audit logs and for how long this is retained.
- Infrastructure logs are collected using AWS Audit Trail
- Application-relatedlogs are collected in our Elastic Search server and retained in long-term cloud storage.
Is the data segmented within audit logs so they can be made available to tenant without compromising other customers?
Is the data segmented within audit logs so they can be made available to tenant without compromising other customers?
How are audit logs reviewed? What recorded events result in action being taken?
How are audit logs reviewed? What recorded events result in action being taken?
Do you use multiple ISPs?
Do you use multiple ISPs?
Do you have DDoS protection, and if so, how?
Do you have DDoS protection, and if so, how?
Can you provide availability of historical data?
Can you provide availability of historical data?
What is your downtime plan (e.g., service upgrade, patch, etc.)?
What is your downtime plan (e.g., service upgrade, patch, etc.)?
Can you accommodate timely forensic investigation (e.g., eDiscovery)?
Can you accommodate timely forensic investigation (e.g., eDiscovery)?
Do you follow Data input and output integrity routines (i.e., reconciliation and edit checks) for application interfaces and databases to prevent manual or systematic processing errors, corruption of data, or misuse?
Do you follow Data input and output integrity routines (i.e., reconciliation and edit checks) for application interfaces and databases to prevent manual or systematic processing errors, corruption of data, or misuse?
Do you follow a defined quality change control and testing process (e.g. ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services?
Do you follow a defined quality change control and testing process (e.g. ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services?
Do you assign Data and objects data by the data owner based on data type, value, sensitivity, and criticality to the organization?
Do you assign Data and objects data by the data owner based on data type, value, sensitivity, and criticality to the organization?
Do you follow Data Security & Information Lifecycle Management Ownership / Stewardship?
Do you follow Data Security & Information Lifecycle Management Ownership / Stewardship?
Do you make sure that Each operating system has been hardened to provide only necessary ports, protocols, and services to meet business needs and have in place supporting technical controls such as: antivirus, file integrity monitoring, and logging as part of their baseline operating build standard or template.
Do you make sure that Each operating system has been hardened to provide only necessary ports, protocols, and services to meet business needs and have in place supporting technical controls such as: antivirus, file integrity monitoring, and logging as part of their baseline operating build standard or template.
Are access privileges to physical media assigned based on role and responsibilities?
Are access privileges to physical media assigned based on role and responsibilities?
Is there a process for secure disposal of both IT equipment and media?
Is there a process for secure disposal of both IT equipment and media?
Are development, test and production environments separate?
Are development, test and production environments separate?
Is production data ever used in a test environment?
Is production data ever used in a test environment?
Does the client scoped data include the disclosure of account numbers or identifiers to the consumer's account?
Does the client scoped data include the disclosure of account numbers or identifiers to the consumer's account?
Do fourth-parties, (e.g., subcontractors, sub-processors, sub-service organizations) have access to or process client scoped data?
Do fourth-parties, (e.g., subcontractors, sub-processors, sub-service organizations) have access to or process client scoped data?
Is there appropriate segregation between the customer Work area & other facility?
Is there appropriate segregation between the customer Work area & other facility?
Does the organization have security controls to restrict physical entry & exit to restricted areas containing sensitive data within the physical security perimeter?
Does the organization have security controls to restrict physical entry & exit to restricted areas containing sensitive data within the physical security perimeter?
What is your retention policy for retaining these logs? (30 days, 60 days, 1 year, etc)
What is your retention policy for retaining these logs? (30 days, 60 days, 1 year, etc)
Is there a process of frisking or manual check for personal storage devices?
Is there a process of frisking or manual check for personal storage devices?
Does the vendor agreement with CSP clearly define the data ownership mentioning that the ownership lies with vendor's customers? (the customer in this case)
Does the vendor agreement with CSP clearly define the data ownership mentioning that the ownership lies with vendor's customers? (the customer in this case)
Is there any data retention or data destruction period discussed with the CSP as per the requirements from vendor's customer (the customer)?
Is there any data retention or data destruction period discussed with the CSP as per the requirements from vendor's customer (the customer)?
Are the procedures for the customer's data handover documented, if the customer wants to terminate the service from CSP/ vendor?
Are the procedures for the customer's data handover documented, if the customer wants to terminate the service from CSP/ vendor?
Does the requirement for secure disposal of all information / data from CSP environment, immediately after termination of service, discussed and agreed with the customer?
Does the requirement for secure disposal of all information / data from CSP environment, immediately after termination of service, discussed and agreed with the customer?
Do you have a secure disposal management (Asset decommission) procedure ? Do you ensure that sensitive data has been deleted or overwritten before disposing off the equipment ?
Do you have a secure disposal management (Asset decommission) procedure ? Do you ensure that sensitive data has been deleted or overwritten before disposing off the equipment ?
Do you allow access to administration tasks for your employees from Portable Devices (phones, PDAs, Tablets, etc...) or their own devices, if yes, please refer to section Mobile Security.
Do you allow access to administration tasks for your employees from Portable Devices (phones, PDAs, Tablets, etc...) or their own devices, if yes, please refer to section Mobile Security.
What method do you use when deleting customer data if requested to do so. Do you provide customers with a certificate that his data was properly sanitized from all computing resources and portable storage media
What method do you use when deleting customer data if requested to do so. Do you provide customers with a certificate that his data was properly sanitized from all computing resources and portable storage media
Are rules pertaining to remote access monitoring configured on DLP solution?
Are rules pertaining to remote access monitoring configured on DLP solution?
Are policies configured to monitor and detect data leakage over different file types?
Are policies configured to monitor and detect data leakage over different file types?
Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from corporate network?
Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from corporate network?
What will be the frequency of data purging?
What will be the frequency of data purging?
Contract end facilitates the return of customer data to the customer in a the customer usable format.
Contract end facilitates the return of customer data to the customer in a the customer usable format.
the customer data is not used for test purposes, unless properly sanitized or anonymized, and agreed upon with the customer.
the customer data is not used for test purposes, unless properly sanitized or anonymized, and agreed upon with the customer.
Wherever relevant, Personally Identifiable Information (PII) is stored according to relevant laws and regulations. Storing of Personally Identifiable Information (PII) is transparent to the user, i.e. report is available for an employee specifiying what personal data is stored for her in the solution and who has access to it.
Wherever relevant, Personally Identifiable Information (PII) is stored according to relevant laws and regulations. Storing of Personally Identifiable Information (PII) is transparent to the user, i.e. report is available for an employee specifiying what personal data is stored for her in the solution and who has access to it.
Do you intend to process the Personal Data you process on behalf of the customer for your own purpose, such as product development, research or analytics, and if so, what is the legal basis for such processing?
Do you intend to process the Personal Data you process on behalf of the customer for your own purpose, such as product development, research or analytics, and if so, what is the legal basis for such processing?
For how long will data be stored and available after end of term?
For how long will data be stored and available after end of term?
Can you provide assurance that Htec data stored or created within the solution will be exportable in common industry formats without loss of fidelity (and context)
Can you provide assurance that Htec data stored or created within the solution will be exportable in common industry formats without loss of fidelity (and context)
Is the Company able to immediately erase customer data, both at the Supplier's and its service provider's premises? Please briefly describe the erasure process and used tools. How can this be validated?
Is the Company able to immediately erase customer data, both at the Supplier's and its service provider's premises? Please briefly describe the erasure process and used tools. How can this be validated?
Can you ensure that all customer data is erased at the end of service?
Can you ensure that all customer data is erased at the end of service?
Do you have a rigorous testing and acceptance procedure for outsourced and packaged application code?
Do you have a rigorous testing and acceptance procedure for outsourced and packaged application code?
Do you have a managed process for approving new 3rd Party Libraries?
Do you have a managed process for approving new 3rd Party Libraries?
Is the supplier willing to cooperate with the FDA if necessary? (site inspections, providing documentation, etc.)
Is the supplier willing to cooperate with the FDA if necessary? (site inspections, providing documentation, etc.)
Data Retention: How long does the service store customer data after account termination?
Data Retention: How long does the service store customer data after account termination?
What kinds of our company's information is involved for your platform? Is there any sensitive information involved? Such as user information, our company's product information, marketing data or code information?
What kinds of our company's information is involved for your platform? Is there any sensitive information involved? Such as user information, our company's product information, marketing data or code information?
If cardholder data is involved, does the Vendor have a PCI certificate?
If cardholder data is involved, does the Vendor have a PCI certificate?
Are controls in place to provide content monitoring and filtering, and data loss prevention?
Are controls in place to provide content monitoring and filtering, and data loss prevention?
Describe the circumstances in which customer data is allowed leave your production systems?
Describe the circumstances in which customer data is allowed leave your production systems?
All production information/data from test environments shall be securely deleted immediately after the testing is complete.
All production information/data from test environments shall be securely deleted immediately after the testing is complete.
Test/development/integration environments shall be physically and logically protected.
Test/development/integration environments shall be physically and logically protected.
Copying or use of production data into test environment shall be periodically audited.
Copying or use of production data into test environment shall be periodically audited.
Information consisting of vulnerabilities and potential non-compliance shall be considered as Sensitive information and be treated accordingly.
Information consisting of vulnerabilities and potential non-compliance shall be considered as Sensitive information and be treated accordingly.
Service Provider shall ensure that the customer data will be erased securely in accordance with acceptable standards upon termination of service.
Service Provider shall ensure that the customer data will be erased securely in accordance with acceptable standards upon termination of service.
Service Provider shall have a procedure for securely destroying storage media which contains the customer assets.
Service Provider shall have a procedure for securely destroying storage media which contains the customer assets.
What are the contract termination processes? How will we have access to our data on termination of the service? Would our data be completely deleted from the vendor's servers after termination?
What are the contract termination processes? How will we have access to our data on termination of the service? Would our data be completely deleted from the vendor's servers after termination?
How is data loss prevented and how is high availability ensured? What are typical measures such as MTBF (failure time) or MTTR (recovery time)?
How is data loss prevented and how is high availability ensured? What are typical measures such as MTBF (failure time) or MTTR (recovery time)?
What security standards are used for application development?
What security standards are used for application development?
Describe your approach to ensuring data security in the SaaS environment.
Describe your approach to ensuring data security in the SaaS environment.
Is PII deleted (or scheduled to delete) from the application in case its retention period is over or on the request of a data subject?
Is PII deleted (or scheduled to delete) from the application in case its retention period is over or on the request of a data subject?
Does the application allow access of PII from a different region/country in which Personal Information is collected? If yes, then specify the region/country.
Does the application allow access of PII from a different region/country in which Personal Information is collected? If yes, then specify the region/country.
How data is stored and handling at Vendor location(whether the the customer data is encrypted, kept in logical segregation location etc).
How data is stored and handling at Vendor location(whether the the customer data is encrypted, kept in logical segregation location etc).
PCI-DSS in case the CSP handles card holder data if card data is processed and stored.
PCI-DSS in case the CSP handles card holder data if card data is processed and stored.
Session tokens generated must be sufficiently long and highly random to withstand session guessing attacks.
Session tokens generated must be sufficiently long and highly random to withstand session guessing attacks.
PSJH full disk encryption software is required on servers and/or workstations containing PHI or sensitive data.
PSJH full disk encryption software is required on servers and/or workstations containing PHI or sensitive data.
Where PHI/PII is stored and processed as part of service delivery for a client engagagement the collection, use, maintenance, sharing & disposal of must be clearly established internally and agreed with client as applicable.
Where PHI/PII is stored and processed as part of service delivery for a client engagagement the collection, use, maintenance, sharing & disposal of must be clearly established internally and agreed with client as applicable.
Disclosures of Personally Identifiable Information (PII), Personal Healthcare Information (PHI) to third parties must be recorded, including what PII/PHI has been disclosed, to whom, at what time, purpose, validity, secure processing requirements, secure disposal requirements shall be documented in consultation with legal, privacy & compliance teams of providence.
Disclosures of Personally Identifiable Information (PII), Personal Healthcare Information (PHI) to third parties must be recorded, including what PII/PHI has been disclosed, to whom, at what time, purpose, validity, secure processing requirements, secure disposal requirements shall be documented in consultation with legal, privacy & compliance teams of providence.
Implement controls to enforce certificate based authentication for SFTP communication.
Implement controls to enforce certificate based authentication for SFTP communication.
System Architecture document must depict high-risk environments and data flows, system architecture, and potential legal compliance impacts illustrating the processing, transmitting, and storing of PHI/PII.
System Architecture document must depict high-risk environments and data flows, system architecture, and potential legal compliance impacts illustrating the processing, transmitting, and storing of PHI/PII.
What controls are in place to ensure secure data disposal upon termination of agreement with Infosys? (i.e. Disk Wipe , Degaussing , physical destruction etc.
What controls are in place to ensure secure data disposal upon termination of agreement with Infosys? (i.e. Disk Wipe , Degaussing , physical destruction etc.
Detail Out the secure coding guidelines ( e.g. OWASP Guide, SANS CWE Top 25,CERT Secure Coding etc.) and code review practices that are followed for the application (if any), which is used for providing services to Infosys.
Detail Out the secure coding guidelines ( e.g. OWASP Guide, SANS CWE Top 25,CERT Secure Coding etc.) and code review practices that are followed for the application (if any), which is used for providing services to Infosys.
Is any unsecure protocol like FTP is used for data transfer?
Is any unsecure protocol like FTP is used for data transfer?
Have there been incidences of security breaches resulting in the failure of core systems (e.g., Distributed Denial-of-Service (DDOS) the attack, etc.)
Have there been incidences of security breaches resulting in the failure of core systems (e.g., Distributed Denial-of-Service (DDOS) the attack, etc.)
What happens to the customer data at service termination?
What happens to the customer data at service termination?
What security features exist if the provider transmits data from one location to another (if applicable)?
What security features exist if the provider transmits data from one location to another (if applicable)?
What are the provider's data leak prevention capabilities?
What are the provider's data leak prevention capabilities?
How often does the provider delete data?
How often does the provider delete data?
Is verification provided that data has been securely deleted?
Is verification provided that data has been securely deleted?
What happens to the customer data when the provider is terminated?
What happens to the customer data when the provider is terminated?
