Are policies and procedures established for labeling, handling and the security of data and objects that contain data?
Are policies and procedures established for labeling, handling and the security of data and objects that contain data?
Are mechanisms for label inheritance implemented for objects that act as aggregate containers for data?
Are mechanisms for label inheritance implemented for objects that act as aggregate containers for data?
Do you adhere to the tenant's retention policy?
Do you adhere to the tenant's retention policy?
Can you provide a published procedure for security mechanisms to prevent data leakage in transit and data at rest leakage upon request?
Can you provide a published procedure for security mechanisms to prevent data leakage in transit and data at rest leakage upon request?
Can you provide tenants, upon request, documentation on how you maintain segregation of duties within your cloud service offering?
Can you provide tenants, upon request, documentation on how you maintain segregation of duties within your cloud service offering?
Do you use industry standards (Build Security in Maturity Model [BSIMM] benchmarks, Open Group ACS Trusted Technology Provider Framework, NIST, etc.) to build in security for your Systems/Software Development Lifecycle (SDLC)?
Do you use industry standards (Build Security in Maturity Model [BSIMM] benchmarks, Open Group ACS Trusted Technology Provider Framework, NIST, etc.) to build in security for your Systems/Software Development Lifecycle (SDLC)?
- security requirements
- independent security review of the environment by a certified individual
- code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
Do you use automated and manual source code analysis tools to detect security defects in code prior to production?
Do you use automated and manual source code analysis tools to detect security defects in code prior to production?
Do you review your applications for security vulnerabilities and address any issues prior to deployment to production?
Do you review your applications for security vulnerabilities and address any issues prior to deployment to production?
Do you verify that all of your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
Do you verify that all of your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
Do you provide tenants with documentation that describes your production change management procedures and their roles/rights/responsibilities within it?
Do you provide tenants with documentation that describes your production change management procedures and their roles/rights/responsibilities within it?
Are any of your data centers located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Are any of your data centers located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Do you provide tenants with geographically resilient hosting options?
Do you provide tenants with geographically resilient hosting options?
Do you provide tenants with infrastructure service failover capability to other providers?
Do you provide tenants with infrastructure service failover capability to other providers?
Are business continuity and disaster recovery plans subject to test at least annually and upon significant organizational or environmental changes to ensure continuing effectiveness?
Are business continuity and disaster recovery plans subject to test at least annually and upon significant organizational or environmental changes to ensure continuing effectiveness?
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports?
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports?
Do you conduct annual network penetration tests of your cloud service infrastructure regularly as prescribed by industry best practices and guidance?
Do you conduct annual network penetration tests of your cloud service infrastructure regularly as prescribed by industry best practices and guidance?
Do you perform annual audits (internal and external) and are the results available to tenants upon request?
Do you perform annual audits (internal and external) and are the results available to tenants upon request?
Are the results of the penetration tests available to tenants at their request?
Are the results of the penetration tests available to tenants at their request?
Are you storing, transmitting, and/or processing payment card data on behalf of our organization?
Are you storing, transmitting, and/or processing payment card data on behalf of our organization?
Can you prove that you are compliant for: Indian IT Act 2000?
Can you prove that you are compliant for: Indian IT Act 2000?
Is there a formal process that details the transition of data from unsupported systems and applications to supported systems and applications?
Is there a formal process that details the transition of data from unsupported systems and applications to supported systems and applications?
What will you deliver back to us on the end of service?
What will you deliver back to us on the end of service?
Do you conduct information audits to determine what personal data is being stored/processed and where is it being stored?
Do you conduct information audits to determine what personal data is being stored/processed and where is it being stored?
Do you have a dedicated information/cyber security team responsible for information security governance across the organization?
Do you have a dedicated information/cyber security team responsible for information security governance across the organization?
Have you defined the information security roles and responsibilities?
Have you defined the information security roles and responsibilities?
Do you have an acceptable usage policy which is signed/agreed by all employees on annual basis?
Do you have an acceptable usage policy which is signed/agreed by all employees on annual basis?
Is your environment SOC-2 Type-II attested or certified for the scope of the service being offered to tenant?
Is your environment SOC-2 Type-II attested or certified for the scope of the service being offered to tenant?
Is your environment CSA-certified for the scope of the service being offered to tenant?
Is your environment CSA-certified for the scope of the service being offered to tenant?
Are all relevant legislative, statutory, regulatory and contractual security requirements identified, documented and tracked?
Are all relevant legislative, statutory, regulatory and contractual security requirements identified, documented and tracked?
Do you monitor effectiveness of cyber security controls through regular metrics?
Do you monitor effectiveness of cyber security controls through regular metrics?
Do you have an approved HR Policy document?
Do you have an approved HR Policy document?
Are your employees screened before joining the organization? Are they bound to keep security of information intact even after their employment contract has ended?
Are your employees screened before joining the organization? Are they bound to keep security of information intact even after their employment contract has ended?
Do you take services from any third party which directly or indirectly impacts services given to tenant or Client of tenant?
Do you take services from any third party which directly or indirectly impacts services given to tenant or Client of tenant?
Can you provide details of these third parties including the name of the third party and the services they will be performing on your behalf?
Can you provide details of these third parties including the name of the third party and the services they will be performing on your behalf?
Do you have a Third Party Security Policy?
Do you have a Third Party Security Policy?
Do you regularly monitor the third party's compliance with security obligations?
Do you regularly monitor the third party's compliance with security obligations?
Is there a process to address any risk that may occur due to change of services being provided to the tenant?
Is there a process to address any risk that may occur due to change of services being provided to the tenant?
Do you permit the use of contractors in roles supporting customer operations?
Do you permit the use of contractors in roles supporting customer operations?
Do you have subscription to brand protection services?
Do you have subscription to brand protection services?
Do you monitor media platforms as well for brand protection?
Do you monitor media platforms as well for brand protection?
Do you have mandatory and regular privacy training and awareness module?
Do you have mandatory and regular privacy training and awareness module?
What is CSA?
What is CSA?
Did you list your organization for CSA STAR LEVL – 1 self-assessment?
Did you list your organization for CSA STAR LEVL – 1 self-assessment?
What are the important features of CSA STAR LEVEL – 1?
What are the important features of CSA STAR LEVEL – 1?
- Operating in a low-risk environment
- Wanting to offer increased transparency around the security controls they have in place.
- Looking for a cost-effective way to improve trust and transparency.
Are the applications and programming interfaces (APIs) designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations?
Are the applications and programming interfaces (APIs) designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations?
Do you comply with the Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols)?
Do you comply with the Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols)?
Do you use Production data in a non-production environment?
Do you use Production data in a non-production environment?
Do you obtain prior to relocation or transfer of hardware, software, or data to an offsite premise?
Do you obtain prior to relocation or transfer of hardware, software, or data to an offsite premise?
Do you have a documented application validation process to test for mobile device, operating system, and application compatibility issues?
Do you have a documented application validation process to test for mobile device, operating system, and application compatibility issues?
What is the California Privacy Rights Act (CPRA)?
What is the California Privacy Rights Act (CPRA)?
Is Xoxoday compliant with California Privacy Rights Act (CPRA)?
Is Xoxoday compliant with California Privacy Rights Act (CPRA)?
Do you provide rights to the consumers with regards to the data processing as per California Privacy Rights Act (CPRA)?
Do you provide rights to the consumers with regards to the data processing as per California Privacy Rights Act (CPRA)?
Did you implement all the CPRA Privacy controls as per the compliance requirements?
Did you implement all the CPRA Privacy controls as per the compliance requirements?
Do you make the CPRA Attestation report available for the customers?
Do you make the CPRA Attestation report available for the customers?
Do you collect any data from California citizens who are not 18 years old?
Do you collect any data from California citizens who are not 18 years old?
How can we submit our request to exercise our Rights Under the CCPA/CPRA?
How can we submit our request to exercise our Rights Under the CCPA/CPRA?
What is SOC 2 compliance?
What is SOC 2 compliance?
What are SOC 2 requirements?
What are SOC 2 requirements?
Is Xoxoday SOC 2 certified?
Is Xoxoday SOC 2 certified?
Is your cloud computing platform (AWS) SOC 2 Compliant?
Is your cloud computing platform (AWS) SOC 2 Compliant?
How do I request Xoxoday for SOC 2 report?
How do I request Xoxoday for SOC 2 report?
Who performs the independent third-party audit of Xoxoday for the SOC Report?
Who performs the independent third-party audit of Xoxoday for the SOC Report?
How long is a SOC 2 report valid?
How long is a SOC 2 report valid?
Is SOC 2 an international standard?
Is SOC 2 an international standard?
Do you conduct a SOC 2 audit every year?
Do you conduct a SOC 2 audit every year?
Did all applicable compliances and controls are audited during the SOC 2 attestation process?
Did all applicable compliances and controls are audited during the SOC 2 attestation process?
Do you process Protected Health Information (PHI)?
Do you process Protected Health Information (PHI)?
Is Xoxoday compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Is Xoxoday compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Do you make the HIPAA Audit report available for the customers?
Do you make the HIPAA Audit report available for the customers?
Do you have the process in place for providing Access Rights to the data subject as per EU GDPR?
Do you have the process in place for providing Access Rights to the data subject as per EU GDPR?
What method do you use when deleting customer data if requested to do so?
What method do you use when deleting customer data if requested to do so?
Do you have procedures in place for responding to a data subject request that involves a customer's Personal Data?
Do you have procedures in place for responding to a data subject request that involves a customer's Personal Data?
Do you perform audits on its Sub-processors to demonstrate their compliance?
Do you perform audits on its Sub-processors to demonstrate their compliance?
Do you conduct independent audits? (Third-Party)
Do you conduct independent audits? (Third-Party)
Does your organization have a plan or framework for business continuity management or disaster recovery management plan and policy in place? Frequency of testing?
Does your organization have a plan or framework for business continuity management or disaster recovery management plan and policy in place? Frequency of testing?
Are the responsibilities regarding data stewardship defined, assigned, documented, and communicated?
Are the responsibilities regarding data stewardship defined, assigned, documented, and communicated?
Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of customer data once a customer has exited your environment or has vacated a resource?
Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of customer data once a customer has exited your environment or has vacated a resource?
Do you classify your assets in terms of business criticality, service-level expectations, and operational continuity requirements?
Do you classify your assets in terms of business criticality, service-level expectations, and operational continuity requirements?
Do you maintain a complete inventory of all of your critical assets located at all sites/ or geographical locations and their assigned ownership?
Do you maintain a complete inventory of all of your critical assets located at all sites/ or geographical locations and their assigned ownership?
Do you have procedures and technical measures in place for data access segmentation in multi-customer system architectures?
Do you have procedures and technical measures in place for data access segmentation in multi-customer system architectures?
Do you support password (e.g., minimum length, age, history, complexity) and account lockout (e.g., lockout threshold, lockout duration) policy enforcement?
Do you support password (e.g., minimum length, age, history, complexity) and account lockout (e.g., lockout threshold, lockout duration) policy enforcement?
Can you provide evidence that due diligence mapping of regulations and standards to your controls/architecture/processes has been performed?
Can you provide evidence that due diligence mapping of regulations and standards to your controls/architecture/processes has been performed?
Is system performance monitored and tuned in order to continuously meet regulatory, contractual, and business requirements for all the systems used to provide services to the customers?
Is system performance monitored and tuned in order to continuously meet regulatory, contractual, and business requirements for all the systems used to provide services to the customers?
Do you maintain current architecture diagrams that include data flows between security domains/zones?
Do you maintain current architecture diagrams that include data flows between security domains/zones?
Are operating systems hardened to provide only the necessary ports, protocols, and services to meet business needs using technical controls (e.g., antivirus, file integrity monitoring, and logging) as part of their baseline build standard or template?
Are operating systems hardened to provide only the necessary ports, protocols, and services to meet business needs using technical controls (e.g., antivirus, file integrity monitoring, and logging) as part of their baseline build standard or template?
Do you use a network segregated from production-level networks when migrating physical servers, applications, or data to virtual servers?
Do you use a network segregated from production-level networks when migrating physical servers, applications, or data to virtual servers?
Do you provide policies and procedures (i.e. service level agreements) governing the migration of application data to and from your service?
Do you provide policies and procedures (i.e. service level agreements) governing the migration of application data to and from your service?
Do you integrate customer requirements into your security incident response plans?
Do you integrate customer requirements into your security incident response plans?
Have you tested your security incident response plans in the last year?
Have you tested your security incident response plans in the last year?
Does your incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
Does your incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?
Do you make security incident information available to all affected customers and providers periodically through electronic methods (e.g., portals)?
Do you make security incident information available to all affected customers and providers periodically through electronic methods (e.g., portals)?
Do you perform annual internal assessments of conformance and effectiveness of your policies, procedures, and supporting measures and metrics?
Do you perform annual internal assessments of conformance and effectiveness of your policies, procedures, and supporting measures and metrics?
Do third-party agreements include provision for the security and protection of information and assets?
Do third-party agreements include provision for the security and protection of information and assets?
Are systems in place to monitor for privacy breaches and notify customers expeditiously if a privacy event may have impacted their data?
Are systems in place to monitor for privacy breaches and notify customers expeditiously if a privacy event may have impacted their data?
Do you have the ability to measure and address non-conformance of provisions and/or terms across the entire supply chain (upstream/downstream)?
Do you have the ability to measure and address non-conformance of provisions and/or terms across the entire supply chain (upstream/downstream)?
Do you mandate annual information security reviews and audits of your third party providers to ensure that all agreed upon security requirements are met?
Do you mandate annual information security reviews and audits of your third party providers to ensure that all agreed upon security requirements are met?
Do you verify that your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
Do you verify that your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
All sub-processors are subject to regular due diligence
All sub-processors are subject to regular due diligence
Privacy training is provided to all staff on induction and at least annually thereafter
Privacy training is provided to all staff on induction and at least annually thereafter
Do you have a member in your organisation with dedicated information security duties?
Do you have a member in your organisation with dedicated information security duties?
Do employees have a unique log-in ID when accessing data?
Do employees have a unique log-in ID when accessing data?
Are network boundaries protected by firewalls?
Are network boundaries protected by firewalls?
Are all servers, end user devices (All systems) configured according to security standards as part of the build process?
Are all servers, end user devices (All systems) configured according to security standards as part of the build process?
Has the Data back-up and recovery process been verified?
Has the Data back-up and recovery process been verified?
Is there formal control of access to System Administrator privileges?
Is there formal control of access to System Administrator privileges?
Are servers configured to capture who accessed a system and what changes were made?
Are servers configured to capture who accessed a system and what changes were made?
Are computer rooms protected against fire and flood?
Are computer rooms protected against fire and flood?
Are security incidents reviewed to capture the root cause and act on key learnings?
Are security incidents reviewed to capture the root cause and act on key learnings?
Does the organisation receive an SSAE-16 SOC Report?
Does the organisation receive an SSAE-16 SOC Report?
Does the organisationis been audited for ISO 27001 or for other security standards?
Does the organisationis been audited for ISO 27001 or for other security standards?
Does the Cloud Hosting Provider provide independent audit reports (e.g., Service Operational Control - SOC) for their cloud hosting services?
Does the Cloud Hosting Provider provide independent audit reports (e.g., Service Operational Control - SOC) for their cloud hosting services?
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)?
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)?
Do employees/contingent workers who have remote access connect to the customer network?
Do employees/contingent workers who have remote access connect to the customer network?
If an employee no longer requires remote access to the customer network, is there a process to inform the the customer in a timely manner to revoke access?
If an employee no longer requires remote access to the customer network, is there a process to inform the the customer in a timely manner to revoke access?
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)?
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)?
Does the current DLP solution have the capability to monitor all the endpoints within the Organization?
Does the current DLP solution have the capability to monitor all the endpoints within the Organization?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization?
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization?
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause?
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause?
Is Risk Assessment Activity carried out for the organization covering the processes and assets of the customer operations?
Is Risk Assessment Activity carried out for the organization covering the processes and assets of the customer operations?
Does the organization has a mechanism to classify & protect sensitive IT assets covering the customer operations?
Does the organization has a mechanism to classify & protect sensitive IT assets covering the customer operations?
Do all employees, contractors and third party users sign terms and conditions of employment stating that they agree to adhere to the information security requirements for their role(s) within the organization?
Do all employees, contractors and third party users sign terms and conditions of employment stating that they agree to adhere to the information security requirements for their role(s) within the organization?
Describe the security controls in place to restrict physical entry & exit (e.g. badge access control systems, biometric systems, man traps, etc)
Describe the security controls in place to restrict physical entry & exit (e.g. badge access control systems, biometric systems, man traps, etc)
What are the fire protection & detection mechanisms placed in critical IT locations pertaining to the customer operations?
What are the fire protection & detection mechanisms placed in critical IT locations pertaining to the customer operations?
Are the major changes affecting the risk profile of the provider environment notified to the customer?
Are the major changes affecting the risk profile of the provider environment notified to the customer?
Is there an established SPOC for notifying these changes and ensuring documentation?
Is there an established SPOC for notifying these changes and ensuring documentation?
Are user e-mail accounts at the vendor processing facility created after necessary management / HR approvals?
Are user e-mail accounts at the vendor processing facility created after necessary management / HR approvals?
Are e-mail ids created if the vendor operations are outsourced / sub-contracted to other parties? If yes, Are proper approvals taken for the same?
Are e-mail ids created if the vendor operations are outsourced / sub-contracted to other parties? If yes, Are proper approvals taken for the same?
Describe your company's policies, procedures, and practices regarding email security controls?
Describe your company's policies, procedures, and practices regarding email security controls?
Is attachment size defined? Are the mail attachments for the customer process scanned for Virus and other malicious content?
Is attachment size defined? Are the mail attachments for the customer process scanned for Virus and other malicious content?
Does e-mail communication from the vendor include a standard disclaimer as a part of the contents?
Does e-mail communication from the vendor include a standard disclaimer as a part of the contents?
Is there restriction for usage & access to internet from systems in the customer operations?
Is there restriction for usage & access to internet from systems in the customer operations?
Has the vendor maintained redundancy for firewall & other network components? How it is ensured that network uptime is 100%
Has the vendor maintained redundancy for firewall & other network components? How it is ensured that network uptime is 100%
Do the modifications in the firewall rule-base for the customer operations go through the change management routine?
Do the modifications in the firewall rule-base for the customer operations go through the change management routine?
Is there a mechanism to ensure that only licensed softwares / applications are installed on the systems?
Is there a mechanism to ensure that only licensed softwares / applications are installed on the systems?
Is each operating system up to date with patches provided by the manufacturer?
Is each operating system up to date with patches provided by the manufacturer?
Whether the capacity demands are monitored and projections of future capacity requirements are made, to ensure that adequate processing power and storage are available. Example: Monitoring hard disk space, RAM and CPU on critical servers.
Whether the capacity demands are monitored and projections of future capacity requirements are made, to ensure that adequate processing power and storage are available. Example: Monitoring hard disk space, RAM and CPU on critical servers.
Does the vendor address AntiVirus Signature Management covering systems used for the customer operations? Is frequency defined?
Does the vendor address AntiVirus Signature Management covering systems used for the customer operations? Is frequency defined?
Are the AV signatures up to date?
Are the AV signatures up to date?
Did the business continuity test include all third parties, including sub-contractors, that support the the customer's business process?
Did the business continuity test include all third parties, including sub-contractors, that support the the customer's business process?
What is the frequency of these tests?
What is the frequency of these tests?
Is there a legal agreement signed between vendor and CSP?
Is there a legal agreement signed between vendor and CSP?
How does vendor ensure protection against Malicious Code and Monitoring on cloud?
How does vendor ensure protection against Malicious Code and Monitoring on cloud?
Does security controls implemented by CSP are as per Internationally accepted guidelines / standards (e.g. CSA Cloud Matrix, NIST, SANS, CIS Critical Controls, OWAPS, ISO)?
Does security controls implemented by CSP are as per Internationally accepted guidelines / standards (e.g. CSA Cloud Matrix, NIST, SANS, CIS Critical Controls, OWAPS, ISO)?
Is there a provision of demanding and review of compliance certificate like ISO27001 / PCI:DSS / NIST etc from CSP?
Is there a provision of demanding and review of compliance certificate like ISO27001 / PCI:DSS / NIST etc from CSP?
How does vendor and CSP ensure the confidentiality, integrity, availability and privacy of data collected, processes, stored and disposed through cloud services?
How does vendor and CSP ensure the confidentiality, integrity, availability and privacy of data collected, processes, stored and disposed through cloud services?
Are the roles and responsibility / duties for cloud services engagement clearly been segregated between the customer and vendor and between Vendor and CSP?
Are the roles and responsibility / duties for cloud services engagement clearly been segregated between the customer and vendor and between Vendor and CSP?
Is there a communication procedure available along with escalation matrix for vendor?
Is there a communication procedure available along with escalation matrix for vendor?
In event of legal / federal investigation of CSP / other tenants, how the security (C, I & A) of Vendor / the customer data is being maintained?
In event of legal / federal investigation of CSP / other tenants, how the security (C, I & A) of Vendor / the customer data is being maintained?
Has the service been audited in the past year for any of the following, by any independent entities? - Privacy - Information Security - Disaster Recovery - Operations - Technology - Other:
Has the service been audited in the past year for any of the following, by any independent entities? - Privacy - Information Security - Disaster Recovery - Operations - Technology - Other:
Have any of the audits addressed above resulted in any exceptions or findings?
Have any of the audits addressed above resulted in any exceptions or findings?
What is the production site physical address (DC, DR and Operations Location)?
What is the production site physical address (DC, DR and Operations Location)?
Are there any additional location(s) where target data (the customer data) is stored/ accessed/ processes/ transferred/ administered?
Are there any additional location(s) where target data (the customer data) is stored/ accessed/ processes/ transferred/ administered?
Please provide details in the following areas in scope to services being provided to the customer: - Operating system(s) - Workstations # of devices - Servers # of devices - List Applications in scope. - Number of employees by function (e.g., development, systems operations, information security)
Please provide details in the following areas in scope to services being provided to the customer: - Operating system(s) - Workstations # of devices - Servers # of devices - List Applications in scope. - Number of employees by function (e.g., development, systems operations, information security)
Details of control mechanism which will be deployed by the function to ensure that the service provider does not violate the internal norms of the insurer or the regulatory requirements set in the local regulator's guidelines? For example sample testing, maker checker, system controls, etc.
Details of control mechanism which will be deployed by the function to ensure that the service provider does not violate the internal norms of the insurer or the regulatory requirements set in the local regulator's guidelines? For example sample testing, maker checker, system controls, etc.
Do you maintain an information labelling and handling procedures? Are documented information tagged/labelled as per your asset classification schema which is at par with BSLI Information classification policy?
Do you maintain an information labelling and handling procedures? Are documented information tagged/labelled as per your asset classification schema which is at par with BSLI Information classification policy?
Are secure work areas adequately protected against environmental hazards? Do you have fire alarm/suppression systems installed across office (secure areas/work areas)? Do you have a VESDA system installed? Do you have temperature and humidity controls deployed? Do you have UPS and DG set systems in place? Do you have precision AC's installed? Do you have smoke detectors installed?
Are secure work areas adequately protected against environmental hazards? Do you have fire alarm/suppression systems installed across office (secure areas/work areas)? Do you have a VESDA system installed? Do you have temperature and humidity controls deployed? Do you have UPS and DG set systems in place? Do you have precision AC's installed? Do you have smoke detectors installed?
Do you use CCTV cameras to monitor the facility on a 7x24-hour basis? If Yes, are all cameras operating and positioned properly to view activity at all entrances/exits to the facility and sensitive areas (e.g.. call center, computer room)?
Do you use CCTV cameras to monitor the facility on a 7x24-hour basis? If Yes, are all cameras operating and positioned properly to view activity at all entrances/exits to the facility and sensitive areas (e.g.. call center, computer room)?
Is there a dedicated team responsible for Information Security?
Is there a dedicated team responsible for Information Security?
Whether all network Infra (Router, Switch, Firewall, etc.,) are integrated with the Service provider Domain and that a central IDAM solution or TACACS (Radius) is implemented for managing access to the network components?
Whether all network Infra (Router, Switch, Firewall, etc.,) are integrated with the Service provider Domain and that a central IDAM solution or TACACS (Radius) is implemented for managing access to the network components?
Whether audit requirements and activities involving checks on operational systems are carefully planned and agreed to minimize the risk of disruptions to business process? Do you agree to allow BSLI Auditors or Contracted Third Parties conduct IS Audit at your premise? Do your agree to allow Surprise Adits to be conducted by BSLI Auditors or Contracted Third Parties?
Whether audit requirements and activities involving checks on operational systems are carefully planned and agreed to minimize the risk of disruptions to business process? Do you agree to allow BSLI Auditors or Contracted Third Parties conduct IS Audit at your premise? Do your agree to allow Surprise Adits to be conducted by BSLI Auditors or Contracted Third Parties?
The organization has a Disaster Recovery Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Disaster Recovery Plan? Disaster Recovery Plan is tested atleast once in a year and test results/learnings are communicated to the customer? The organization has a Business Continuity Policy in place?
The organization has a Disaster Recovery Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Disaster Recovery Plan? Disaster Recovery Plan is tested atleast once in a year and test results/learnings are communicated to the customer? The organization has a Business Continuity Policy in place?
The organization has a Crisis Management in place for any Crisis Impacting its Operations? The organization has a Business Continuity/Alternate Site Plan in place to support/resume its key products & services? The Business Continuity plan complies to the recovery requirements of the customer (RTO,RPO & ROL) The organization has a Pandemic Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Business Continuity / Alternate Site Plan? Business Continuity / Alternate Site Plan is tested atleast once in a year and test results/learnings are communicated to the customer?
The organization has a Crisis Management in place for any Crisis Impacting its Operations? The organization has a Business Continuity/Alternate Site Plan in place to support/resume its key products & services? The Business Continuity plan complies to the recovery requirements of the customer (RTO,RPO & ROL) The organization has a Pandemic Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Business Continuity / Alternate Site Plan? Business Continuity / Alternate Site Plan is tested atleast once in a year and test results/learnings are communicated to the customer?
No Generic IDs to issued / used within the application
No Generic IDs to issued / used within the application
Appropriate architecture and processes to be set to ensure application meets the availability requirements through implementaton of HA / DR and Processes like Backup and restoration For SaaS applications SLAs need to be adhered to as well for uptime assurances provided
Appropriate architecture and processes to be set to ensure application meets the availability requirements through implementaton of HA / DR and Processes like Backup and restoration For SaaS applications SLAs need to be adhered to as well for uptime assurances provided
Ability to selective delete any Sensitive / PII information basis retention policy, customer request or as needed due to any business requirement
Ability to selective delete any Sensitive / PII information basis retention policy, customer request or as needed due to any business requirement
Does your organisation have a pandemic plan? Please submit a copy of the Pandemic plan mentioning the business continuity strategies for services rendered to the customer
Does your organisation have a pandemic plan? Please submit a copy of the Pandemic plan mentioning the business continuity strategies for services rendered to the customer
How would your company protect its employees and clients against getting infected in the Workplace? Please elaborate
How would your company protect its employees and clients against getting infected in the Workplace? Please elaborate
Is there a mechanism to identify and send sick employees or visitors home? Please elaborate
Is there a mechanism to identify and send sick employees or visitors home? Please elaborate
Are the mentioned business continuity strategies tested in the last 12 months?
Are the mentioned business continuity strategies tested in the last 12 months?
Does the business continuity strategies defined for pandemic fulfill the Recovery Time Objective, Recovery Point Objective & Revised Operating Level (MBCO) requirements as agreed contractually or mutually
Does the business continuity strategies defined for pandemic fulfill the Recovery Time Objective, Recovery Point Objective & Revised Operating Level (MBCO) requirements as agreed contractually or mutually
Are Crisis communicaiton procedures defined to notify the customer in case of any impact to your organisation due to pandemic situation and providing periodic updates on the developments.
Are Crisis communicaiton procedures defined to notify the customer in case of any impact to your organisation due to pandemic situation and providing periodic updates on the developments.
Does Supplier consider itself a Controller or Processor, or Joint Controller with the customer?
Does Supplier consider itself a Controller or Processor, or Joint Controller with the customer?
Does Supplier have an automatic method for advising the customer of new Sub Processors?
Does Supplier have an automatic method for advising the customer of new Sub Processors?
Does Supplier have adequate written agreements on data protection requiring appropriate technical and organisational measures in place with such Sub Processors or will be put into place prior to any subcontracting?
Does Supplier have adequate written agreements on data protection requiring appropriate technical and organisational measures in place with such Sub Processors or will be put into place prior to any subcontracting?
What certifications does Supplier have in place (i.e. SSAE 16 or ISAE 3402, ISO 27001 etc.)?
What certifications does Supplier have in place (i.e. SSAE 16 or ISAE 3402, ISO 27001 etc.)?
Does Supplier have business continuity plans that have been implemented and tested?
Does Supplier have business continuity plans that have been implemented and tested?
Does Supplier have cybersecurity insurance? If so, please provide material details of the coverage?
Does Supplier have cybersecurity insurance? If so, please provide material details of the coverage?
Confirm how Supplier demonstrates compliance with its data processing obligations.
Confirm how Supplier demonstrates compliance with its data processing obligations.
Provide the detailed Technical Architecture description of all the components of the proposed solution including monitoring solutions used by the provider
Provide the detailed Technical Architecture description of all the components of the proposed solution including monitoring solutions used by the provider
Can you list the security certifications of you company and can the customer get a certificate/report of the relevant certications
Can you list the security certifications of you company and can the customer get a certificate/report of the relevant certications
Provide an overview of the various standards, methodologies, processes and tools used to build in Security in your SDLC and detect security defects and vulnerabilities in your applications (internal or outsourced developments) prior to deployment to production (BSIMM, NIST, Manual or automated source code analysis, peer review, etc)
Provide an overview of the various standards, methodologies, processes and tools used to build in Security in your SDLC and detect security defects and vulnerabilities in your applications (internal or outsourced developments) prior to deployment to production (BSIMM, NIST, Manual or automated source code analysis, peer review, etc)
Can the customer get a copy of the last 2 reports of each of the audits performed and the action plan conducted to fix the identified issues?
Can the customer get a copy of the last 2 reports of each of the audits performed and the action plan conducted to fix the identified issues?
Describe the status of your readiness regarding European Directive EU 2016/1148 (NIS Directive) regarding the Security of the Network and Information System
Describe the status of your readiness regarding European Directive EU 2016/1148 (NIS Directive) regarding the Security of the Network and Information System
Provide the Continuity of Activity plan in place, including the frequency of the tests performed to ensure continuing effectiveness
Provide the Continuity of Activity plan in place, including the frequency of the tests performed to ensure continuing effectiveness
Provide an overview of the various standards, methodologies, tools, policies and processes in place to support service operations (ITIL v4 and COBIT 5, etc.)
Provide an overview of the various standards, methodologies, tools, policies and processes in place to support service operations (ITIL v4 and COBIT 5, etc.)
Describe how high availability of the proposed solution is addressed including redundancy mechanisms, geographical resilient hosting options, service failover capability to other providers, etc. Also describe the process in place to test redundancy and how frequent the test is performed.
Describe how high availability of the proposed solution is addressed including redundancy mechanisms, geographical resilient hosting options, service failover capability to other providers, etc. Also describe the process in place to test redundancy and how frequent the test is performed.
Describe the SLAs you are committed to regarding the impact of any disruption of your organization to your customers (degraded performances, service interruption, etc.) and what security KPI are made available to the customer in the contractual SLAs engaging the provider
Describe the SLAs you are committed to regarding the impact of any disruption of your organization to your customers (degraded performances, service interruption, etc.) and what security KPI are made available to the customer in the contractual SLAs engaging the provider
Provide the documentation regarding your program in place to manage risk
Provide the documentation regarding your program in place to manage risk
Do you have a cyber insurance?
Do you have a cyber insurance?
Describe how you provide training about Security and compliance to your staff, how often the awareness is performed, how you document their acknowledgment and the formal disciplinary or sanction policy established for employees who have violated security policies and procedures.
Describe how you provide training about Security and compliance to your staff, how often the awareness is performed, how you document their acknowledgment and the formal disciplinary or sanction policy established for employees who have violated security policies and procedures.
Describe how firewalling and vulnerability assessments accommodating the virtualization technologies is performed (e.g. virtualization aware)?
Describe how firewalling and vulnerability assessments accommodating the virtualization technologies is performed (e.g. virtualization aware)?
What is your process to monitor that system performance continuously meets all requirements (contractual, business, regulatory) to provide proper service to your customers. Can the customer run his own performance measurement?
What is your process to monitor that system performance continuously meets all requirements (contractual, business, regulatory) to provide proper service to your customers. Can the customer run his own performance measurement?
How often do you perform revalidations of the policies of FW, IPS, WAF, etc. and document the business justification in the access control lists.
How often do you perform revalidations of the policies of FW, IPS, WAF, etc. and document the business justification in the access control lists.
Describe the process to manage the Antivirus/antimalware and specify how frequently the patterns are updated and controlled.
Describe the process to manage the Antivirus/antimalware and specify how frequently the patterns are updated and controlled.
Describe how your tenants can report Bugs and security vulnerabilities and the process in place to remedy reported defects. Are your customers informed of discovered defects and the relevant remediation plan?
Describe how your tenants can report Bugs and security vulnerabilities and the process in place to remedy reported defects. Are your customers informed of discovered defects and the relevant remediation plan?
Describe how reversibility is addressed, and more specifically can virtual machine images be downloaded and ported to a new cloud provider or to on-site storage, how long the customer's data is available for his retrieval, under what format (e.g. OVF), etc.
Describe how reversibility is addressed, and more specifically can virtual machine images be downloaded and ported to a new cloud provider or to on-site storage, how long the customer's data is available for his retrieval, under what format (e.g. OVF), etc.
If you are relying on supplier/subcontractors, provide a full list of those involved in providing the contracted service and specify if you will stand Accountable for any security breach originating from one of your suppliers/subcontractors
If you are relying on supplier/subcontractors, provide a full list of those involved in providing the contracted service and specify if you will stand Accountable for any security breach originating from one of your suppliers/subcontractors
Provide an overview of the periodic reviews you perform to check the conformance and effectiveness of your policies, procedures and supporting measures and metrics. Specify how these reviews extend to all your partners upstream/downstream
Provide an overview of the periodic reviews you perform to check the conformance and effectiveness of your policies, procedures and supporting measures and metrics. Specify how these reviews extend to all your partners upstream/downstream
If administrators are allowed to access the infrastructure hosting the proposed solution using mobile devices, provide an exhaustive overview of your centralized MDM solution and more specifically of how you control integrity and security level of the private device and how you guarantee that no customer data is locally cached on the personal device
If administrators are allowed to access the infrastructure hosting the proposed solution using mobile devices, provide an exhaustive overview of your centralized MDM solution and more specifically of how you control integrity and security level of the private device and how you guarantee that no customer data is locally cached on the personal device
Have the information security policy and standards been approved by senior management?
Have the information security policy and standards been approved by senior management?
Is antivirus software installed on workstations?
Is antivirus software installed on workstations?
Does the organisation have security measures in place for data protection?
Does the organisation have security measures in place for data protection?
Are End User Devices (Servers, Desktops, Laptops, Tablets, Smartphones) used for transmitting, processing or storing Data has anti-malware, file integrity monitoring or application whitelisting deployed in the organisation?
Are End User Devices (Servers, Desktops, Laptops, Tablets, Smartphones) used for transmitting, processing or storing Data has anti-malware, file integrity monitoring or application whitelisting deployed in the organisation?
Are non-company managed PCs used to connect to the company network?
Are non-company managed PCs used to connect to the company network?
What is the frequency of BC/DR plan Testing?
What is the frequency of BC/DR plan Testing?
Have BC/DR drill been conducted at reguralar planed intervals?
Have BC/DR drill been conducted at reguralar planed intervals?
Are computer rooms protected against fire and flood? (2)
Are computer rooms protected against fire and flood? (2)
Is there an established incident management program approved by management, communicated to appropriate constituents, maintain and revieweed?
Is there an established incident management program approved by management, communicated to appropriate constituents, maintain and revieweed?
Are security incidents reviewed to capture the root cause and act on key learnings? (2)
Are security incidents reviewed to capture the root cause and act on key learnings? (2)
Does the organisation have a formal Incident Response plan?
Does the organisation have a formal Incident Response plan?
Are all potential incidents assessed to determine appropriate classification, severity and impact?
Are all potential incidents assessed to determine appropriate classification, severity and impact?
Has the organisation experienced an information security breach in the past three to five years?
Has the organisation experienced an information security breach in the past three to five years?
Does the organisation receive an SSAE-16 SOC Report? (2)
Does the organisation receive an SSAE-16 SOC Report? (2)
Does the organisationis been audited for ISO 27001 or for other security standards? (2)
Does the organisationis been audited for ISO 27001 or for other security standards? (2)
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)? (2)
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)? (2)
Are Global Blocklist and Whitelist configurations (such as URL's/domains inaccessible/accessible through the organization's proxies) enabled and reveiwed annually
Are Global Blocklist and Whitelist configurations (such as URL's/domains inaccessible/accessible through the organization's proxies) enabled and reveiwed annually
Users may have a legitimate business requirement to access blocked websites. If such a need arises, is there a process to request and obtain approval for the same?
Users may have a legitimate business requirement to access blocked websites. If such a need arises, is there a process to request and obtain approval for the same?
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)? (2)
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)? (2)
Does the current DLP solution have the capability to monitor all the endpoints within the Organization? (2)
Does the current DLP solution have the capability to monitor all the endpoints within the Organization? (2)
Is there a formalized risk governance plan that defines the Enterprise Risk Management program requirements?
Is there a formalized risk governance plan that defines the Enterprise Risk Management program requirements?
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization? (2)
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization? (2)
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause? (2)
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause? (2)
Is the Saas Solution deployed on public cloud or cloud hosted by Saas Vendor?
Is the Saas Solution deployed on public cloud or cloud hosted by Saas Vendor?
Are hardening standards defined and followed for all infrastructure components (OS, Network Devices, Servers, Firewalls, DBs etc.)
Are hardening standards defined and followed for all infrastructure components (OS, Network Devices, Servers, Firewalls, DBs etc.)
Is VPN and VPC services used for transmitting data securely e.g. tunneling services?
Is VPN and VPC services used for transmitting data securely e.g. tunneling services?
What kind of access the vendor employees will have on the application and how access to the customer data in the application is restricted from being accessed by Vendor employees?
What kind of access the vendor employees will have on the application and how access to the customer data in the application is restricted from being accessed by Vendor employees?
What policies are configured for restricting PII leakage from the system?
What policies are configured for restricting PII leakage from the system?
Is user access controlled and has limited access to the data and configuration settings on cloud?
Is user access controlled and has limited access to the data and configuration settings on cloud?
Vendor shall immediately inform the customer about any security incident.
Vendor shall immediately inform the customer about any security incident.
Does the agreement contains right to audit the service provider Information System
Does the agreement contains right to audit the service provider Information System
Compliant with all regulatory requirements
Compliant with all regulatory requirements
Compliance to IT Act and other Acts applicable to data
Compliance to IT Act and other Acts applicable to data
ISO 27001:2013 or any equivalent Information Secuirty Management System
ISO 27001:2013 or any equivalent Information Secuirty Management System
Service Organization Control SOC type 2 or any equivalent compliance report
Service Organization Control SOC type 2 or any equivalent compliance report
ISO 27018:2018 Code of Practice for Protection of PII in Public Cloud, if PII data is stored on the cloud.
ISO 27018:2018 Code of Practice for Protection of PII in Public Cloud, if PII data is stored on the cloud.
PCI-DSS in case the CSP handles card holder data if card data is processed and stored.
PCI-DSS in case the CSP handles card holder data if card data is processed and stored.
Which all processes Vendor is handling currently and how the customer is sharing the data with them?
Which all processes Vendor is handling currently and how the customer is sharing the data with them?
How data sharing between vendor and the customer will take place?
How data sharing between vendor and the customer will take place?
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Sub-contractor responsibilities and dependencies are clarified, and risks of employment of subcontractors are fully managed. Subcontractor is subject to all requirements the Contractor is.
Sub-contractor responsibilities and dependencies are clarified, and risks of employment of subcontractors are fully managed. Subcontractor is subject to all requirements the Contractor is.
Vendor has relevant encryption capabilities, and is able to apply encryption at the customer data at rest and in transit (when solution is to be hosted on the customer datacenter solution, it should be secured using a the customer approved digital certificate), whenever deemed necessary and required by the customer or relevant external regulation. The solution should provide secure and reliable ways to exchange data with the customer backend systems and SaaS applications as well.
Vendor has relevant encryption capabilities, and is able to apply encryption at the customer data at rest and in transit (when solution is to be hosted on the customer datacenter solution, it should be secured using a the customer approved digital certificate), whenever deemed necessary and required by the customer or relevant external regulation. The solution should provide secure and reliable ways to exchange data with the customer backend systems and SaaS applications as well.
Sufficient service uptime is guaranteed, meeting the customer expectations (on availability, RTO, RPO). Vendor has a BCP and DRP in place, ensuring service downtimes are kept as short as possible.
Sufficient service uptime is guaranteed, meeting the customer expectations (on availability, RTO, RPO). Vendor has a BCP and DRP in place, ensuring service downtimes are kept as short as possible.
There is proper control in place for the usage of system utilities to circumvent application controls, and this possibility is disabled.
There is proper control in place for the usage of system utilities to circumvent application controls, and this possibility is disabled.
Contractor is certified under external security best practices and standards (e.g. ISO). Contract shall include an audit clause that gives the customer the right to obtain independent audit reports (ISAE 3402 type 2, SOC 2, SSAE 18, ISO27k, PCI-DSS Level 1, etc.), network/application penetration testing reports, and vulnerability scanning results. The results can be summarized (not containing confidential technical details), or detailed when limited to the systems used by the customer. Furthermore, the customer should be allowed to initiate independent vulnerability scanning / penetration testing on the services received by the Vendor.
Contractor is certified under external security best practices and standards (e.g. ISO). Contract shall include an audit clause that gives the customer the right to obtain independent audit reports (ISAE 3402 type 2, SOC 2, SSAE 18, ISO27k, PCI-DSS Level 1, etc.), network/application penetration testing reports, and vulnerability scanning results. The results can be summarized (not containing confidential technical details), or detailed when limited to the systems used by the customer. Furthermore, the customer should be allowed to initiate independent vulnerability scanning / penetration testing on the services received by the Vendor.
Guarantees are offered to the customer on resolving security incidents / outages.
Guarantees are offered to the customer on resolving security incidents / outages.
Provide a general description of the information security measures applicable to the services you offer to the customer.
Provide a general description of the information security measures applicable to the services you offer to the customer.
the customer requires transfer outside of the EEA to have a valid legal basis. Please describe the legal basis for each of the countries that personal data is transferred to.
the customer requires transfer outside of the EEA to have a valid legal basis. Please describe the legal basis for each of the countries that personal data is transferred to.
Are you, or have you been involved in any legal proceedings, civil or public, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and document the outcome of these proceedings.
Are you, or have you been involved in any legal proceedings, civil or public, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and document the outcome of these proceedings.
Are you aware of any legal proceedings, civil or public, that any of your (sub) processors have been involved in, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and outcome of these proceedings.
Are you aware of any legal proceedings, civil or public, that any of your (sub) processors have been involved in, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and outcome of these proceedings.
To the extent applicable: 1) Describe the certifications and audit scheme that you have or will put in place, to allow the customer to verify compliance with applicable law and the Data Processing Agreement during the contract period 2) Describe the regularity and scope of any third party audits with regard to information security, data protection compliance and to what extent (sub) contractors are covered by the audit schemes 3) Describe how the customer will obtain access to reports from audits for any transfer of Personal Data to countries outside the EEA.
To the extent applicable: 1) Describe the certifications and audit scheme that you have or will put in place, to allow the customer to verify compliance with applicable law and the Data Processing Agreement during the contract period 2) Describe the regularity and scope of any third party audits with regard to information security, data protection compliance and to what extent (sub) contractors are covered by the audit schemes 3) Describe how the customer will obtain access to reports from audits for any transfer of Personal Data to countries outside the EEA.
Through discussions with the vendor, try to obtain an overview of the value chain from the cloud vendor and backwards to subcontractors
Through discussions with the vendor, try to obtain an overview of the value chain from the cloud vendor and backwards to subcontractors
Does the contract detail the scope and functionality of the online services?
Does the contract detail the scope and functionality of the online services?
Any written documentation for the SLA? Are SLA objectives measurable and have relevant penalties? Do they cover availability, response times or other? What does the SLA cover?
Any written documentation for the SLA? Are SLA objectives measurable and have relevant penalties? Do they cover availability, response times or other? What does the SLA cover?
Are there any technical and organisational measures that aim to remedy the risks entailed by lack of control and lack of information featuring in the cloud computing environment? E.g. measures aimed at ensuring availability, integrity, confidentiality, isolation, intervenability and portability.
Are there any technical and organisational measures that aim to remedy the risks entailed by lack of control and lack of information featuring in the cloud computing environment? E.g. measures aimed at ensuring availability, integrity, confidentiality, isolation, intervenability and portability.
What kind of certifications does the cloud vendor have (ISO 2001, SOC report etc.)?
What kind of certifications does the cloud vendor have (ISO 2001, SOC report etc.)?
Is there a clause saying that no data shall be processed by Supplier or any subcontractors for other purposes than the one specified in the contract?
Is there a clause saying that no data shall be processed by Supplier or any subcontractors for other purposes than the one specified in the contract?
Does the contract specify that Supplier may not communicate the data to third parties, even for preservation purposes unless it is provided for in the contract that there will be subcontractors?
Does the contract specify that Supplier may not communicate the data to third parties, even for preservation purposes unless it is provided for in the contract that there will be subcontractors?
Does the data processing agreement specify the types of personal data processed by Supplier?
Does the data processing agreement specify the types of personal data processed by Supplier?
Does the contract ensure a logging of processing operations on personal data performed by Supplier and its sub-contractors?
Does the contract ensure a logging of processing operations on personal data performed by Supplier and its sub-contractors?
Does the Supplier ensure lawfulness of cross-border data transfers and do they have a list of locations in which the services may be provided from? May the customer limit the vendor's right to change or disregard such a list?
Does the Supplier ensure lawfulness of cross-border data transfers and do they have a list of locations in which the services may be provided from? May the customer limit the vendor's right to change or disregard such a list?
Does the contract include any clause specifying that Supplier must inform the customer of any intended changes in regards to changes in sub-processors? the customer shall retain at all times the possibility to object to such changes or to terminate the contract.
Does the contract include any clause specifying that Supplier must inform the customer of any intended changes in regards to changes in sub-processors? the customer shall retain at all times the possibility to object to such changes or to terminate the contract.
Any specific restrictions in the right to use? Acceptable use policy is one example that should be considered versus the customer's needs.
Any specific restrictions in the right to use? Acceptable use policy is one example that should be considered versus the customer's needs.
Does the cloud provider have right to suspend services for specific reasons? As an example, in a situation with non-payment? If yes, is there a notice period or other important conditions to be observed?
Does the cloud provider have right to suspend services for specific reasons? As an example, in a situation with non-payment? If yes, is there a notice period or other important conditions to be observed?
Which law is the contract subject to? What are the legal venue for disputes arising under the contract? What are the regulations around dispute resolution?
Which law is the contract subject to? What are the legal venue for disputes arising under the contract? What are the regulations around dispute resolution?
Do you perform a regular information security risk assessment?
Do you perform a regular information security risk assessment?
Do you provide customers with ongoing visibility and reporting of your SLA performance?
Do you provide customers with ongoing visibility and reporting of your SLA performance?
Do you have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
Do you have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
Are there policies and procedures in place to triage and remedy reported bugs and security vulnerabilities for product and service offerings?
Are there policies and procedures in place to triage and remedy reported bugs and security vulnerabilities for product and service offerings?
Do you specifically train your employees regarding their specific role and the information security controls they must fulfil?
Do you specifically train your employees regarding their specific role and the information security controls they must fulfil?
Name and description of the software/service.
Name and description of the software/service.
Is there a respondent information security function responsible for security initiatives?
Is there a respondent information security function responsible for security initiatives?
Can the respondent do Creation, review and approve of information security policies?
Can the respondent do Creation, review and approve of information security policies?
What are your data leak prevention capabilities?
What are your data leak prevention capabilities?
Do you have a policy that requires endpoints (laptops,desktops,etc) to have anti-malware software? What capabilities does the anti-malware solution has? (Signature based detections, NGAV, EDR, etc.)
Do you have a policy that requires endpoints (laptops,desktops,etc) to have anti-malware software? What capabilities does the anti-malware solution has? (Signature based detections, NGAV, EDR, etc.)
Does your IT provide remote wipe or corporate data wipe for all endpoints (laptops,desktops,etc) and company-accepted BYOD devices?
Does your IT provide remote wipe or corporate data wipe for all endpoints (laptops,desktops,etc) and company-accepted BYOD devices?
Is the solution provided to Customer part of a valid ISO 27001 certification? If so, please provide a valid ISO/IEC 27001 certificate with corresponding SOA - Statement of Applicability
Is the solution provided to Customer part of a valid ISO 27001 certification? If so, please provide a valid ISO/IEC 27001 certificate with corresponding SOA - Statement of Applicability
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports? (2)
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports? (2)
Does the Company use Software Development Life Cycle (SDLC) process to ensure quality and correctness of the solution built?
Does the Company use Software Development Life Cycle (SDLC) process to ensure quality and correctness of the solution built?
What is the strategy around application Secure Code Scanning & management?
What is the strategy around application Secure Code Scanning & management?
Is there a status page available for communication about the application's untime status, or any ongoing and past incidents?
Is there a status page available for communication about the application's untime status, or any ongoing and past incidents?
Are the retained logs sufficient to permit forensic analysis on security events?
Are the retained logs sufficient to permit forensic analysis on security events?
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants?
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants?
What is your SLA - uptime and availability?
What is your SLA - uptime and availability?
What is the penalty offered to the customers for SLA violations?
What is the penalty offered to the customers for SLA violations?
What level of support is provided to the clients? Mention the time slots where support is available
What level of support is provided to the clients? Mention the time slots where support is available
Please provide support covered under standard annual license and annual maintenance where applicable
Please provide support covered under standard annual license and annual maintenance where applicable
Details of certifications Which includes for each certification: Certification Body First Certification Date Current Certification date
Details of certifications Which includes for each certification: Certification Body First Certification Date Current Certification date
The vendor should detail how frequently backups of customer data are made, how long they are retained, and how soon customer data is purged following deletion by an end user
The vendor should detail how frequently backups of customer data are made, how long they are retained, and how soon customer data is purged following deletion by an end user
Define Service monitoring.
Define Service monitoring.
Does the role of Quality unit during product development and/or during service provision define?
Does the role of Quality unit during product development and/or during service provision define?
When our company needs to access the logs of Vendor and our company or that of our company's users for case investigation, how long does it take Vendor to provide complete logs to our company? (1-24 hours is appropriate)
When our company needs to access the logs of Vendor and our company or that of our company's users for case investigation, how long does it take Vendor to provide complete logs to our company? (1-24 hours is appropriate)
In the admin console, is there an interactive interface to look up our company's user's detailed information?
In the admin console, is there an interactive interface to look up our company's user's detailed information?
What kind of permission request process do Vendor's O&M personnel, including DBAs, would go through if they want to refer to our company's data stored in the Vendor backend system?
What kind of permission request process do Vendor's O&M personnel, including DBAs, would go through if they want to refer to our company's data stored in the Vendor backend system?
When the Vendor's operation and maintenance personnel, including the DBA, try to refer to our company's data stored in the Vendor backend system, is there an audit log record of the entire operation process?
When the Vendor's operation and maintenance personnel, including the DBA, try to refer to our company's data stored in the Vendor backend system, is there an audit log record of the entire operation process?
When the logs which described above are needed, whether or not can it be completely provided to our company when there is a need for case investigation?
When the logs which described above are needed, whether or not can it be completely provided to our company when there is a need for case investigation?
When the logs which described above are needed, how long does it take Vendor to provide them to our company? (1-24 hours is appropriate)
When the logs which described above are needed, how long does it take Vendor to provide them to our company? (1-24 hours is appropriate)
Are there any other compliance qualifications? If so, please list out in detail
Are there any other compliance qualifications? If so, please list out in detail
Summary of key risks based on risk assessment reports
Summary of key risks based on risk assessment reports
A risk management process shall be used to balance the benefits of cloud computing with the security risks associated before engaging with a Cloud Service provider.
A risk management process shall be used to balance the benefits of cloud computing with the security risks associated before engaging with a Cloud Service provider.
The risk assessment framework adopted by NSE may be used for the cloud service risk assessment.
The risk assessment framework adopted by NSE may be used for the cloud service risk assessment.
The outcome of the risk management process shall determine the model and controls that shall be adopted.
The outcome of the risk management process shall determine the model and controls that shall be adopted.
The Cloud Service Provider shall ensure that it will demonstrate compliance with NSE policy requirements and regulatory requirements.
The Cloud Service Provider shall ensure that it will demonstrate compliance with NSE policy requirements and regulatory requirements.
The Cloud Service Provider shall conduct annual audit by an independent third-party auditor to check the design effectiveness as well as their operating effectiveness of their internal controls covering the principles of Security, Availability, Confidentiality, and Privacy.
The Cloud Service Provider shall conduct annual audit by an independent third-party auditor to check the design effectiveness as well as their operating effectiveness of their internal controls covering the principles of Security, Availability, Confidentiality, and Privacy.
NSE shall be provided access to these reports as and when required.
NSE shall be provided access to these reports as and when required.
The Cloud Service Provider shall provide complete visibility to ensure NSE's services are being processes and delivered in a secure manner.
The Cloud Service Provider shall provide complete visibility to ensure NSE's services are being processes and delivered in a secure manner.
NSE shall have all the Service Level arrangements documented in the agreement/ contract with the Cloud Service provider guided by NSE's Outsourcing Policy.
NSE shall have all the Service Level arrangements documented in the agreement/ contract with the Cloud Service provider guided by NSE's Outsourcing Policy.
NSE shall review the Service Level Agreements (SLA) for amendments, annually or as when required.
NSE shall review the Service Level Agreements (SLA) for amendments, annually or as when required.
Cloud Service Provider shall provide regular reports on the SLA achieved and compliance to the agreement/contract to NSE. The frequency of reporting shall be mandated in the agreement / contract.
Cloud Service Provider shall provide regular reports on the SLA achieved and compliance to the agreement/contract to NSE. The frequency of reporting shall be mandated in the agreement / contract.
Any breach in the SLA by Cloud Service provider shall be reported as mandated by NSE.
Any breach in the SLA by Cloud Service provider shall be reported as mandated by NSE.
In a multi-tenant cloud architecture, the Cloud Service Provider shall ensure that NSE's data shall be isolated and inaccessible to any other tenants.
In a multi-tenant cloud architecture, the Cloud Service Provider shall ensure that NSE's data shall be isolated and inaccessible to any other tenants.
Any access by other tenants to NSE's data shall be considered as a breach and the Cloud Service Provider shall ensure the breach notification process is followed.
Any access by other tenants to NSE's data shall be considered as a breach and the Cloud Service Provider shall ensure the breach notification process is followed.
Cloud Service provider shall notify NSE of any potential breach incident or any actual breach as mandated by NSE.
Cloud Service provider shall notify NSE of any potential breach incident or any actual breach as mandated by NSE.
NSE shall ensure that the cloud computing services can be ported to any other Cloud Service Provider or to other data centres with least impact to business.
NSE shall ensure that the cloud computing services can be ported to any other Cloud Service Provider or to other data centres with least impact to business.
On completion of the transfer, the Cloud Service Provider shall delete all the data and information from its infrastructure and provide a certificate to NSE that the data has been securely deleted and the same cannot be recovered by any means.
On completion of the transfer, the Cloud Service Provider shall delete all the data and information from its infrastructure and provide a certificate to NSE that the data has been securely deleted and the same cannot be recovered by any means.
Wherever applicable, NSE shall maintain an up to date inventory of hardware, software and virtual assets hosting NSE's applications and data.
Wherever applicable, NSE shall maintain an up to date inventory of hardware, software and virtual assets hosting NSE's applications and data.
The inventory shall be reviewed and updated as per the Asset Management Policy of NSE.
The inventory shall be reviewed and updated as per the Asset Management Policy of NSE.
Cloud Service Provider shall ensure that no database server, application server or storage devices hosting NSE's data & information be made publicly available over the internet.
Cloud Service Provider shall ensure that no database server, application server or storage devices hosting NSE's data & information be made publicly available over the internet.
When is live (standard service) phone technical support available? Is backup (phone or email) available for off-hours?
When is live (standard service) phone technical support available? Is backup (phone or email) available for off-hours?
Describe the training that is available with the initial system installation.
Describe the training that is available with the initial system installation.
What type of training does your company recommend, require, and offer?
What type of training does your company recommend, require, and offer?
Do you provide on-demand training over the Internet? If so, what training is available to users? Is there an associated cost?
Do you provide on-demand training over the Internet? If so, what training is available to users? Is there an associated cost?
What is your escalation process for support issues? Describe in detail.
What is your escalation process for support issues? Describe in detail.
Who will have access to UP data? (Just Supplier employees? Contractors? Employees and contingent employees?)
Who will have access to UP data? (Just Supplier employees? Contractors? Employees and contingent employees?)
Describe your employee and contractor background checks
Describe your employee and contractor background checks
How do you monitor third parties that have access to UP data?
How do you monitor third parties that have access to UP data?
Does the cloud service provider require the use of two-factor authentication for the administrative control of servers, routers, switches and firewalls?
Does the cloud service provider require the use of two-factor authentication for the administrative control of servers, routers, switches and firewalls?
How is user access monitored and documented?
How is user access monitored and documented?
Network IDS?
Network IDS?
Host IDS?
Host IDS?
SIEM?
SIEM?
Are security controls audited on an annual basis?
Are security controls audited on an annual basis?
Can documentation be provided that can show how UP data cannot be compromised by other customers or non-customers of the Supplier?
Can documentation be provided that can show how UP data cannot be compromised by other customers or non-customers of the Supplier?
What is the size and relevant experience (in years) of the security and incident response teams?
What is the size and relevant experience (in years) of the security and incident response teams?
How is the data stored?
How is the data stored?
Is planned/scheduled maintenance included in the calculated uptime? Will it count against the SLA?
Is planned/scheduled maintenance included in the calculated uptime? Will it count against the SLA?
Does planned/scheduled maintenance count against the SLA?
Does planned/scheduled maintenance count against the SLA?
What is your resiliency, reliability, back-up and disaster recovery strategy?
What is your resiliency, reliability, back-up and disaster recovery strategy?
How often are these processes tested?
How often are these processes tested?
Describe your established maintenance window.
Describe your established maintenance window.
Describe in detail your service or mitigation plans to continue to make the service available to customers during a denial of service attack.
Describe in detail your service or mitigation plans to continue to make the service available to customers during a denial of service attack.
Does the architecture of the provided service include redundancy of security systems, including firewalls, IDS/IPS, any other critical security service?
Does the architecture of the provided service include redundancy of security systems, including firewalls, IDS/IPS, any other critical security service?
Does Supplier have established procedures for cooperating with local government and law enforcement requesting customer data?
Does Supplier have established procedures for cooperating with local government and law enforcement requesting customer data?
Describe your established procedures for cooperating with local government and law enforcement requesting customer data.
Describe your established procedures for cooperating with local government and law enforcement requesting customer data.
Which cloud providers do you rely on?
Which cloud providers do you rely on?
Does the penetration test follow an industry approved methodology, please describe
Does the penetration test follow an industry approved methodology, please describe
Please describe the company/user data you require to provide your service: personal information, financial data, confidential/sensitive data, government data
Please describe the company/user data you require to provide your service: personal information, financial data, confidential/sensitive data, government data
Do you have capabilities to anonymize data?
Do you have capabilities to anonymize data?
Do you keep sensitive data (as defined by your data classification matrix) in hard copy (e.g. paper copies)? If so, please describe.
Do you keep sensitive data (as defined by your data classification matrix) in hard copy (e.g. paper copies)? If so, please describe.
How do you regularly audit your critical vendors?
How do you regularly audit your critical vendors?
Do you have a formal Information Security Program (InfoSec SP) in place?
Do you have a formal Information Security Program (InfoSec SP) in place?
Do you review your Information Security Policies at least once a year?
Do you review your Information Security Policies at least once a year?
Do you have a Information security risk management program (InfoSec RMP)?
Do you have a Information security risk management program (InfoSec RMP)?
Do you have management support or a security management forum to evaluate and take action on security risks?
Do you have management support or a security management forum to evaluate and take action on security risks?
Do you have a dedicated information security team? If so, what is the composition and reporting structure?
Do you have a dedicated information security team? If so, what is the composition and reporting structure?
Do you publish a path for responisble disclosure of security vulnerabilities (ie security@ or /security)?
Do you publish a path for responisble disclosure of security vulnerabilities (ie security@ or /security)?
Do you have an established bug bounty program?
Do you have an established bug bounty program?
Are all endpoint laptops that connect directly to production networks centrally managed?
Are all endpoint laptops that connect directly to production networks centrally managed?
Describe standard employee issued device security configuration/features. (Login Password, antimalware, Full Disk Encryption, Administrative Privileges, Firewall, Auto-lock, etc.)
Describe standard employee issued device security configuration/features. (Login Password, antimalware, Full Disk Encryption, Administrative Privileges, Firewall, Auto-lock, etc.)
Does sensitive or private data ever reside on endpoint devices? How is this policy enforced?
Does sensitive or private data ever reside on endpoint devices? How is this policy enforced?
How do you keep aware of potential security vulnerabilities and threats that may affect your service?
How do you keep aware of potential security vulnerabilities and threats that may affect your service?
How is your Incident Response Plan tested? Include how often.
How is your Incident Response Plan tested? Include how often.
Describe how threat modelling is incorporated in the design phase of development?
Describe how threat modelling is incorporated in the design phase of development?
How do you train developers in SSDLC / Secure Coding Practices?
How do you train developers in SSDLC / Secure Coding Practices?
How do you monitor vulnerabilities in dependencies?
How do you monitor vulnerabilities in dependencies?
Do you outsource development? (contracted with a 3rd party? open source project inclusion?)
Do you outsource development? (contracted with a 3rd party? open source project inclusion?)
What types of security reviews do you perform on custom-built software?
What types of security reviews do you perform on custom-built software?
Does application support IP whitelisting for API access?
Does application support IP whitelisting for API access?
How do you conduct internal audits (audits lead by your personnel) of the service? please describe the scope, remediation process and frequency of audits.
How do you conduct internal audits (audits lead by your personnel) of the service? please describe the scope, remediation process and frequency of audits.
How do you conduct external (third-party) audits of the service? please describe the scope and frequency of audits.
How do you conduct external (third-party) audits of the service? please describe the scope and frequency of audits.
Please provide a copy of the most recent report.
Please provide a copy of the most recent report.
Do you seek a right to use or own customer derived data for your own purposes?
Do you seek a right to use or own customer derived data for your own purposes?
Do your information security and privacy policies align with industry standards (ISO-27001, NIST Cyber Security Framework, ISO-22307, CoBIT, etc.)?
Do your information security and privacy policies align with industry standards (ISO-27001, NIST Cyber Security Framework, ISO-22307, CoBIT, etc.)?
Are all personnel required to sign Confidentiality Agreements to protect customer information, as a condition of employment?
Are all personnel required to sign Confidentiality Agreements to protect customer information, as a condition of employment?
Hardware security
Hardware security
Paper Document Security
Paper Document Security
Physical access control
Physical access control
Maintenance - Describe here how physical maintenance of hardware is managed
Maintenance - Describe here how physical maintenance of hardware is managed
Backups - Indicate here how backups are managed. Clarify whether they are stored in safe place
Backups - Indicate here how backups are managed. Clarify whether they are stored in safe place
Governance - Describe the documentary base setting out data protection objectives and rules
Governance - Describe the documentary base setting out data protection objectives and rules
Managing Privacy Risk - Describe processes to control the risks that processing operations performed by the organisation
Managing Privacy Risk - Describe processes to control the risks that processing operations performed by the organisation
If the customer data will be held by a subcontractor to your organisation, how will you ensure that their Information Security meets required standards?
If the customer data will be held by a subcontractor to your organisation, how will you ensure that their Information Security meets required standards?
Will an asset register be completed to log all assets holding the customer data and who is responsible for updating it?
Will an asset register be completed to log all assets holding the customer data and who is responsible for updating it?
How will you decide which of your staff (support, development etc.) need access to the the customer system and data? How will you manage that access and what controls are in place, to ensure that privileged access rights will be restricted and controlled?
How will you decide which of your staff (support, development etc.) need access to the the customer system and data? How will you manage that access and what controls are in place, to ensure that privileged access rights will be restricted and controlled?
Is your organisation ISO/IEC 27001 or similarly certified or compliant? Please provide details. If yes please provide evidence and skip section 5.
Is your organisation ISO/IEC 27001 or similarly certified or compliant? Please provide details. If yes please provide evidence and skip section 5.
When a person working with the customer data no longer performs that role, are their permissions to the customer data revoked?
When a person working with the customer data no longer performs that role, are their permissions to the customer data revoked?
Is your organisation's Information Security Management System (i.e. control objectives, controls, policies, processes and procedures for information security) reviewed, internally and independently audited for compliance at planned intervals or when significant changes to the security implementation occurs?
Is your organisation's Information Security Management System (i.e. control objectives, controls, policies, processes and procedures for information security) reviewed, internally and independently audited for compliance at planned intervals or when significant changes to the security implementation occurs?
Have all relevant statutory, regulatory, contractual requirements, (including: intellectual property rights, protection of records, protection of personally identifiable information and cryptographic controls) and the organisation's approach to meet these requirements, been explicitly identified, documented and kept up to date, for the/each the customer information system?
Have all relevant statutory, regulatory, contractual requirements, (including: intellectual property rights, protection of records, protection of personally identifiable information and cryptographic controls) and the organisation's approach to meet these requirements, been explicitly identified, documented and kept up to date, for the/each the customer information system?
Describe how and when media containing the customer data would be securely destroyed and how you would evidence this?
Describe how and when media containing the customer data would be securely destroyed and how you would evidence this?
Will any physical media containing the customer data, be transferred outside your organisation and if so, what procedures will be in place to protect the media from compromise?
Will any physical media containing the customer data, be transferred outside your organisation and if so, what procedures will be in place to protect the media from compromise?
Is there a documented standard procedure followed for building and hardening host machines? If so please attach a copy.
Is there a documented standard procedure followed for building and hardening host machines? If so please attach a copy.
Are these procedures periodically reviewed and kept in line with current best practice?
Are these procedures periodically reviewed and kept in line with current best practice?
How will security incidents relating to the customer data be reported to the customer?
How will security incidents relating to the customer data be reported to the customer?
What physical measures (e.g. CCTV, Coded Locks, Guards) will be in place to protect the customer data that is stored: At your offices/location At the data centre How will these controls be managed and monitored?
What physical measures (e.g. CCTV, Coded Locks, Guards) will be in place to protect the customer data that is stored: At your offices/location At the data centre How will these controls be managed and monitored?
Emergency, temporary or test accounts should be documented, have a specified period of validity and terminated immediately after validity period expires.
Emergency, temporary or test accounts should be documented, have a specified period of validity and terminated immediately after validity period expires.
Responsibilities and duties for system users shall be segregated based on the defined roles.
Responsibilities and duties for system users shall be segregated based on the defined roles.
There should be a minimum three types of user groups for systems and applications (e.g. operator, supervisor, engineer, domain administrator, etc.) where technically feasible.
There should be a minimum three types of user groups for systems and applications (e.g. operator, supervisor, engineer, domain administrator, etc.) where technically feasible.
Role based user accounts shall be implemented for operation users (operators, supervisors, shift controller, engineer, etc.) with specific and defined privileges based on the principle of least privilege for each role.
Role based user accounts shall be implemented for operation users (operators, supervisors, shift controller, engineer, etc.) with specific and defined privileges based on the principle of least privilege for each role.
Privileges for all accounts used with the customer assets shall be identified and documented.
Privileges for all accounts used with the customer assets shall be identified and documented.
Where strong authentication and identity verification is required, authentication methods alternative, or additional, to passwords, such as cryptographic means, smart cards, tokens or biometric means, shall be used.
Where strong authentication and identity verification is required, authentication methods alternative, or additional, to passwords, such as cryptographic means, smart cards, tokens or biometric means, shall be used.
Temporary account user name and passwords shall be communicated in a secure manner following these practices: When users are required to change the passwords, they should initially be provided with secure temporary authentication information, which they are immediately forced to change. Verify the identity of a user prior to providing a new, replacement or temporary password. Temporary authentication information shall be unique to a user. Users shall acknowledge the receipt of temporary passwords.
Temporary account user name and passwords shall be communicated in a secure manner following these practices: When users are required to change the passwords, they should initially be provided with secure temporary authentication information, which they are immediately forced to change. Verify the identity of a user prior to providing a new, replacement or temporary password. Temporary authentication information shall be unique to a user. Users shall acknowledge the receipt of temporary passwords.
All users and access to the customer networks and services shall be documented.
All users and access to the customer networks and services shall be documented.
Where technically feasible, ensure all authentication attempts (successful and unsuccessful) are logged up to the capabilities of the authentication system.
Where technically feasible, ensure all authentication attempts (successful and unsuccessful) are logged up to the capabilities of the authentication system.
Only protocol ports and services required for proper functioning of the system or application shall be allowed on each system.
Only protocol ports and services required for proper functioning of the system or application shall be allowed on each system.
All network filtering mechanisms (e.g. firewalls) shall apply an opt-in principle with a fail-safe mechanism (i.e. default deny rule that drops all traffic, except that which is explicitly allowed and if an error/failure occurs the system should fail in a secure manner: security controls and settings remain in effect and are enforced).
All network filtering mechanisms (e.g. firewalls) shall apply an opt-in principle with a fail-safe mechanism (i.e. default deny rule that drops all traffic, except that which is explicitly allowed and if an error/failure occurs the system should fail in a secure manner: security controls and settings remain in effect and are enforced).
All equipment connected to the customer networks shall be identified and classified based on the defined classification scheme. All equipment connected to the customer networks should have appropriate technical and/or business justifications supporting the need for that connection.
All equipment connected to the customer networks shall be identified and classified based on the defined classification scheme. All equipment connected to the customer networks should have appropriate technical and/or business justifications supporting the need for that connection.
Unique identifiers shall be developed in, or attached to, the equipment to indicate whether the asset is permitted to connect to the network.
Unique identifiers shall be developed in, or attached to, the equipment to indicate whether the asset is permitted to connect to the network.
Where technically feasible, implement network-based technical controls that detect and prevent connections and/or attempts to connect equipment to the customer networks.
Where technically feasible, implement network-based technical controls that detect and prevent connections and/or attempts to connect equipment to the customer networks.
Detection capabilities should be augmented with event correlation (e.g. SIEM) used to correlate approved and expected connections of equipment to the customer networks.
Detection capabilities should be augmented with event correlation (e.g. SIEM) used to correlate approved and expected connections of equipment to the customer networks.
Network devices shall be securely configured taking following measures into consideration: Source and address violation rules. Router protection (e.g. hardening). Specific sub-netting for publicly accessible systems. Boundary protection device for external connections. Monitoring for suspicious traffic.
Network devices shall be securely configured taking following measures into consideration: Source and address violation rules. Router protection (e.g. hardening). Specific sub-netting for publicly accessible systems. Boundary protection device for external connections. Monitoring for suspicious traffic.
Wherever feasible, vendor-supplied software packages shall be used without any changes.
Wherever feasible, vendor-supplied software packages shall be used without any changes.
When changes to software packages are required, the following shall be considered: Responsibility for future maintenance of the software. Compatibility with existing application software. Risks of existing application controls being altered or compromised.
When changes to software packages are required, the following shall be considered: Responsibility for future maintenance of the software. Compatibility with existing application software. Risks of existing application controls being altered or compromised.
Where technically feasible, any changes to software shall be tested in a non-production/test environment before moving it to a production environment.
Where technically feasible, any changes to software shall be tested in a non-production/test environment before moving it to a production environment.
Based on the information asset's classification, controls shall be applied to restrict access to information and applications.
Based on the information asset's classification, controls shall be applied to restrict access to information and applications.
Service account passwords or application hard-coded passwords that cannot be changed shall be documented and additional compensating controls shall be identified to protect and monitor such systems.
Service account passwords or application hard-coded passwords that cannot be changed shall be documented and additional compensating controls shall be identified to protect and monitor such systems.
Contracts with vendors shall include the requirements for secure design, coding, testing practices and a warranty clause that the software/system is free from security vulnerabilities.
Contracts with vendors shall include the requirements for secure design, coding, testing practices and a warranty clause that the software/system is free from security vulnerabilities.
Document/guide for secure use or operation of the supplied system or component shall be provided
Document/guide for secure use or operation of the supplied system or component shall be provided
Patch management policy and process is in place to cover patch qualification, patch distribution, update and auditing process
Patch management policy and process is in place to cover patch qualification, patch distribution, update and auditing process
Third parties shall address security vulnerabilities brought to its attention by the customer in a timely manner.
Third parties shall address security vulnerabilities brought to its attention by the customer in a timely manner.
For any hardware, software or firmware, supplied, a quality certificate (QC) ensuring that all provided hardware, software or firmware is free from any dormant malicious programmes should be provided.
For any hardware, software or firmware, supplied, a quality certificate (QC) ensuring that all provided hardware, software or firmware is free from any dormant malicious programmes should be provided.
All systems shall be tested prior to acquisition and prior to accepting new systems into operational environment based on predefined criteria.
All systems shall be tested prior to acquisition and prior to accepting new systems into operational environment based on predefined criteria.
Identify and document criteria for testing new features or enhancements to existing systems or assets.
Identify and document criteria for testing new features or enhancements to existing systems or assets.
Define criteria for accepting products (e.g. in terms of their functionality), to ensure identified security requirements are met.
Define criteria for accepting products (e.g. in terms of their functionality), to ensure identified security requirements are met.
Ensure tests are performed and results are documented.
Ensure tests are performed and results are documented.
Where the functionality in a proposed product does not satisfy the specified requirement, the risk introduced, and associated controls should be documented and reconsidered prior to purchasing the product.
Where the functionality in a proposed product does not satisfy the specified requirement, the risk introduced, and associated controls should be documented and reconsidered prior to purchasing the product.
All system vendors and third parties shall follow security test processes outlined in the system and services acquisition process document (e.g. FAT, SAT, unit testing, integration testing and UAT)
All system vendors and third parties shall follow security test processes outlined in the system and services acquisition process document (e.g. FAT, SAT, unit testing, integration testing and UAT)
the customer responsible staff shall sign-off and certify that all relevant security requirements have been tested satisfactorily before turn-over to operations.
the customer responsible staff shall sign-off and certify that all relevant security requirements have been tested satisfactorily before turn-over to operations.
Any variation between system design and system implementation shall be recorded and security risk assessment shall be conducted to determine mitigation strategies.
Any variation between system design and system implementation shall be recorded and security risk assessment shall be conducted to determine mitigation strategies.
All software and hardware acquisition contracts shall include identified rules and requirements and require compliance and the possibility to audit the development processes.
All software and hardware acquisition contracts shall include identified rules and requirements and require compliance and the possibility to audit the development processes.
Only licensed third-party libraries and components shall be used.
Only licensed third-party libraries and components shall be used.
Formal change control processes shall be used to manage changes to software code, taking into account that: Impacts of changes to software are understood using risk assessment methodologies. Changes do not compromise exiting security and control measures. Existing documentation is updated. Acceptance testing is performed to validate if system behaves only as expected.
Formal change control processes shall be used to manage changes to software code, taking into account that: Impacts of changes to software are understood using risk assessment methodologies. Changes do not compromise exiting security and control measures. Existing documentation is updated. Acceptance testing is performed to validate if system behaves only as expected.
Vendors and third parties shall provide documented artefacts to ensure that security controls as requested within this manual are instituted in the system.
Vendors and third parties shall provide documented artefacts to ensure that security controls as requested within this manual are instituted in the system.
All supply chain requirements are also applicable to work subcontracted by vendors and third parties to develop, test or integrate systems for the customer.
All supply chain requirements are also applicable to work subcontracted by vendors and third parties to develop, test or integrate systems for the customer.
All conditions under which the transfer of information/data must be protected shall be documented and maintained.
All conditions under which the transfer of information/data must be protected shall be documented and maintained.
Actions to be taken when issues arise regarding the transfer of information/data must be identified and documented.
Actions to be taken when issues arise regarding the transfer of information/data must be identified and documented.
To ensure information is adequately protected during transfer, specific controls and procedures shall be identified. Security controls shall be appropriate to the strictest classification level of the information/data to be handled. Such countermeasures may include encryption and/or cryptographic signatures, physical restriction to assets and/or access control mechanisms.
To ensure information is adequately protected during transfer, specific controls and procedures shall be identified. Security controls shall be appropriate to the strictest classification level of the information/data to be handled. Such countermeasures may include encryption and/or cryptographic signatures, physical restriction to assets and/or access control mechanisms.
An exchange of information agreement with each external party outlining clear roles and responsibilities of each party must be established. Consider security conditions such as: Ensuring traceability and non-repudiation. Responsibilities for tracking message transmission, dispatch, and receipt. Licensing and escrow agreements. Ownership and responsibilities for data protection, copyright, license compliance, etc. Responsibilities and liabilities in the event of security incidents, such as loss or disclosure of data. Selection and audit criteria for couriers or escrow agents. Maintaining chains of custody for information being stored or transferred, including documentation and management of access control levels.
An exchange of information agreement with each external party outlining clear roles and responsibilities of each party must be established. Consider security conditions such as: Ensuring traceability and non-repudiation. Responsibilities for tracking message transmission, dispatch, and receipt. Licensing and escrow agreements. Ownership and responsibilities for data protection, copyright, license compliance, etc. Responsibilities and liabilities in the event of security incidents, such as loss or disclosure of data. Selection and audit criteria for couriers or escrow agents. Maintaining chains of custody for information being stored or transferred, including documentation and management of access control levels.
Records of media transfer shall be kept.
Records of media transfer shall be kept.
Monitor and audit the log records to ensure requirements are being met.
Monitor and audit the log records to ensure requirements are being met.
Document and maintain up-to-date all points of interconnection between information/data systems and the types of information/data to be protected regarding the identified interconnections.
Document and maintain up-to-date all points of interconnection between information/data systems and the types of information/data to be protected regarding the identified interconnections.
A security risk assessment shall be conducted to determine which message's authenticities and integrities are critical to prevent unacceptable impacts to the customer.
A security risk assessment shall be conducted to determine which message's authenticities and integrities are critical to prevent unacceptable impacts to the customer.
Monitor message tampering and source spoofing for messages for which authenticity and/or integrity need to be ensured.
Monitor message tampering and source spoofing for messages for which authenticity and/or integrity need to be ensured.
Appropriate compensating controls shall be in place to protect against security threats to weak protocols (e.g. protocols lacking encryption or authentication mechanisms).
Appropriate compensating controls shall be in place to protect against security threats to weak protocols (e.g. protocols lacking encryption or authentication mechanisms).
Any traffic between OT/IT networks shall to be officially approved after a security risk assessment on the suggested traffic, and documented with business justification, the risk it represents and the controls that will be used to reduce the risk to an acceptable level.
Any traffic between OT/IT networks shall to be officially approved after a security risk assessment on the suggested traffic, and documented with business justification, the risk it represents and the controls that will be used to reduce the risk to an acceptable level.
Serial Interfaces shall be secured based on security risk taking in consideration the following: Employ protection and detection capabilities where applicable and subject to vendor's confirmation of proven performance. Compensating/alternate security controls shall be employed where mitigation measures cannot be applied due to technical or operational infeasibility.
Serial Interfaces shall be secured based on security risk taking in consideration the following: Employ protection and detection capabilities where applicable and subject to vendor's confirmation of proven performance. Compensating/alternate security controls shall be employed where mitigation measures cannot be applied due to technical or operational infeasibility.
Ensure security requirements and service outages are captured in service level agreements for network services. Include auditable security requirements.
Ensure security requirements and service outages are captured in service level agreements for network services. Include auditable security requirements.
Audit network services provider as defined in the service agreement.
Audit network services provider as defined in the service agreement.
All systems and equipment shall be maintained to assure that security has not been degraded below the accepted level. Preventive maintenance shall be performed at least once a year.
All systems and equipment shall be maintained to assure that security has not been degraded below the accepted level. Preventive maintenance shall be performed at least once a year.
Identify all products and components (e.g. physical and logical) used within the entity that are programmable/configurable (this may be acquired through, and documented within, the asset inventory).
Identify all products and components (e.g. physical and logical) used within the entity that are programmable/configurable (this may be acquired through, and documented within, the asset inventory).
Define and document mandatory products and components configuration baselines based on security best practices and the customer defined standards.
Define and document mandatory products and components configuration baselines based on security best practices and the customer defined standards.
Any deviations to the the customer defined configuration baseline (e.g. application/system incompatibility, lack of vendor approval, etc.) should be recorded and appropriate compensating controls shall be implemented.
Any deviations to the the customer defined configuration baseline (e.g. application/system incompatibility, lack of vendor approval, etc.) should be recorded and appropriate compensating controls shall be implemented.
Potential adverse impacts to the customer environment associated with the use of troubleshooting and other tools shall be evaluated through security risk assessment before approving the use of these tools.
Potential adverse impacts to the customer environment associated with the use of troubleshooting and other tools shall be evaluated through security risk assessment before approving the use of these tools.
Security health checks shall also be carried out and documented during each maintenance cycle. Include topics such as: Inventory register check for any inconsistencies. Inter-communication architecture. Open ports and services. System hardening. Protection from malicious code. Up-to-date security patches. Equipment backup. Performance and capacity monitoring. Renewal of subscription licenses.
Security health checks shall also be carried out and documented during each maintenance cycle. Include topics such as: Inventory register check for any inconsistencies. Inter-communication architecture. Open ports and services. System hardening. Protection from malicious code. Up-to-date security patches. Equipment backup. Performance and capacity monitoring. Renewal of subscription licenses.
If during security health checks changes to approved baselines are discovered a report shall be generated and reviewed.
If during security health checks changes to approved baselines are discovered a report shall be generated and reviewed.
Records shall be maintained, for a period of five years or as legal, regulatory or operationally required, of all suspected and actual faults, and all preventive and corrective maintenance activities.
Records shall be maintained, for a period of five years or as legal, regulatory or operationally required, of all suspected and actual faults, and all preventive and corrective maintenance activities.
All test and development environments shall be required to meet specifically defined security requirements designed to support the integrity of these environments and prevent introduction of threats to the production environment.
All test and development environments shall be required to meet specifically defined security requirements designed to support the integrity of these environments and prevent introduction of threats to the production environment.
Obsolete systems shall not be used and plans to replace/refresh must be established to reach an acceptable risk level and support.
Obsolete systems shall not be used and plans to replace/refresh must be established to reach an acceptable risk level and support.
Upgrade plan for OS obsolescence, HW/SW obsolescence etc. for all systems, assets and components shall be based on the criteria that it is obsolete and/or resulting high maintenance costs and no system vendor support is available.
Upgrade plan for OS obsolescence, HW/SW obsolescence etc. for all systems, assets and components shall be based on the criteria that it is obsolete and/or resulting high maintenance costs and no system vendor support is available.
Where technically feasible, employ anti-malicious code protection mechanisms for the network devices as well as servers, workstations, laptops and other devices connected to the the customer environment.
Where technically feasible, employ anti-malicious code protection mechanisms for the network devices as well as servers, workstations, laptops and other devices connected to the the customer environment.
Anti-malicious code protection (including supported anti-malware products, configuration settings, etc.) for IT\OT assets shall be endorsed by the vendor.
Anti-malicious code protection (including supported anti-malware products, configuration settings, etc.) for IT\OT assets shall be endorsed by the vendor.
Any deviations to the entity-defined anti-malicious code requirements (e.g. application/system incompatibility, lack of vendor approval, etc.) shall be recorded. Risks due to deviations shall be managed to entity acceptable levels through compensating controls.
Any deviations to the entity-defined anti-malicious code requirements (e.g. application/system incompatibility, lack of vendor approval, etc.) shall be recorded. Risks due to deviations shall be managed to entity acceptable levels through compensating controls.
Anti-malicious code protection tools shall be monitored for detection events and alerts.
Anti-malicious code protection tools shall be monitored for detection events and alerts.
Anti-malicious code shall be deployed with defined scanning, update, and monitoring requirements across OT/IT assets.
Anti-malicious code shall be deployed with defined scanning, update, and monitoring requirements across OT/IT assets.
All new system/asset shall not be considered in production until a vulnerability assessment has been conducted and vulnerabilities addressed.
All new system/asset shall not be considered in production until a vulnerability assessment has been conducted and vulnerabilities addressed.
In the absence of an approved entity-specific retention schedule, data backup shall be retained as per defined logging standard, after which tapes or another storage backup media may be overwritten.
In the absence of an approved entity-specific retention schedule, data backup shall be retained as per defined logging standard, after which tapes or another storage backup media may be overwritten.
Periodically verification if the customer sensitive information is exposed to the general public and/or exposed to internal network shall be conducted.
Periodically verification if the customer sensitive information is exposed to the general public and/or exposed to internal network shall be conducted.
Information regarding potential security issues shall be collected, analysed and reported in a timely manner.
Information regarding potential security issues shall be collected, analysed and reported in a timely manner.
Time distribution/clock synchronization shall be implemented in all environments from a secure and accurate source that uses an accepted secure standard protocol (e.g. IEEE 1588-2008/IEC 61588:2009).
Time distribution/clock synchronization shall be implemented in all environments from a secure and accurate source that uses an accepted secure standard protocol (e.g. IEEE 1588-2008/IEC 61588:2009).
Requirements for monitoring shall be identified: Types of systems and assets. Outline which aspects must be monitored. How monitoring is to be performed. Account for instances where automated monitoring is not technically feasible. Logs and realtime traffic shall be monitored and analysed.
Requirements for monitoring shall be identified: Types of systems and assets. Outline which aspects must be monitored. How monitoring is to be performed. Account for instances where automated monitoring is not technically feasible. Logs and realtime traffic shall be monitored and analysed.
A Security Incident and Event Management (SIEM) solution, or equivalent, shall be implemented.
A Security Incident and Event Management (SIEM) solution, or equivalent, shall be implemented.
Does the CSP agreement include security requirements that address the following security controls? 1. Data ownership 2. Data protection and storage 3. Information security incidents handling 4. Change, Recovery and Restoration 5. Data handling and storing location 6. Portability and continuity 7. Compliance and monitoring rights and methods
Does the CSP agreement include security requirements that address the following security controls? 1. Data ownership 2. Data protection and storage 3. Information security incidents handling 4. Change, Recovery and Restoration 5. Data handling and storing location 6. Portability and continuity 7. Compliance and monitoring rights and methods
Supporting Utilities: Short-term UPS to facilitate an orderly shutdown of critical in the event of primary power source loss. Long-term alternate power supply capable of maintaining minimum operational capability in case of long term power loss. Primary and alternate telecommunications equipment to support reliable operations.
Supporting Utilities: Short-term UPS to facilitate an orderly shutdown of critical in the event of primary power source loss. Long-term alternate power supply capable of maintaining minimum operational capability in case of long term power loss. Primary and alternate telecommunications equipment to support reliable operations.
Cabling Security: Power, system and communication cables shall be secured. Based on information security risk, communication cables might need to be monitored against network tap attempts and network tampering, specifically when protective technical controls are not technically feasible.
Cabling Security: Power, system and communication cables shall be secured. Based on information security risk, communication cables might need to be monitored against network tap attempts and network tampering, specifically when protective technical controls are not technically feasible.
Third party compliance to the customer security policies and procedures shall be ensured and addressed by formal contract and signed Non-Disclosure Agreement (NDA) between the customer and the third party
Third party compliance to the customer security policies and procedures shall be ensured and addressed by formal contract and signed Non-Disclosure Agreement (NDA) between the customer and the third party
Service Level Agreements shall be documented and agreed upon by all parties to ensure there is no possibility for misunderstanding between the customer and the third party regarding each party's obligations to fulfil relevant information security requirements set forth by the customer security policies and procedures.
Service Level Agreements shall be documented and agreed upon by all parties to ensure there is no possibility for misunderstanding between the customer and the third party regarding each party's obligations to fulfil relevant information security requirements set forth by the customer security policies and procedures.
External Parties shall be responsible for ensuring its personnel uphold and upkeep the customer Security Policies. All software/hardware used by the External Parties personnel inside/outside the customer premises for accessing the customer information shall be declared and may be subjected to an audit. The External Parties shall co-operate with the customer and its entities in ensuring the same.
External Parties shall be responsible for ensuring its personnel uphold and upkeep the customer Security Policies. All software/hardware used by the External Parties personnel inside/outside the customer premises for accessing the customer information shall be declared and may be subjected to an audit. The External Parties shall co-operate with the customer and its entities in ensuring the same.
Any exceptions to the entity defined Supplier Service Delivery requirements shall be recorded. Risks due to exceptions shall be managed to acceptable levels through application of compensating controls.
Any exceptions to the entity defined Supplier Service Delivery requirements shall be recorded. Risks due to exceptions shall be managed to acceptable levels through application of compensating controls.
Service agreements shall include a methodology for communicating change management issues between the customer and the external/third party.
Service agreements shall include a methodology for communicating change management issues between the customer and the external/third party.
the customer shall conduct audits of external/third parties in conjunction with review of independent auditor's reports, if available, and follow-up on issues identified.
the customer shall conduct audits of external/third parties in conjunction with review of independent auditor's reports, if available, and follow-up on issues identified.
Entities shall maintain appropriate reports and records, to monitor and measure the compliance with the security requirements as documented in the agreements with the third-parties.
Entities shall maintain appropriate reports and records, to monitor and measure the compliance with the security requirements as documented in the agreements with the third-parties.
Changes to the provision of services provided by third parties shall be managed through risk assessment taking into consideration the criticality of business process, systems and security requirements. The following aspects should be taken into considerations: Changes to third-party agreements; Changes to the third parity organisational structure; Sub-contracting; Modifications or updates of the third party's policies and procedures; Changes to the third-party risk profile.
Changes to the provision of services provided by third parties shall be managed through risk assessment taking into consideration the criticality of business process, systems and security requirements. The following aspects should be taken into considerations: Changes to third-party agreements; Changes to the third parity organisational structure; Sub-contracting; Modifications or updates of the third party's policies and procedures; Changes to the third-party risk profile.
Disaster Recovery plans and procedures shall be in place to prevent and recover from any major breakdown or disaster.
Disaster Recovery plans and procedures shall be in place to prevent and recover from any major breakdown or disaster.
Disaster recovery plans and procedures shall take into account information security requirements applicable to adverse situations.
Disaster recovery plans and procedures shall take into account information security requirements applicable to adverse situations.
Disaster recovery plan shall include a full recovery and reconstitution of the customer assets.
Disaster recovery plan shall include a full recovery and reconstitution of the customer assets.
Recovery procedures shall be reviewed on a yearly basis.
Recovery procedures shall be reviewed on a yearly basis.
Disaster recovery plan and procedures shall be communicated to all stakeholders internal and external to the organisation (employees, third parties).
Disaster recovery plan and procedures shall be communicated to all stakeholders internal and external to the organisation (employees, third parties).
Contingency roles, responsibilities shall be documented with contact information, and activities associated with restoring the system after a disruption or failure, in the disaster recovery plans.
Contingency roles, responsibilities shall be documented with contact information, and activities associated with restoring the system after a disruption or failure, in the disaster recovery plans.
Continuity plans shall be tested periodically, and the lessons learned documented.
Continuity plans shall be tested periodically, and the lessons learned documented.
When changes occur, disaster recovery plans shall be reviewed and updated, such as: Acquisition of new equipment or upgrading of systems, assets or components; Personnel; Addresses or telephone numbers; Business strategy; Location, facilities and resources; Legislation; Contractors, suppliers and key customers; Processes, or new or withdrawn ones; Risk (HSE, operational and financial, etc.).
When changes occur, disaster recovery plans shall be reviewed and updated, such as: Acquisition of new equipment or upgrading of systems, assets or components; Personnel; Addresses or telephone numbers; Business strategy; Location, facilities and resources; Legislation; Contractors, suppliers and key customers; Processes, or new or withdrawn ones; Risk (HSE, operational and financial, etc.).
Following corrective action shall be taken when non-compliance is identified: Identify the immediate and underlying causes of the non-compliance. Assess and document the risks introduced by non-compliance. Evaluate actions to be taken to attain compliance. Implement the proper corrective action.
Following corrective action shall be taken when non-compliance is identified: Identify the immediate and underlying causes of the non-compliance. Assess and document the risks introduced by non-compliance. Evaluate actions to be taken to attain compliance. Implement the proper corrective action.
Review whether the corrective action taken is effective shall be conducted: Document results generated from reviews and corrective actions. Observe those results over time in order to identify trends and implement further corrective action.
Review whether the corrective action taken is effective shall be conducted: Document results generated from reviews and corrective actions. Observe those results over time in order to identify trends and implement further corrective action.
Security assessments shall be conducted only by resources identified by the relevant the customer department/role and shall be carefully planned and agreed upon when performed against operational environment.
Security assessments shall be conducted only by resources identified by the relevant the customer department/role and shall be carefully planned and agreed upon when performed against operational environment.
Measures taken to ensure assessment activities minimise the risk of disruptions to the environment and business processes shall be documented and communicated. In particular, assessment activities shall not include network scanning or penetration testing on OT systems, as it may degrade the performance and impact the plant operations.
Measures taken to ensure assessment activities minimise the risk of disruptions to the environment and business processes shall be documented and communicated. In particular, assessment activities shall not include network scanning or penetration testing on OT systems, as it may degrade the performance and impact the plant operations.
Sensitive information shall be verified or assessed in-site and shall not be handed out or distributed.
Sensitive information shall be verified or assessed in-site and shall not be handed out or distributed.
An action plan that describes how the identified non-conformities will be addressed shall be developed and maintained on regular basis.
An action plan that describes how the identified non-conformities will be addressed shall be developed and maintained on regular basis.
the customer shall plan and conduct assessments of the information security controls in place through an established assurance process which will be continuously identifying technical and non-technical gaps.
the customer shall plan and conduct assessments of the information security controls in place through an established assurance process which will be continuously identifying technical and non-technical gaps.
Performance improvement plans shall consider and develop strategies to identify the suitability, adequacy and effectiveness of information security controls in place.
Performance improvement plans shall consider and develop strategies to identify the suitability, adequacy and effectiveness of information security controls in place.
Performance improvement plan shall leverage and document security metrics and measurements from incident reports, and audits for future improvement.
Performance improvement plan shall leverage and document security metrics and measurements from incident reports, and audits for future improvement.
The implementation of performance improvement plan shall be monitored on a regular basis: Document and maintain corrective and/or continuous improvement actions taken. Review and report the effectiveness of corrective and/or continuous improvement actions.
The implementation of performance improvement plan shall be monitored on a regular basis: Document and maintain corrective and/or continuous improvement actions taken. Review and report the effectiveness of corrective and/or continuous improvement actions.
Service shall have acceptable clause regarding data ownership and intellectual property rights as per UAE regulations and the customer policies
Service shall have acceptable clause regarding data ownership and intellectual property rights as per UAE regulations and the customer policies
Contract / statement of work / order form clearly details the services to be provided.
Contract / statement of work / order form clearly details the services to be provided.
Contract includes service levels or a separate SLA has been signed (with uptime and support response at the minimum) and consequences if service levels are not met (e.g. rebates; liquidated damages).
Contract includes service levels or a separate SLA has been signed (with uptime and support response at the minimum) and consequences if service levels are not met (e.g. rebates; liquidated damages).
Service provider shall have clear and secure controls associated with approving access to the customer data or systems by service provider staff for support and/or troubleshooting purposes.
Service provider shall have clear and secure controls associated with approving access to the customer data or systems by service provider staff for support and/or troubleshooting purposes.
Service provider should have cyber insurance covering security breaches.
Service provider should have cyber insurance covering security breaches.
Detailed access and audit logs shall be available for the customer to obtain via an API or other means, which should align with the customer security monitoring requirements
Detailed access and audit logs shall be available for the customer to obtain via an API or other means, which should align with the customer security monitoring requirements
Service Provider shall have solid DR and Business continuity plan in line with the customer requirements
Service Provider shall have solid DR and Business continuity plan in line with the customer requirements
Service Provider shall have solid endpoint security controls such as AV, EDR, exploitation protection, HIPS, App whitelisting IDS, DDOS, malware sandboxing, etc.
Service Provider shall have solid endpoint security controls such as AV, EDR, exploitation protection, HIPS, App whitelisting IDS, DDOS, malware sandboxing, etc.
Service Provider should allow the customer to preform technical and compliance audits on provider infrastructure that host the customer systems
Service Provider should allow the customer to preform technical and compliance audits on provider infrastructure that host the customer systems
Describe your security model, including network, data, and application security; data center security; application and system support; upgrades and maintenance; and personnel access rights.
Describe your security model, including network, data, and application security; data center security; application and system support; upgrades and maintenance; and personnel access rights.
How often is the platform scheduled for software patches and updates?
How often is the platform scheduled for software patches and updates?
Does the vendor allow security audits by the customer or by agents of the customer (e.g. an appointed Audit firm)?
Does the vendor allow security audits by the customer or by agents of the customer (e.g. an appointed Audit firm)?
Is there security accreditation in place such as SAS70/SSAE 16 Type II, ISO 27002 etc?
Is there security accreditation in place such as SAS70/SSAE 16 Type II, ISO 27002 etc?
What processes does the vendor have to detect and prevent viruses and other malicious software from damaging the service and the customer's data?
What processes does the vendor have to detect and prevent viruses and other malicious software from damaging the service and the customer's data?
What are the security and malpractice escalation processes?
What are the security and malpractice escalation processes?
What are the controls over interruption to the service? (SLA). What is the RPO (recovery point objective) and RTO (recovery time objective) for the service?
What are the controls over interruption to the service? (SLA). What is the RPO (recovery point objective) and RTO (recovery time objective) for the service?
What security standards are used for application development?
What security standards are used for application development?
Describe the network topology.
Describe the network topology.
Describe your approach to ensuring data security in the SaaS environment.
Describe your approach to ensuring data security in the SaaS environment.
TSL IT Security Compliance?
TSL IT Security Compliance?
Data Governance & Management features?
Data Governance & Management features?
Intelligence to predict failures and auto-corrections? Failures can be Infrastructure / Process transaction with validations as per TSL business rules
Intelligence to predict failures and auto-corrections? Failures can be Infrastructure / Process transaction with validations as per TSL business rules
What is the percentage that the SLA guarantees (in case the platform provides the services in a Saas Model)?
What is the percentage that the SLA guarantees (in case the platform provides the services in a Saas Model)?
Can evidence be provided of the processes that are implemented to guarantee the confidentiality of information, including a description of how our data is separated from other customer's data, and what controls are in place to prevent other customers from viewing our data?
Can evidence be provided of the processes that are implemented to guarantee the confidentiality of information, including a description of how our data is separated from other customer's data, and what controls are in place to prevent other customers from viewing our data?
Are there controls in place to prevent administrators and other staff from the Vendor's organisation from downloading customer data to removable storage (USB memory sticks, CD ROM etc)?
Are there controls in place to prevent administrators and other staff from the Vendor's organisation from downloading customer data to removable storage (USB memory sticks, CD ROM etc)?
Which databases are used in the backend? Which database optimization approaches are taken?
Which databases are used in the backend? Which database optimization approaches are taken?
Describe the hosting infrastructure.
Describe the hosting infrastructure.
How is system usage and performance monitored?
How is system usage and performance monitored?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
Is your DR plan based on active-active or active-passive?
Is your DR plan based on active-active or active-passive?
Does the application or solution have Access Control Mechanism to ensure restricted/controlled access to PII (as per business requirement)?
Does the application or solution have Access Control Mechanism to ensure restricted/controlled access to PII (as per business requirement)?
Are logs being maintained for processing activities performed on PII?
Are logs being maintained for processing activities performed on PII?
Is there an Access Control Mechanism to ensure restricted/controlled Third Party access to the application?
Is there an Access Control Mechanism to ensure restricted/controlled Third Party access to the application?
Does the application allow PII to be updated in case there is a requirement for the same?
Does the application allow PII to be updated in case there is a requirement for the same?
What is the services you are going to provide to Darwinbox
What is the services you are going to provide to Darwinbox
Has your organization formally appointed a central point of contact for security coordination? If so, whom, and what is their position within the organization? Are responsibilities clearly documented? i.e. job descriptions, information security policy
Has your organization formally appointed a central point of contact for security coordination? If so, whom, and what is their position within the organization? Are responsibilities clearly documented? i.e. job descriptions, information security policy
Have your employees been provided formal information security training? Have policies been communicated to your employees? Are periodic security reminders provided? i.e. New employee orientation, annual training, posters in public areas, email reminders, etc.
Have your employees been provided formal information security training? Have policies been communicated to your employees? Are periodic security reminders provided? i.e. New employee orientation, annual training, posters in public areas, email reminders, etc.
Are your employees required to sign a non-disclosure agreement? If so, are employees required to sign the non-disclosure agreement annually? Non-disclosure and/or confidentiality form at initial employment
Are your employees required to sign a non-disclosure agreement? If so, are employees required to sign the non-disclosure agreement annually? Non-disclosure and/or confidentiality form at initial employment
Do you have a formal process to manage the termination and or transfer of employees? i.e. All equipment is returned, user ID's disabled in systems, Windows, badges and/or keys returned. On Transfer is existing access reviewed for relevance?
Do you have a formal process to manage the termination and or transfer of employees? i.e. All equipment is returned, user ID's disabled in systems, Windows, badges and/or keys returned. On Transfer is existing access reviewed for relevance?
Has antivirus software been deployed and installed on your computers and supporting systems (e.g., desktops, servers and gateways)? 1) Product installed? Centrally managed? Updated daily? Reviewed for being current?
Has antivirus software been deployed and installed on your computers and supporting systems (e.g., desktops, servers and gateways)? 1) Product installed? Centrally managed? Updated daily? Reviewed for being current?
Whom do we contact if we identify a security issue or breach involving or impacting your product? Please provide an email address and/or full contact information b) What is their expected SLA to respond to initial contact? c) What is the definition of issue priority (ex: minor vs. major, 0-4 scale)? d) What is their expected SLA to implement changes needed to fix issues according to priority?
Whom do we contact if we identify a security issue or breach involving or impacting your product? Please provide an email address and/or full contact information b) What is their expected SLA to respond to initial contact? c) What is the definition of issue priority (ex: minor vs. major, 0-4 scale)? d) What is their expected SLA to implement changes needed to fix issues according to priority?
- Reach out to us at cs@xoxoday.com to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same.
Which all in-house or third party applications Vendor will use for the customer operations?
Which all in-house or third party applications Vendor will use for the customer operations?
Does the application support any APIs? And how are they consumed internally and externally? What controls are implemented for sharing such APIs externally?
Does the application support any APIs? And how are they consumed internally and externally? What controls are implemented for sharing such APIs externally?
How the security of the exposed APIs is managed?
How the security of the exposed APIs is managed?
Are your admins are cloud certified?
Are your admins are cloud certified?
Do you have a setup of processes for regular internal audit for data protection compliance?
Do you have a setup of processes for regular internal audit for data protection compliance?
A copy of the third-party information security program validation performed on the product/ environment, such as: SOC 2 Type II report and/or ISO 27001 certificate.
A copy of the third-party information security program validation performed on the product/ environment, such as: SOC 2 Type II report and/or ISO 27001 certificate.
A copy of audit reports from the data center where the production instance of your product is hosted (SOC1, SOC2, bridge Letters, ISO27001, other security certifications, etc.).
A copy of audit reports from the data center where the production instance of your product is hosted (SOC1, SOC2, bridge Letters, ISO27001, other security certifications, etc.).
Do you follow any particular internationally accepted best practices or standards?
Do you follow any particular internationally accepted best practices or standards?
Does the system have an international certification/award in System Security?
Does the system have an international certification/award in System Security?
Can a user login be prevented during non-office hours (e.g., off-shift, on leaves)?
Can a user login be prevented during non-office hours (e.g., off-shift, on leaves)?
Does solution provide/support remote procedure calls?
Does solution provide/support remote procedure calls?
Does solution provide/support message-oriented middleware?
Does solution provide/support message-oriented middleware?
Does solution use SSL (If use web service)?
Does solution use SSL (If use web service)?
Does solution support SFTP (both sending and receiving file)?
Does solution support SFTP (both sending and receiving file)?
Does solution support Data encryption/decryption?
Does solution support Data encryption/decryption?
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
Does your solution provide the CheckSum as data validation module?
Does your solution provide the CheckSum as data validation module?
CLIENT must have the ability to govern the data stored in cloud.
CLIENT must have the ability to govern the data stored in cloud.
CLOUD SERVICE PROVIDER (CSP) must have security policy, standard and procedure/guideline, which at least on the same level as CLIENT ISMS and must be uphold to protect CLIENT data from any security threats.
CLOUD SERVICE PROVIDER (CSP) must have security policy, standard and procedure/guideline, which at least on the same level as CLIENT ISMS and must be uphold to protect CLIENT data from any security threats.
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently? Are results communicated to clients? How often?
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently? Are results communicated to clients? How often?
What arrangements are in place for return of data to customer upon contract conclusion or termination?
What arrangements are in place for return of data to customer upon contract conclusion or termination?
Can the service provider provide the latest copy of SOC 2 Type II report or equivalent?
Can the service provider provide the latest copy of SOC 2 Type II report or equivalent?
Provide information on your solutions/services BCP/DR.
Provide information on your solutions/services BCP/DR.
Please provide a copy of the incident management standard and procedures?
Please provide a copy of the incident management standard and procedures?
Has an independent security third party audit been completed on you? (If so, please name the auditing firm and last audit date in the comment box)
Has an independent security third party audit been completed on you? (If so, please name the auditing firm and last audit date in the comment box)
Do you take special measures to make sure the customer data is secure during the collection process? If so, describe the measures briefly.
Do you take special measures to make sure the customer data is secure during the collection process? If so, describe the measures briefly.
Have we implemented Email Gateway solution to block the SPAM emails? Have we implemented SPF/ DKIM/ DMARC effectively?
Have we implemented Email Gateway solution to block the SPAM emails? Have we implemented SPF/ DKIM/ DMARC effectively?
What is the password standard for the applications users, administrators, network users, etc. please describe in details. How are initial passwords communicated to users? Are all new users issued random initial passwords? Are users forced to change their password upon first logon? How is user's identity verified prior to resetting a password? What is the minimum password length? After how many days does a password expire? How many passwords are stored in the password history? What is the number of invalid password attempts prior to lockout? Can PINs or secret questions be used as a stand-alone method of authentication?
What is the password standard for the applications users, administrators, network users, etc. please describe in details. How are initial passwords communicated to users? Are all new users issued random initial passwords? Are users forced to change their password upon first logon? How is user's identity verified prior to resetting a password? What is the minimum password length? After how many days does a password expire? How many passwords are stored in the password history? What is the number of invalid password attempts prior to lockout? Can PINs or secret questions be used as a stand-alone method of authentication?
CSP ISO/IEC 27001/27002:2013 independent attestation, CSP ISO/IEC 27018:2014 independent attestation, CSP SOC 2 Type 2 independent attestation
CSP ISO/IEC 27001/27002:2013 independent attestation, CSP ISO/IEC 27018:2014 independent attestation, CSP SOC 2 Type 2 independent attestation
Will you notify FINCARE in case of any request to provide information, in the form of a subpoena, a warrant, or court order in which access to the FINCARE data is requested?
Will you notify FINCARE in case of any request to provide information, in the form of a subpoena, a warrant, or court order in which access to the FINCARE data is requested?
Do you include right to audit by consumer to your environment?
Do you include right to audit by consumer to your environment?
Will you make necessary audit logs and activity monitoring available when requested?
Will you make necessary audit logs and activity monitoring available when requested?
Do you encrypt sensitive data in PaaS applications and storage and sensitive volumes in IaaS
Do you encrypt sensitive data in PaaS applications and storage and sensitive volumes in IaaS
Do you have controls in place to prevent data leakage or intentional/accidental compromise between tenants in a multitenant environment?
Do you have controls in place to prevent data leakage or intentional/accidental compromise between tenants in a multitenant environment?
Does your data management policies and procedures address tenant and service level conflicts of interests?
Does your data management policies and procedures address tenant and service level conflicts of interests?
Can you demonstrate the data sovereignty and residency issues and provide details of jurisdiction of data storage and the local laws applicable?
Can you demonstrate the data sovereignty and residency issues and provide details of jurisdiction of data storage and the local laws applicable?
Are these datacenters are owned by you? If not, provide the details of the datacenter service provider
Are these datacenters are owned by you? If not, provide the details of the datacenter service provider
Datacenter security standard and procedure
Datacenter security standard and procedure
Third party assessment reports and attestations - ISO 27001, PCI DSS, etc
Third party assessment reports and attestations - ISO 27001, PCI DSS, etc
Any change to the design that impacts security posture of the system must be reviewed and approved by EIS Architecture Team, before a new component (e.g., custom built modules, 3rd party components, vendor supplied components) is released.
Any change to the design that impacts security posture of the system must be reviewed and approved by EIS Architecture Team, before a new component (e.g., custom built modules, 3rd party components, vendor supplied components) is released.
Minimum security standards and latest vendor security updates must be applied to all components. Wherever it is not supported or cannnot be applied, compensating controls must be evaluated with ISRA and implemented to reduce the risk.
Minimum security standards and latest vendor security updates must be applied to all components. Wherever it is not supported or cannnot be applied, compensating controls must be evaluated with ISRA and implemented to reduce the risk.
Project teams must maintain: Accurate (Create/Update/Delete) inventories of project components that are required for application to be up & running (including Production & Non-Production).
Project teams must maintain: Accurate (Create/Update/Delete) inventories of project components that are required for application to be up & running (including Production & Non-Production).
Implement version control practices (for Source code, binaries, container images) to govern development and provide auditing. Ensure versions are stored in a centralized repository, the change can be reversed/ rolled back during a security incident.
Implement version control practices (for Source code, binaries, container images) to govern development and provide auditing. Ensure versions are stored in a centralized repository, the change can be reversed/ rolled back during a security incident.
Applications should be architected with a minimum of three separate tiers: web, application, and storage/database.
Applications should be architected with a minimum of three separate tiers: web, application, and storage/database.
All remote system administrative functionality and remote access to an operating system (e.g., RDP, SSH, etc.) must be disabled and not directly accessible from the Internet, and only PSJH Information Security-approved remote access technologies are allowed.
All remote system administrative functionality and remote access to an operating system (e.g., RDP, SSH, etc.) must be disabled and not directly accessible from the Internet, and only PSJH Information Security-approved remote access technologies are allowed.
All public IP addresses must be removed from the subscription, except those that were coordinated with and approved by PSJH Cloud Engineering and Information Security Architecture.
All public IP addresses must be removed from the subscription, except those that were coordinated with and approved by PSJH Cloud Engineering and Information Security Architecture.
Access to the PaaS must be provisioned using PSJH IAM team, privileged access should be determined by business justification, and granted by IAM.
Access to the PaaS must be provisioned using PSJH IAM team, privileged access should be determined by business justification, and granted by IAM.
Ensure that all encryption and hashing methods comply with policies and organizational requirements for protection of information.
Ensure that all encryption and hashing methods comply with policies and organizational requirements for protection of information.
If Cryptographic keys have to be tranferred manually, then encrypted channels to be used Eg., use Secure Email of O365, ProofPoint Secure Email.
If Cryptographic keys have to be tranferred manually, then encrypted channels to be used Eg., use Secure Email of O365, ProofPoint Secure Email.
Ensure that the integrity of cryptographic key is protected while they are stored. Eg., use Hashing SHA256, Digital Signatures
Ensure that the integrity of cryptographic key is protected while they are stored. Eg., use Hashing SHA256, Digital Signatures
PHI, PII, and regulated or confidential data must use a minimum protocol of TLS 1.2, and an encryption algorithm and strength of AES-256 while in transit.
PHI, PII, and regulated or confidential data must use a minimum protocol of TLS 1.2, and an encryption algorithm and strength of AES-256 while in transit.
Application that handles PHI, PCI, PII (and other regulated data) must comply with applicable federal laws, Executive Orders, directives, policies, regulations.
Application that handles PHI, PCI, PII (and other regulated data) must comply with applicable federal laws, Executive Orders, directives, policies, regulations.
File-integrity monitoring tools should be in place to monitor modifications to critical system files, configuration files, and content files (leverage Crowdstrike as applicable).
File-integrity monitoring tools should be in place to monitor modifications to critical system files, configuration files, and content files (leverage Crowdstrike as applicable).
Application must ensure that the information used for authentication must be securely stored and transmitted in an encrypted form using algorithms in accordance to the Providence's information security policy.
Application must ensure that the information used for authentication must be securely stored and transmitted in an encrypted form using algorithms in accordance to the Providence's information security policy.
The application must be partitioned into public and restricted areas using separate folders for authenticated and non-authenticated users.
The application must be partitioned into public and restricted areas using separate folders for authenticated and non-authenticated users.
Mobile applications that are homegrown/ procured shall be released to caregivers via MDM & MAM solutions (such as Microsoft InTune).
Mobile applications that are homegrown/ procured shall be released to caregivers via MDM & MAM solutions (such as Microsoft InTune).
The mobile application must time out after 15 or fewer minutes of inactivity, requiring a user to re-enter a password, PIN, or re-initiate a biometric authentication mechanism before application content can be viewed again.
The mobile application must time out after 15 or fewer minutes of inactivity, requiring a user to re-enter a password, PIN, or re-initiate a biometric authentication mechanism before application content can be viewed again.
Code obfuscation is applied to native apps
Code obfuscation is applied to native apps
Roles must be assigned to manage updates on the server, resources, and/or other supporting assets.
Roles must be assigned to manage updates on the server, resources, and/or other supporting assets.
PSJH-managed EDR (running real-time scanning on a continuous basis) on the solution's servers, workstations, and/or other applicable devices is required.
PSJH-managed EDR (running real-time scanning on a continuous basis) on the solution's servers, workstations, and/or other applicable devices is required.
PSJH-managed host-based firewall client is required on the solution's servers, workstations, and/or other applicable devices.
PSJH-managed host-based firewall client is required on the solution's servers, workstations, and/or other applicable devices.
Ensure the user session is invalidated on the server-side when the user logs out.
Ensure the user session is invalidated on the server-side when the user logs out.
Implement REST and web services using session based authentication.
Implement REST and web services using session based authentication.
Require a standardized approach to structured exception and error handling across all layers.
Require a standardized approach to structured exception and error handling across all layers.
All input validation failures must result in input rejection and must be logged.
All input validation failures must result in input rejection and must be logged.
Product Owners must integrate compliance of security requirements in corresponding criteria in Definition of Done (DoD). Any requirement & recommendations provided by EIS that are not met by the application will need to have a security exception through ISRA
Product Owners must integrate compliance of security requirements in corresponding criteria in Definition of Done (DoD). Any requirement & recommendations provided by EIS that are not met by the application will need to have a security exception through ISRA
Implement generic error or notification messages in applications to limit information useful for attacks.
Implement generic error or notification messages in applications to limit information useful for attacks.
Manual input of file names and file paths must be avoided where possible.
Manual input of file names and file paths must be avoided where possible.
Vulnerabilities are to be identified, reported, and remediated through the software-development life cycle. Effective utilization of enterprise SAST, DAST, OSA, IaC Security, Penetration Testing etc., to be adopted throughout the lifecycle of system development (and periodically).
Vulnerabilities are to be identified, reported, and remediated through the software-development life cycle. Effective utilization of enterprise SAST, DAST, OSA, IaC Security, Penetration Testing etc., to be adopted throughout the lifecycle of system development (and periodically).
How do you handle data from Russia and China?
How do you handle data from Russia and China?
Description of your general Security concept including on how you handle Confidentiality, Integrity and Availability.
Description of your general Security concept including on how you handle Confidentiality, Integrity and Availability.
What are the security controls and restrictions implemented to control the upload, download, viewing and modification of Infosys data (including structured and unstructured data e.g. emails, databases etc.) by users within your organization, including admin users?
What are the security controls and restrictions implemented to control the upload, download, viewing and modification of Infosys data (including structured and unstructured data e.g. emails, databases etc.) by users within your organization, including admin users?
Specify the frequency of AV scans and list down the events/scenarios that triggers the scans
Specify the frequency of AV scans and list down the events/scenarios that triggers the scans
In a multi tenant model, please explain what controls are present to prevent infections spreading across to Infosys specific applications/infra from other tenants/customers sharing the same infrastructure?
In a multi tenant model, please explain what controls are present to prevent infections spreading across to Infosys specific applications/infra from other tenants/customers sharing the same infrastructure?
Have there been any information security breaches within the organization in the last 1 year (even if they did not impact Infosys)? If yes, please detail out the corrective and preventive actions taken by the organization to strengthen the information security program.
Have there been any information security breaches within the organization in the last 1 year (even if they did not impact Infosys)? If yes, please detail out the corrective and preventive actions taken by the organization to strengthen the information security program.
Provide details about the Information security framework and controls that are deployed within your organization to safeguard Infosys data and ensure compliance to applicable industry standards
Provide details about the Information security framework and controls that are deployed within your organization to safeguard Infosys data and ensure compliance to applicable industry standards
Is cyber security compliance review of application and risk assesement conducted atleast annually?
Is cyber security compliance review of application and risk assesement conducted atleast annually?
Are cyber security compliance review findings mitigated? Please highlight any open points.
Are cyber security compliance review findings mitigated? Please highlight any open points.
Are detected vulnerabilities patched timely?
Are detected vulnerabilities patched timely?
Is anti-malware and anti-virus installed on servers and development machines?
Is anti-malware and anti-virus installed on servers and development machines?
Is anti-malware and anti-virus updated regularly?
Is anti-malware and anti-virus updated regularly?
Is the code restricted from publicly available?
Is the code restricted from publicly available?
Is the application server are hardened for security and maintained?
Is the application server are hardened for security and maintained?
Is the database server comply with identity and access control policy?
Is the database server comply with identity and access control policy?
Is the database server comply with password policy?
Is the database server comply with password policy?
Is the database server have latest operating system, licensed and supported?
Is the database server have latest operating system, licensed and supported?
Is application server configuration is backed-up and can be restored within RPO and RTO?
Is application server configuration is backed-up and can be restored within RPO and RTO?
Is incidents are logged, investigated and reported timely?
Is incidents are logged, investigated and reported timely?
Explain the limitations to how the customer can use the service as outlined in the provider's acceptable usage policies, licensing rights or other providers usage restrictions.
Explain the limitations to how the customer can use the service as outlined in the provider's acceptable usage policies, licensing rights or other providers usage restrictions.
What advance notice will be provided by the provider for any change of terms?
What advance notice will be provided by the provider for any change of terms?
Does the contract/terms of service outline meaningful liability for the provider in the event that the the customer environment/data is breached?
Does the contract/terms of service outline meaningful liability for the provider in the event that the the customer environment/data is breached?
Does the provider have an active SLA in place that identifies minimum performance (e.g., uptime, etc.)?
Does the provider have an active SLA in place that identifies minimum performance (e.g., uptime, etc.)?
Describe the SLA
Describe the SLA
Does the provider provide regular service management reports (e.g., SLA performance)? If so, state the frequency of such reporting.
Does the provider provide regular service management reports (e.g., SLA performance)? If so, state the frequency of such reporting.
Describe penalties associated with SLA non-compliance.
Describe penalties associated with SLA non-compliance.
Does the provider monitor service continuity with upstream providers in the event of provider failure?
Does the provider monitor service continuity with upstream providers in the event of provider failure?
Do we have the planed downtime scheduled (e.g., service, upgrade, patch, etc.)?
Do we have the planed downtime scheduled (e.g., service, upgrade, patch, etc.)?
Are the same security controls implemented at the failover site as that of primary site?
Are the same security controls implemented at the failover site as that of primary site?
Are the provider's routine maintenance windows manageable for the customer?
Are the provider's routine maintenance windows manageable for the customer?
Describe the process to terminate the service
Describe the process to terminate the service
Can the customer data and the service be moved/transferred to another provider at any time?
Can the customer data and the service be moved/transferred to another provider at any time?
Does the customer have the right to terminate if the provider introduces material modifications to service terms?
Does the customer have the right to terminate if the provider introduces material modifications to service terms?
What standards does the provider follow for application development? Do these include rigorous testing and acceptance protocols?
What standards does the provider follow for application development? Do these include rigorous testing and acceptance protocols?
Where and how will the customer data be stored? Are there impacts on security in light of the differences in legal/regulatory compliance requirements depending on storage location?
Where and how will the customer data be stored? Are there impacts on security in light of the differences in legal/regulatory compliance requirements depending on storage location?
Does the provider have a cyber plan in place? If so, please provide details.
Does the provider have a cyber plan in place? If so, please provide details.
Have there been any major security incident(s) reported with the provider in the last two years? If so, detail the incident(s) and resolution(s)
Have there been any major security incident(s) reported with the provider in the last two years? If so, detail the incident(s) and resolution(s)
What activities are logged by the provider? Consider: Network traffic, file and server access, Security systems
What activities are logged by the provider? Consider: Network traffic, file and server access, Security systems
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants? (2)
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants? (2)
Who can set up activities to be logged?
Who can set up activities to be logged?
What is the provider's incident response procedure for handling a security or data breach?
What is the provider's incident response procedure for handling a security or data breach?
Does the provider's incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
Does the provider's incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
When are audits conducted (i.e., frequency)? What standard/certification is used to conduct audits (e.g., ISO 27001, SSAE 16 SOC 2, etc.)? Will the customer receive a copy of the audit report when finalized? Is this requirement outlined in the contract with the service provider?
When are audits conducted (i.e., frequency)? What standard/certification is used to conduct audits (e.g., ISO 27001, SSAE 16 SOC 2, etc.)? Will the customer receive a copy of the audit report when finalized? Is this requirement outlined in the contract with the service provider?
Are mechanisms for label inheritance implemented for objects that act as aggregate containers for data?
Are mechanisms for label inheritance implemented for objects that act as aggregate containers for data?
Do you adhere to the tenant's retention policy?
Do you adhere to the tenant's retention policy?
Can you provide a published procedure for security mechanisms to prevent data leakage in transit and data at rest leakage upon request?
Can you provide a published procedure for security mechanisms to prevent data leakage in transit and data at rest leakage upon request?
Can you provide tenants, upon request, documentation on how you maintain segregation of duties within your cloud service offering?
Can you provide tenants, upon request, documentation on how you maintain segregation of duties within your cloud service offering?
Do you use industry standards (Build Security in Maturity Model [BSIMM] benchmarks, Open Group ACS Trusted Technology Provider Framework, NIST, etc.) to build in security for your Systems/Software Development Lifecycle (SDLC)?
Do you use industry standards (Build Security in Maturity Model [BSIMM] benchmarks, Open Group ACS Trusted Technology Provider Framework, NIST, etc.) to build in security for your Systems/Software Development Lifecycle (SDLC)?
- security requirements
- independent security review of the environment by a certified individual
- code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
Do you use automated and manual source code analysis tools to detect security defects in code prior to production?
Do you use automated and manual source code analysis tools to detect security defects in code prior to production?
Do you review your applications for security vulnerabilities and address any issues prior to deployment to production?
Do you review your applications for security vulnerabilities and address any issues prior to deployment to production?
Do you verify that all of your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
Do you verify that all of your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
Do you provide tenants with documentation that describes your production change management procedures and their roles/rights/responsibilities within it?
Do you provide tenants with documentation that describes your production change management procedures and their roles/rights/responsibilities within it?
Are any of your data centers located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Are any of your data centers located in places that have a high probability/occurrence of high-impact environmental risks (floods, tornadoes, earthquakes, hurricanes, etc.)?
Do you provide tenants with geographically resilient hosting options?
Do you provide tenants with geographically resilient hosting options?
Do you provide tenants with infrastructure service failover capability to other providers?
Do you provide tenants with infrastructure service failover capability to other providers?
Are business continuity and disaster recovery plans subject to test at least annually and upon significant organizational or environmental changes to ensure continuing effectiveness?
Are business continuity and disaster recovery plans subject to test at least annually and upon significant organizational or environmental changes to ensure continuing effectiveness?
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports?
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports?
Do you conduct annual network penetration tests of your cloud service infrastructure regularly as prescribed by industry best practices and guidance?
Do you conduct annual network penetration tests of your cloud service infrastructure regularly as prescribed by industry best practices and guidance?
Do you perform annual audits (internal and external) and are the results available to tenants upon request?
Do you perform annual audits (internal and external) and are the results available to tenants upon request?
Are the results of the penetration tests available to tenants at their request?
Are the results of the penetration tests available to tenants at their request?
Are you storing, transmitting, and/or processing payment card data on behalf of our organization?
Are you storing, transmitting, and/or processing payment card data on behalf of our organization?
Can you prove that you are compliant for: Indian IT Act 2000?
Can you prove that you are compliant for: Indian IT Act 2000?
Is there a formal process that details the transition of data from unsupported systems and applications to supported systems and applications?
Is there a formal process that details the transition of data from unsupported systems and applications to supported systems and applications?
What will you deliver back to us on the end of service?
What will you deliver back to us on the end of service?
Do you conduct information audits to determine what personal data is being stored/processed and where is it being stored?
Do you conduct information audits to determine what personal data is being stored/processed and where is it being stored?
Do you have a dedicated information/cyber security team responsible for information security governance across the organization?
Do you have a dedicated information/cyber security team responsible for information security governance across the organization?
Have you defined the information security roles and responsibilities?
Have you defined the information security roles and responsibilities?
Do you have an acceptable usage policy which is signed/agreed by all employees on annual basis?
Do you have an acceptable usage policy which is signed/agreed by all employees on annual basis?
Is your environment SOC-2 Type-II attested or certified for the scope of the service being offered to tenant?
Is your environment SOC-2 Type-II attested or certified for the scope of the service being offered to tenant?
Is your environment CSA-certified for the scope of the service being offered to tenant?
Is your environment CSA-certified for the scope of the service being offered to tenant?
Are all relevant legislative, statutory, regulatory and contractual security requirements identified, documented and tracked?
Are all relevant legislative, statutory, regulatory and contractual security requirements identified, documented and tracked?
Do you monitor effectiveness of cyber security controls through regular metrics?
Do you monitor effectiveness of cyber security controls through regular metrics?
Do you have an approved HR Policy document?
Do you have an approved HR Policy document?
Are your employees screened before joining the organization? Are they bound to keep security of information intact even after their employment contract has ended?
Are your employees screened before joining the organization? Are they bound to keep security of information intact even after their employment contract has ended?
Do you take services from any third party which directly or indirectly impacts services given to tenant or Client of tenant?
Do you take services from any third party which directly or indirectly impacts services given to tenant or Client of tenant?
Can you provide details of these third parties including the name of the third party and the services they will be performing on your behalf?
Can you provide details of these third parties including the name of the third party and the services they will be performing on your behalf?
Do you have a Third Party Security Policy?
Do you have a Third Party Security Policy?
Do you regularly monitor the third party's compliance with security obligations?
Do you regularly monitor the third party's compliance with security obligations?
Is there a process to address any risk that may occur due to change of services being provided to the tenant?
Is there a process to address any risk that may occur due to change of services being provided to the tenant?
Do you permit the use of contractors in roles supporting customer operations?
Do you permit the use of contractors in roles supporting customer operations?
Do you have subscription to brand protection services?
Do you have subscription to brand protection services?
Do you monitor media platforms as well for brand protection?
Do you monitor media platforms as well for brand protection?
Do you have mandatory and regular privacy training and awareness module?
Do you have mandatory and regular privacy training and awareness module?
What is CSA?
What is CSA?
Did you list your organization for CSA STAR LEVL – 1 self-assessment?
Did you list your organization for CSA STAR LEVL – 1 self-assessment?
What are the important features of CSA STAR LEVEL – 1?
What are the important features of CSA STAR LEVEL – 1?
- Operating in a low-risk environment
- Wanting to offer increased transparency around the security controls they have in place.
- Looking for a cost-effective way to improve trust and transparency.
Are the applications and programming interfaces (APIs) designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations?
Are the applications and programming interfaces (APIs) designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations?
Do you comply with the Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols)?
Do you comply with the Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols)?
Do you use Production data in a non-production environment?
Do you use Production data in a non-production environment?
Do you obtain prior to relocation or transfer of hardware, software, or data to an offsite premise?
Do you obtain prior to relocation or transfer of hardware, software, or data to an offsite premise?
Do you have a documented application validation process to test for mobile device, operating system, and application compatibility issues?
Do you have a documented application validation process to test for mobile device, operating system, and application compatibility issues?
What is the California Privacy Rights Act (CPRA)?
What is the California Privacy Rights Act (CPRA)?
Is Xoxoday compliant with California Privacy Rights Act (CPRA)?
Is Xoxoday compliant with California Privacy Rights Act (CPRA)?
Do you provide rights to the consumers with regards to the data processing as per California Privacy Rights Act (CPRA)?
Do you provide rights to the consumers with regards to the data processing as per California Privacy Rights Act (CPRA)?
Did you implement all the CPRA Privacy controls as per the compliance requirements?
Did you implement all the CPRA Privacy controls as per the compliance requirements?
Do you make the CPRA Attestation report available for the customers?
Do you make the CPRA Attestation report available for the customers?
Do you collect any data from California citizens who are not 18 years old?
Do you collect any data from California citizens who are not 18 years old?
How can we submit our request to exercise our Rights Under the CCPA/CPRA?
How can we submit our request to exercise our Rights Under the CCPA/CPRA?
What is SOC 2 compliance?
What is SOC 2 compliance?
What are SOC 2 requirements?
What are SOC 2 requirements?
Is Xoxoday SOC 2 certified?
Is Xoxoday SOC 2 certified?
Is your cloud computing platform (AWS) SOC 2 Compliant?
Is your cloud computing platform (AWS) SOC 2 Compliant?
How do I request Xoxoday for SOC 2 report?
How do I request Xoxoday for SOC 2 report?
Who performs the independent third-party audit of Xoxoday for the SOC Report?
Who performs the independent third-party audit of Xoxoday for the SOC Report?
How long is a SOC 2 report valid?
How long is a SOC 2 report valid?
Is SOC 2 an international standard?
Is SOC 2 an international standard?
Do you conduct a SOC 2 audit every year?
Do you conduct a SOC 2 audit every year?
Did all applicable compliances and controls are audited during the SOC 2 attestation process?
Did all applicable compliances and controls are audited during the SOC 2 attestation process?
Do you process Protected Health Information (PHI)?
Do you process Protected Health Information (PHI)?
Is Xoxoday compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Is Xoxoday compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Do you make the HIPAA Audit report available for the customers?
Do you make the HIPAA Audit report available for the customers?
Do you have the process in place for providing Access Rights to the data subject as per EU GDPR?
Do you have the process in place for providing Access Rights to the data subject as per EU GDPR?
What method do you use when deleting customer data if requested to do so?
What method do you use when deleting customer data if requested to do so?
Do you have procedures in place for responding to a data subject request that involves a customer's Personal Data?
Do you have procedures in place for responding to a data subject request that involves a customer's Personal Data?
Do you perform audits on its Sub-processors to demonstrate their compliance?
Do you perform audits on its Sub-processors to demonstrate their compliance?
Do you conduct independent audits? (Third-Party)
Do you conduct independent audits? (Third-Party)
Does your organization have a plan or framework for business continuity management or disaster recovery management plan and policy in place? Frequency of testing?
Does your organization have a plan or framework for business continuity management or disaster recovery management plan and policy in place? Frequency of testing?
Are the responsibilities regarding data stewardship defined, assigned, documented, and communicated?
Are the responsibilities regarding data stewardship defined, assigned, documented, and communicated?
Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of customer data once a customer has exited your environment or has vacated a resource?
Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of customer data once a customer has exited your environment or has vacated a resource?
Do you classify your assets in terms of business criticality, service-level expectations, and operational continuity requirements?
Do you classify your assets in terms of business criticality, service-level expectations, and operational continuity requirements?
Do you maintain a complete inventory of all of your critical assets located at all sites/ or geographical locations and their assigned ownership?
Do you maintain a complete inventory of all of your critical assets located at all sites/ or geographical locations and their assigned ownership?
Do you have procedures and technical measures in place for data access segmentation in multi-customer system architectures?
Do you have procedures and technical measures in place for data access segmentation in multi-customer system architectures?
Do you support password (e.g., minimum length, age, history, complexity) and account lockout (e.g., lockout threshold, lockout duration) policy enforcement?
Do you support password (e.g., minimum length, age, history, complexity) and account lockout (e.g., lockout threshold, lockout duration) policy enforcement?
Can you provide evidence that due diligence mapping of regulations and standards to your controls/architecture/processes has been performed?
Can you provide evidence that due diligence mapping of regulations and standards to your controls/architecture/processes has been performed?
Is system performance monitored and tuned in order to continuously meet regulatory, contractual, and business requirements for all the systems used to provide services to the customers?
Is system performance monitored and tuned in order to continuously meet regulatory, contractual, and business requirements for all the systems used to provide services to the customers?
Do you maintain current architecture diagrams that include data flows between security domains/zones?
Do you maintain current architecture diagrams that include data flows between security domains/zones?
Are operating systems hardened to provide only the necessary ports, protocols, and services to meet business needs using technical controls (e.g., antivirus, file integrity monitoring, and logging) as part of their baseline build standard or template?
Are operating systems hardened to provide only the necessary ports, protocols, and services to meet business needs using technical controls (e.g., antivirus, file integrity monitoring, and logging) as part of their baseline build standard or template?
Do you use a network segregated from production-level networks when migrating physical servers, applications, or data to virtual servers?
Do you use a network segregated from production-level networks when migrating physical servers, applications, or data to virtual servers?
Do you provide policies and procedures (i.e. service level agreements) governing the migration of application data to and from your service?
Do you provide policies and procedures (i.e. service level agreements) governing the migration of application data to and from your service?
Do you integrate customer requirements into your security incident response plans?
Do you integrate customer requirements into your security incident response plans?
Have you tested your security incident response plans in the last year?
Have you tested your security incident response plans in the last year?
Does your incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
Does your incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?
Do you make security incident information available to all affected customers and providers periodically through electronic methods (e.g., portals)?
Do you make security incident information available to all affected customers and providers periodically through electronic methods (e.g., portals)?
Do you perform annual internal assessments of conformance and effectiveness of your policies, procedures, and supporting measures and metrics?
Do you perform annual internal assessments of conformance and effectiveness of your policies, procedures, and supporting measures and metrics?
Do third-party agreements include provision for the security and protection of information and assets?
Do third-party agreements include provision for the security and protection of information and assets?
Are systems in place to monitor for privacy breaches and notify customers expeditiously if a privacy event may have impacted their data?
Are systems in place to monitor for privacy breaches and notify customers expeditiously if a privacy event may have impacted their data?
Do you have the ability to measure and address non-conformance of provisions and/or terms across the entire supply chain (upstream/downstream)?
Do you have the ability to measure and address non-conformance of provisions and/or terms across the entire supply chain (upstream/downstream)?
Do you mandate annual information security reviews and audits of your third party providers to ensure that all agreed upon security requirements are met?
Do you mandate annual information security reviews and audits of your third party providers to ensure that all agreed upon security requirements are met?
Do you verify that your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
Do you verify that your software suppliers adhere to industry standards for Systems/Software Development Lifecycle (SDLC) security?
All sub-processors are subject to regular due diligence
All sub-processors are subject to regular due diligence
Privacy training is provided to all staff on induction and at least annually thereafter
Privacy training is provided to all staff on induction and at least annually thereafter
Do you have a member in your organisation with dedicated information security duties?
Do you have a member in your organisation with dedicated information security duties?
Do employees have a unique log-in ID when accessing data?
Do employees have a unique log-in ID when accessing data?
Are network boundaries protected by firewalls?
Are network boundaries protected by firewalls?
Are all servers, end user devices (All systems) configured according to security standards as part of the build process?
Are all servers, end user devices (All systems) configured according to security standards as part of the build process?
Has the Data back-up and recovery process been verified?
Has the Data back-up and recovery process been verified?
Is there formal control of access to System Administrator privileges?
Is there formal control of access to System Administrator privileges?
Are servers configured to capture who accessed a system and what changes were made?
Are servers configured to capture who accessed a system and what changes were made?
Are computer rooms protected against fire and flood?
Are computer rooms protected against fire and flood?
Are security incidents reviewed to capture the root cause and act on key learnings?
Are security incidents reviewed to capture the root cause and act on key learnings?
Does the organisation receive an SSAE-16 SOC Report?
Does the organisation receive an SSAE-16 SOC Report?
Does the organisationis been audited for ISO 27001 or for other security standards?
Does the organisationis been audited for ISO 27001 or for other security standards?
Does the Cloud Hosting Provider provide independent audit reports (e.g., Service Operational Control - SOC) for their cloud hosting services?
Does the Cloud Hosting Provider provide independent audit reports (e.g., Service Operational Control - SOC) for their cloud hosting services?
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)?
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)?
Do employees/contingent workers who have remote access connect to the customer network?
Do employees/contingent workers who have remote access connect to the customer network?
If an employee no longer requires remote access to the customer network, is there a process to inform the the customer in a timely manner to revoke access?
If an employee no longer requires remote access to the customer network, is there a process to inform the the customer in a timely manner to revoke access?
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)?
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)?
Does the current DLP solution have the capability to monitor all the endpoints within the Organization?
Does the current DLP solution have the capability to monitor all the endpoints within the Organization?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified as personally identifiable financial information under the Gramm-Leach-Bliley Act?
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization?
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization?
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause?
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause?
Is Risk Assessment Activity carried out for the organization covering the processes and assets of the customer operations?
Is Risk Assessment Activity carried out for the organization covering the processes and assets of the customer operations?
Does the organization has a mechanism to classify & protect sensitive IT assets covering the customer operations?
Does the organization has a mechanism to classify & protect sensitive IT assets covering the customer operations?
Do all employees, contractors and third party users sign terms and conditions of employment stating that they agree to adhere to the information security requirements for their role(s) within the organization?
Do all employees, contractors and third party users sign terms and conditions of employment stating that they agree to adhere to the information security requirements for their role(s) within the organization?
Describe the security controls in place to restrict physical entry & exit (e.g. badge access control systems, biometric systems, man traps, etc)
Describe the security controls in place to restrict physical entry & exit (e.g. badge access control systems, biometric systems, man traps, etc)
What are the fire protection & detection mechanisms placed in critical IT locations pertaining to the customer operations?
What are the fire protection & detection mechanisms placed in critical IT locations pertaining to the customer operations?
Are the major changes affecting the risk profile of the provider environment notified to the customer?
Are the major changes affecting the risk profile of the provider environment notified to the customer?
Is there an established SPOC for notifying these changes and ensuring documentation?
Is there an established SPOC for notifying these changes and ensuring documentation?
Are user e-mail accounts at the vendor processing facility created after necessary management / HR approvals?
Are user e-mail accounts at the vendor processing facility created after necessary management / HR approvals?
Are e-mail ids created if the vendor operations are outsourced / sub-contracted to other parties? If yes, Are proper approvals taken for the same?
Are e-mail ids created if the vendor operations are outsourced / sub-contracted to other parties? If yes, Are proper approvals taken for the same?
Describe your company's policies, procedures, and practices regarding email security controls?
Describe your company's policies, procedures, and practices regarding email security controls?
Is attachment size defined? Are the mail attachments for the customer process scanned for Virus and other malicious content?
Is attachment size defined? Are the mail attachments for the customer process scanned for Virus and other malicious content?
Does e-mail communication from the vendor include a standard disclaimer as a part of the contents?
Does e-mail communication from the vendor include a standard disclaimer as a part of the contents?
Is there restriction for usage & access to internet from systems in the customer operations?
Is there restriction for usage & access to internet from systems in the customer operations?
Has the vendor maintained redundancy for firewall & other network components? How it is ensured that network uptime is 100%
Has the vendor maintained redundancy for firewall & other network components? How it is ensured that network uptime is 100%
Do the modifications in the firewall rule-base for the customer operations go through the change management routine?
Do the modifications in the firewall rule-base for the customer operations go through the change management routine?
Is there a mechanism to ensure that only licensed softwares / applications are installed on the systems?
Is there a mechanism to ensure that only licensed softwares / applications are installed on the systems?
Is each operating system up to date with patches provided by the manufacturer?
Is each operating system up to date with patches provided by the manufacturer?
Whether the capacity demands are monitored and projections of future capacity requirements are made, to ensure that adequate processing power and storage are available. Example: Monitoring hard disk space, RAM and CPU on critical servers.
Whether the capacity demands are monitored and projections of future capacity requirements are made, to ensure that adequate processing power and storage are available. Example: Monitoring hard disk space, RAM and CPU on critical servers.
Does the vendor address AntiVirus Signature Management covering systems used for the customer operations? Is frequency defined?
Does the vendor address AntiVirus Signature Management covering systems used for the customer operations? Is frequency defined?
Are the AV signatures up to date?
Are the AV signatures up to date?
Did the business continuity test include all third parties, including sub-contractors, that support the the customer's business process?
Did the business continuity test include all third parties, including sub-contractors, that support the the customer's business process?
What is the frequency of these tests?
What is the frequency of these tests?
Is there a legal agreement signed between vendor and CSP?
Is there a legal agreement signed between vendor and CSP?
How does vendor ensure protection against Malicious Code and Monitoring on cloud?
How does vendor ensure protection against Malicious Code and Monitoring on cloud?
Does security controls implemented by CSP are as per Internationally accepted guidelines / standards (e.g. CSA Cloud Matrix, NIST, SANS, CIS Critical Controls, OWAPS, ISO)?
Does security controls implemented by CSP are as per Internationally accepted guidelines / standards (e.g. CSA Cloud Matrix, NIST, SANS, CIS Critical Controls, OWAPS, ISO)?
Is there a provision of demanding and review of compliance certificate like ISO27001 / PCI:DSS / NIST etc from CSP?
Is there a provision of demanding and review of compliance certificate like ISO27001 / PCI:DSS / NIST etc from CSP?
How does vendor and CSP ensure the confidentiality, integrity, availability and privacy of data collected, processes, stored and disposed through cloud services?
How does vendor and CSP ensure the confidentiality, integrity, availability and privacy of data collected, processes, stored and disposed through cloud services?
Are the roles and responsibility / duties for cloud services engagement clearly been segregated between the customer and vendor and between Vendor and CSP?
Are the roles and responsibility / duties for cloud services engagement clearly been segregated between the customer and vendor and between Vendor and CSP?
Is there a communication procedure available along with escalation matrix for vendor?
Is there a communication procedure available along with escalation matrix for vendor?
In event of legal / federal investigation of CSP / other tenants, how the security (C, I & A) of Vendor / the customer data is being maintained?
In event of legal / federal investigation of CSP / other tenants, how the security (C, I & A) of Vendor / the customer data is being maintained?
Has the service been audited in the past year for any of the following, by any independent entities? - Privacy - Information Security - Disaster Recovery - Operations - Technology - Other:
Has the service been audited in the past year for any of the following, by any independent entities? - Privacy - Information Security - Disaster Recovery - Operations - Technology - Other:
Have any of the audits addressed above resulted in any exceptions or findings?
Have any of the audits addressed above resulted in any exceptions or findings?
What is the production site physical address (DC, DR and Operations Location)?
What is the production site physical address (DC, DR and Operations Location)?
Are there any additional location(s) where target data (the customer data) is stored/ accessed/ processes/ transferred/ administered?
Are there any additional location(s) where target data (the customer data) is stored/ accessed/ processes/ transferred/ administered?
Please provide details in the following areas in scope to services being provided to the customer: - Operating system(s) - Workstations # of devices - Servers # of devices - List Applications in scope. - Number of employees by function (e.g., development, systems operations, information security)
Please provide details in the following areas in scope to services being provided to the customer: - Operating system(s) - Workstations # of devices - Servers # of devices - List Applications in scope. - Number of employees by function (e.g., development, systems operations, information security)
Details of control mechanism which will be deployed by the function to ensure that the service provider does not violate the internal norms of the insurer or the regulatory requirements set in the local regulator's guidelines? For example sample testing, maker checker, system controls, etc.
Details of control mechanism which will be deployed by the function to ensure that the service provider does not violate the internal norms of the insurer or the regulatory requirements set in the local regulator's guidelines? For example sample testing, maker checker, system controls, etc.
Do you maintain an information labelling and handling procedures? Are documented information tagged/labelled as per your asset classification schema which is at par with BSLI Information classification policy?
Do you maintain an information labelling and handling procedures? Are documented information tagged/labelled as per your asset classification schema which is at par with BSLI Information classification policy?
Are secure work areas adequately protected against environmental hazards? Do you have fire alarm/suppression systems installed across office (secure areas/work areas)? Do you have a VESDA system installed? Do you have temperature and humidity controls deployed? Do you have UPS and DG set systems in place? Do you have precision AC's installed? Do you have smoke detectors installed?
Are secure work areas adequately protected against environmental hazards? Do you have fire alarm/suppression systems installed across office (secure areas/work areas)? Do you have a VESDA system installed? Do you have temperature and humidity controls deployed? Do you have UPS and DG set systems in place? Do you have precision AC's installed? Do you have smoke detectors installed?
Do you use CCTV cameras to monitor the facility on a 7x24-hour basis? If Yes, are all cameras operating and positioned properly to view activity at all entrances/exits to the facility and sensitive areas (e.g.. call center, computer room)?
Do you use CCTV cameras to monitor the facility on a 7x24-hour basis? If Yes, are all cameras operating and positioned properly to view activity at all entrances/exits to the facility and sensitive areas (e.g.. call center, computer room)?
Is there a dedicated team responsible for Information Security?
Is there a dedicated team responsible for Information Security?
Whether all network Infra (Router, Switch, Firewall, etc.,) are integrated with the Service provider Domain and that a central IDAM solution or TACACS (Radius) is implemented for managing access to the network components?
Whether all network Infra (Router, Switch, Firewall, etc.,) are integrated with the Service provider Domain and that a central IDAM solution or TACACS (Radius) is implemented for managing access to the network components?
Whether audit requirements and activities involving checks on operational systems are carefully planned and agreed to minimize the risk of disruptions to business process? Do you agree to allow BSLI Auditors or Contracted Third Parties conduct IS Audit at your premise? Do your agree to allow Surprise Adits to be conducted by BSLI Auditors or Contracted Third Parties?
Whether audit requirements and activities involving checks on operational systems are carefully planned and agreed to minimize the risk of disruptions to business process? Do you agree to allow BSLI Auditors or Contracted Third Parties conduct IS Audit at your premise? Do your agree to allow Surprise Adits to be conducted by BSLI Auditors or Contracted Third Parties?
The organization has a Disaster Recovery Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Disaster Recovery Plan? Disaster Recovery Plan is tested atleast once in a year and test results/learnings are communicated to the customer? The organization has a Business Continuity Policy in place?
The organization has a Disaster Recovery Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Disaster Recovery Plan? Disaster Recovery Plan is tested atleast once in a year and test results/learnings are communicated to the customer? The organization has a Business Continuity Policy in place?
The organization has a Crisis Management in place for any Crisis Impacting its Operations? The organization has a Business Continuity/Alternate Site Plan in place to support/resume its key products & services? The Business Continuity plan complies to the recovery requirements of the customer (RTO,RPO & ROL) The organization has a Pandemic Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Business Continuity / Alternate Site Plan? Business Continuity / Alternate Site Plan is tested atleast once in a year and test results/learnings are communicated to the customer?
The organization has a Crisis Management in place for any Crisis Impacting its Operations? The organization has a Business Continuity/Alternate Site Plan in place to support/resume its key products & services? The Business Continuity plan complies to the recovery requirements of the customer (RTO,RPO & ROL) The organization has a Pandemic Plan in place to support its key products & services? The organization has a Test Calendar in place to test its Business Continuity / Alternate Site Plan? Business Continuity / Alternate Site Plan is tested atleast once in a year and test results/learnings are communicated to the customer?
No Generic IDs to issued / used within the application
No Generic IDs to issued / used within the application
Appropriate architecture and processes to be set to ensure application meets the availability requirements through implementaton of HA / DR and Processes like Backup and restoration For SaaS applications SLAs need to be adhered to as well for uptime assurances provided
Appropriate architecture and processes to be set to ensure application meets the availability requirements through implementaton of HA / DR and Processes like Backup and restoration For SaaS applications SLAs need to be adhered to as well for uptime assurances provided
Ability to selective delete any Sensitive / PII information basis retention policy, customer request or as needed due to any business requirement
Ability to selective delete any Sensitive / PII information basis retention policy, customer request or as needed due to any business requirement
Does your organisation have a pandemic plan? Please submit a copy of the Pandemic plan mentioning the business continuity strategies for services rendered to the customer
Does your organisation have a pandemic plan? Please submit a copy of the Pandemic plan mentioning the business continuity strategies for services rendered to the customer
How would your company protect its employees and clients against getting infected in the Workplace? Please elaborate
How would your company protect its employees and clients against getting infected in the Workplace? Please elaborate
Is there a mechanism to identify and send sick employees or visitors home? Please elaborate
Is there a mechanism to identify and send sick employees or visitors home? Please elaborate
Are the mentioned business continuity strategies tested in the last 12 months?
Are the mentioned business continuity strategies tested in the last 12 months?
Does the business continuity strategies defined for pandemic fulfill the Recovery Time Objective, Recovery Point Objective & Revised Operating Level (MBCO) requirements as agreed contractually or mutually
Does the business continuity strategies defined for pandemic fulfill the Recovery Time Objective, Recovery Point Objective & Revised Operating Level (MBCO) requirements as agreed contractually or mutually
Are Crisis communicaiton procedures defined to notify the customer in case of any impact to your organisation due to pandemic situation and providing periodic updates on the developments.
Are Crisis communicaiton procedures defined to notify the customer in case of any impact to your organisation due to pandemic situation and providing periodic updates on the developments.
Does Supplier consider itself a Controller or Processor, or Joint Controller with the customer?
Does Supplier consider itself a Controller or Processor, or Joint Controller with the customer?
Does Supplier have an automatic method for advising the customer of new Sub Processors?
Does Supplier have an automatic method for advising the customer of new Sub Processors?
Does Supplier have adequate written agreements on data protection requiring appropriate technical and organisational measures in place with such Sub Processors or will be put into place prior to any subcontracting?
Does Supplier have adequate written agreements on data protection requiring appropriate technical and organisational measures in place with such Sub Processors or will be put into place prior to any subcontracting?
What certifications does Supplier have in place (i.e. SSAE 16 or ISAE 3402, ISO 27001 etc.)?
What certifications does Supplier have in place (i.e. SSAE 16 or ISAE 3402, ISO 27001 etc.)?
Does Supplier have business continuity plans that have been implemented and tested?
Does Supplier have business continuity plans that have been implemented and tested?
Does Supplier have cybersecurity insurance? If so, please provide material details of the coverage?
Does Supplier have cybersecurity insurance? If so, please provide material details of the coverage?
Confirm how Supplier demonstrates compliance with its data processing obligations.
Confirm how Supplier demonstrates compliance with its data processing obligations.
Provide the detailed Technical Architecture description of all the components of the proposed solution including monitoring solutions used by the provider
Provide the detailed Technical Architecture description of all the components of the proposed solution including monitoring solutions used by the provider
Can you list the security certifications of you company and can the customer get a certificate/report of the relevant certications
Can you list the security certifications of you company and can the customer get a certificate/report of the relevant certications
Provide an overview of the various standards, methodologies, processes and tools used to build in Security in your SDLC and detect security defects and vulnerabilities in your applications (internal or outsourced developments) prior to deployment to production (BSIMM, NIST, Manual or automated source code analysis, peer review, etc)
Provide an overview of the various standards, methodologies, processes and tools used to build in Security in your SDLC and detect security defects and vulnerabilities in your applications (internal or outsourced developments) prior to deployment to production (BSIMM, NIST, Manual or automated source code analysis, peer review, etc)
Can the customer get a copy of the last 2 reports of each of the audits performed and the action plan conducted to fix the identified issues?
Can the customer get a copy of the last 2 reports of each of the audits performed and the action plan conducted to fix the identified issues?
Describe the status of your readiness regarding European Directive EU 2016/1148 (NIS Directive) regarding the Security of the Network and Information System
Describe the status of your readiness regarding European Directive EU 2016/1148 (NIS Directive) regarding the Security of the Network and Information System
Provide the Continuity of Activity plan in place, including the frequency of the tests performed to ensure continuing effectiveness
Provide the Continuity of Activity plan in place, including the frequency of the tests performed to ensure continuing effectiveness
Provide an overview of the various standards, methodologies, tools, policies and processes in place to support service operations (ITIL v4 and COBIT 5, etc.)
Provide an overview of the various standards, methodologies, tools, policies and processes in place to support service operations (ITIL v4 and COBIT 5, etc.)
Describe how high availability of the proposed solution is addressed including redundancy mechanisms, geographical resilient hosting options, service failover capability to other providers, etc. Also describe the process in place to test redundancy and how frequent the test is performed.
Describe how high availability of the proposed solution is addressed including redundancy mechanisms, geographical resilient hosting options, service failover capability to other providers, etc. Also describe the process in place to test redundancy and how frequent the test is performed.
Describe the SLAs you are committed to regarding the impact of any disruption of your organization to your customers (degraded performances, service interruption, etc.) and what security KPI are made available to the customer in the contractual SLAs engaging the provider
Describe the SLAs you are committed to regarding the impact of any disruption of your organization to your customers (degraded performances, service interruption, etc.) and what security KPI are made available to the customer in the contractual SLAs engaging the provider
Provide the documentation regarding your program in place to manage risk
Provide the documentation regarding your program in place to manage risk
Do you have a cyber insurance?
Do you have a cyber insurance?
Describe how you provide training about Security and compliance to your staff, how often the awareness is performed, how you document their acknowledgment and the formal disciplinary or sanction policy established for employees who have violated security policies and procedures.
Describe how you provide training about Security and compliance to your staff, how often the awareness is performed, how you document their acknowledgment and the formal disciplinary or sanction policy established for employees who have violated security policies and procedures.
Describe how firewalling and vulnerability assessments accommodating the virtualization technologies is performed (e.g. virtualization aware)?
Describe how firewalling and vulnerability assessments accommodating the virtualization technologies is performed (e.g. virtualization aware)?
What is your process to monitor that system performance continuously meets all requirements (contractual, business, regulatory) to provide proper service to your customers. Can the customer run his own performance measurement?
What is your process to monitor that system performance continuously meets all requirements (contractual, business, regulatory) to provide proper service to your customers. Can the customer run his own performance measurement?
How often do you perform revalidations of the policies of FW, IPS, WAF, etc. and document the business justification in the access control lists.
How often do you perform revalidations of the policies of FW, IPS, WAF, etc. and document the business justification in the access control lists.
Describe the process to manage the Antivirus/antimalware and specify how frequently the patterns are updated and controlled.
Describe the process to manage the Antivirus/antimalware and specify how frequently the patterns are updated and controlled.
Describe how your tenants can report Bugs and security vulnerabilities and the process in place to remedy reported defects. Are your customers informed of discovered defects and the relevant remediation plan?
Describe how your tenants can report Bugs and security vulnerabilities and the process in place to remedy reported defects. Are your customers informed of discovered defects and the relevant remediation plan?
Describe how reversibility is addressed, and more specifically can virtual machine images be downloaded and ported to a new cloud provider or to on-site storage, how long the customer's data is available for his retrieval, under what format (e.g. OVF), etc.
Describe how reversibility is addressed, and more specifically can virtual machine images be downloaded and ported to a new cloud provider or to on-site storage, how long the customer's data is available for his retrieval, under what format (e.g. OVF), etc.
If you are relying on supplier/subcontractors, provide a full list of those involved in providing the contracted service and specify if you will stand Accountable for any security breach originating from one of your suppliers/subcontractors
If you are relying on supplier/subcontractors, provide a full list of those involved in providing the contracted service and specify if you will stand Accountable for any security breach originating from one of your suppliers/subcontractors
Provide an overview of the periodic reviews you perform to check the conformance and effectiveness of your policies, procedures and supporting measures and metrics. Specify how these reviews extend to all your partners upstream/downstream
Provide an overview of the periodic reviews you perform to check the conformance and effectiveness of your policies, procedures and supporting measures and metrics. Specify how these reviews extend to all your partners upstream/downstream
If administrators are allowed to access the infrastructure hosting the proposed solution using mobile devices, provide an exhaustive overview of your centralized MDM solution and more specifically of how you control integrity and security level of the private device and how you guarantee that no customer data is locally cached on the personal device
If administrators are allowed to access the infrastructure hosting the proposed solution using mobile devices, provide an exhaustive overview of your centralized MDM solution and more specifically of how you control integrity and security level of the private device and how you guarantee that no customer data is locally cached on the personal device
Have the information security policy and standards been approved by senior management?
Have the information security policy and standards been approved by senior management?
Is antivirus software installed on workstations?
Is antivirus software installed on workstations?
Does the organisation have security measures in place for data protection?
Does the organisation have security measures in place for data protection?
Are End User Devices (Servers, Desktops, Laptops, Tablets, Smartphones) used for transmitting, processing or storing Data has anti-malware, file integrity monitoring or application whitelisting deployed in the organisation?
Are End User Devices (Servers, Desktops, Laptops, Tablets, Smartphones) used for transmitting, processing or storing Data has anti-malware, file integrity monitoring or application whitelisting deployed in the organisation?
Are non-company managed PCs used to connect to the company network?
Are non-company managed PCs used to connect to the company network?
What is the frequency of BC/DR plan Testing?
What is the frequency of BC/DR plan Testing?
Have BC/DR drill been conducted at reguralar planed intervals?
Have BC/DR drill been conducted at reguralar planed intervals?
Are computer rooms protected against fire and flood? (2)
Are computer rooms protected against fire and flood? (2)
Is there an established incident management program approved by management, communicated to appropriate constituents, maintain and revieweed?
Is there an established incident management program approved by management, communicated to appropriate constituents, maintain and revieweed?
Are security incidents reviewed to capture the root cause and act on key learnings? (2)
Are security incidents reviewed to capture the root cause and act on key learnings? (2)
Does the organisation have a formal Incident Response plan?
Does the organisation have a formal Incident Response plan?
Are all potential incidents assessed to determine appropriate classification, severity and impact?
Are all potential incidents assessed to determine appropriate classification, severity and impact?
Has the organisation experienced an information security breach in the past three to five years?
Has the organisation experienced an information security breach in the past three to five years?
Does the organisation receive an SSAE-16 SOC Report? (2)
Does the organisation receive an SSAE-16 SOC Report? (2)
Does the organisationis been audited for ISO 27001 or for other security standards? (2)
Does the organisationis been audited for ISO 27001 or for other security standards? (2)
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards
Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)? (2)
Is the Cloud Service Provider certified by an independent third party for compliance with domestic or international control standards (e.g., the National Institute of Standards and Technology - NIST, the International Organization for Standardization - ISO)? (2)
Are Global Blocklist and Whitelist configurations (such as URL's/domains inaccessible/accessible through the organization's proxies) enabled and reveiwed annually
Are Global Blocklist and Whitelist configurations (such as URL's/domains inaccessible/accessible through the organization's proxies) enabled and reveiwed annually
Users may have a legitimate business requirement to access blocked websites. If such a need arises, is there a process to request and obtain approval for the same?
Users may have a legitimate business requirement to access blocked websites. If such a need arises, is there a process to request and obtain approval for the same?
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)? (2)
Are controls implemented to restrict sharing of files via conferencing/collaboration tools to the external parties (Microsoft Teams, Skype, Cisco WebEx etc.)? (2)
Does the current DLP solution have the capability to monitor all the endpoints within the Organization? (2)
Does the current DLP solution have the capability to monitor all the endpoints within the Organization? (2)
Is there a formalized risk governance plan that defines the Enterprise Risk Management program requirements?
Is there a formalized risk governance plan that defines the Enterprise Risk Management program requirements?
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization? (2)
Is there a formalized Risk Assessment process that identifies, quantifies, and prioritizes risks based on the risk acceptance levels relevant to the organization? (2)
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause? (2)
Do contracts with all subcontractors include Non-Disclosure/Confidentiality Agreements, data breach notification, Indemnification/liability and termination/exit clause? (2)
Is the Saas Solution deployed on public cloud or cloud hosted by Saas Vendor?
Is the Saas Solution deployed on public cloud or cloud hosted by Saas Vendor?
Are hardening standards defined and followed for all infrastructure components (OS, Network Devices, Servers, Firewalls, DBs etc.)
Are hardening standards defined and followed for all infrastructure components (OS, Network Devices, Servers, Firewalls, DBs etc.)
Is VPN and VPC services used for transmitting data securely e.g. tunneling services?
Is VPN and VPC services used for transmitting data securely e.g. tunneling services?
What kind of access the vendor employees will have on the application and how access to the customer data in the application is restricted from being accessed by Vendor employees?
What kind of access the vendor employees will have on the application and how access to the customer data in the application is restricted from being accessed by Vendor employees?
What policies are configured for restricting PII leakage from the system?
What policies are configured for restricting PII leakage from the system?
Is user access controlled and has limited access to the data and configuration settings on cloud?
Is user access controlled and has limited access to the data and configuration settings on cloud?
Vendor shall immediately inform the customer about any security incident.
Vendor shall immediately inform the customer about any security incident.
Does the agreement contains right to audit the service provider Information System
Does the agreement contains right to audit the service provider Information System
Compliant with all regulatory requirements
Compliant with all regulatory requirements
Compliance to IT Act and other Acts applicable to data
Compliance to IT Act and other Acts applicable to data
ISO 27001:2013 or any equivalent Information Secuirty Management System
ISO 27001:2013 or any equivalent Information Secuirty Management System
Service Organization Control SOC type 2 or any equivalent compliance report
Service Organization Control SOC type 2 or any equivalent compliance report
ISO 27018:2018 Code of Practice for Protection of PII in Public Cloud, if PII data is stored on the cloud.
ISO 27018:2018 Code of Practice for Protection of PII in Public Cloud, if PII data is stored on the cloud.
PCI-DSS in case the CSP handles card holder data if card data is processed and stored.
PCI-DSS in case the CSP handles card holder data if card data is processed and stored.
Which all processes Vendor is handling currently and how the customer is sharing the data with them?
Which all processes Vendor is handling currently and how the customer is sharing the data with them?
How data sharing between vendor and the customer will take place?
How data sharing between vendor and the customer will take place?
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Will any Personally Identifiable Information (PII) be stored with vendor? Please mention specific reports that are to be stored.
Sub-contractor responsibilities and dependencies are clarified, and risks of employment of subcontractors are fully managed. Subcontractor is subject to all requirements the Contractor is.
Sub-contractor responsibilities and dependencies are clarified, and risks of employment of subcontractors are fully managed. Subcontractor is subject to all requirements the Contractor is.
Vendor has relevant encryption capabilities, and is able to apply encryption at the customer data at rest and in transit (when solution is to be hosted on the customer datacenter solution, it should be secured using a the customer approved digital certificate), whenever deemed necessary and required by the customer or relevant external regulation. The solution should provide secure and reliable ways to exchange data with the customer backend systems and SaaS applications as well.
Vendor has relevant encryption capabilities, and is able to apply encryption at the customer data at rest and in transit (when solution is to be hosted on the customer datacenter solution, it should be secured using a the customer approved digital certificate), whenever deemed necessary and required by the customer or relevant external regulation. The solution should provide secure and reliable ways to exchange data with the customer backend systems and SaaS applications as well.
Sufficient service uptime is guaranteed, meeting the customer expectations (on availability, RTO, RPO). Vendor has a BCP and DRP in place, ensuring service downtimes are kept as short as possible.
Sufficient service uptime is guaranteed, meeting the customer expectations (on availability, RTO, RPO). Vendor has a BCP and DRP in place, ensuring service downtimes are kept as short as possible.
There is proper control in place for the usage of system utilities to circumvent application controls, and this possibility is disabled.
There is proper control in place for the usage of system utilities to circumvent application controls, and this possibility is disabled.
Contractor is certified under external security best practices and standards (e.g. ISO). Contract shall include an audit clause that gives the customer the right to obtain independent audit reports (ISAE 3402 type 2, SOC 2, SSAE 18, ISO27k, PCI-DSS Level 1, etc.), network/application penetration testing reports, and vulnerability scanning results. The results can be summarized (not containing confidential technical details), or detailed when limited to the systems used by the customer. Furthermore, the customer should be allowed to initiate independent vulnerability scanning / penetration testing on the services received by the Vendor.
Contractor is certified under external security best practices and standards (e.g. ISO). Contract shall include an audit clause that gives the customer the right to obtain independent audit reports (ISAE 3402 type 2, SOC 2, SSAE 18, ISO27k, PCI-DSS Level 1, etc.), network/application penetration testing reports, and vulnerability scanning results. The results can be summarized (not containing confidential technical details), or detailed when limited to the systems used by the customer. Furthermore, the customer should be allowed to initiate independent vulnerability scanning / penetration testing on the services received by the Vendor.
Guarantees are offered to the customer on resolving security incidents / outages.
Guarantees are offered to the customer on resolving security incidents / outages.
Provide a general description of the information security measures applicable to the services you offer to the customer.
Provide a general description of the information security measures applicable to the services you offer to the customer.
the customer requires transfer outside of the EEA to have a valid legal basis. Please describe the legal basis for each of the countries that personal data is transferred to.
the customer requires transfer outside of the EEA to have a valid legal basis. Please describe the legal basis for each of the countries that personal data is transferred to.
Are you, or have you been involved in any legal proceedings, civil or public, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and document the outcome of these proceedings.
Are you, or have you been involved in any legal proceedings, civil or public, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and document the outcome of these proceedings.
Are you aware of any legal proceedings, civil or public, that any of your (sub) processors have been involved in, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and outcome of these proceedings.
Are you aware of any legal proceedings, civil or public, that any of your (sub) processors have been involved in, relating to processing of Personal Data in connection with the services that you offer to the customer, in the last five years? If so, please elaborate on the nature and outcome of these proceedings.
To the extent applicable: 1) Describe the certifications and audit scheme that you have or will put in place, to allow the customer to verify compliance with applicable law and the Data Processing Agreement during the contract period 2) Describe the regularity and scope of any third party audits with regard to information security, data protection compliance and to what extent (sub) contractors are covered by the audit schemes 3) Describe how the customer will obtain access to reports from audits for any transfer of Personal Data to countries outside the EEA.
To the extent applicable: 1) Describe the certifications and audit scheme that you have or will put in place, to allow the customer to verify compliance with applicable law and the Data Processing Agreement during the contract period 2) Describe the regularity and scope of any third party audits with regard to information security, data protection compliance and to what extent (sub) contractors are covered by the audit schemes 3) Describe how the customer will obtain access to reports from audits for any transfer of Personal Data to countries outside the EEA.
Through discussions with the vendor, try to obtain an overview of the value chain from the cloud vendor and backwards to subcontractors
Through discussions with the vendor, try to obtain an overview of the value chain from the cloud vendor and backwards to subcontractors
Does the contract detail the scope and functionality of the online services?
Does the contract detail the scope and functionality of the online services?
Any written documentation for the SLA? Are SLA objectives measurable and have relevant penalties? Do they cover availability, response times or other? What does the SLA cover?
Any written documentation for the SLA? Are SLA objectives measurable and have relevant penalties? Do they cover availability, response times or other? What does the SLA cover?
Are there any technical and organisational measures that aim to remedy the risks entailed by lack of control and lack of information featuring in the cloud computing environment? E.g. measures aimed at ensuring availability, integrity, confidentiality, isolation, intervenability and portability.
Are there any technical and organisational measures that aim to remedy the risks entailed by lack of control and lack of information featuring in the cloud computing environment? E.g. measures aimed at ensuring availability, integrity, confidentiality, isolation, intervenability and portability.
What kind of certifications does the cloud vendor have (ISO 2001, SOC report etc.)?
What kind of certifications does the cloud vendor have (ISO 2001, SOC report etc.)?
Is there a clause saying that no data shall be processed by Supplier or any subcontractors for other purposes than the one specified in the contract?
Is there a clause saying that no data shall be processed by Supplier or any subcontractors for other purposes than the one specified in the contract?
Does the contract specify that Supplier may not communicate the data to third parties, even for preservation purposes unless it is provided for in the contract that there will be subcontractors?
Does the contract specify that Supplier may not communicate the data to third parties, even for preservation purposes unless it is provided for in the contract that there will be subcontractors?
Does the data processing agreement specify the types of personal data processed by Supplier?
Does the data processing agreement specify the types of personal data processed by Supplier?
Does the contract ensure a logging of processing operations on personal data performed by Supplier and its sub-contractors?
Does the contract ensure a logging of processing operations on personal data performed by Supplier and its sub-contractors?
Does the Supplier ensure lawfulness of cross-border data transfers and do they have a list of locations in which the services may be provided from? May the customer limit the vendor's right to change or disregard such a list?
Does the Supplier ensure lawfulness of cross-border data transfers and do they have a list of locations in which the services may be provided from? May the customer limit the vendor's right to change or disregard such a list?
Does the contract include any clause specifying that Supplier must inform the customer of any intended changes in regards to changes in sub-processors? the customer shall retain at all times the possibility to object to such changes or to terminate the contract.
Does the contract include any clause specifying that Supplier must inform the customer of any intended changes in regards to changes in sub-processors? the customer shall retain at all times the possibility to object to such changes or to terminate the contract.
Any specific restrictions in the right to use? Acceptable use policy is one example that should be considered versus the customer's needs.
Any specific restrictions in the right to use? Acceptable use policy is one example that should be considered versus the customer's needs.
Does the cloud provider have right to suspend services for specific reasons? As an example, in a situation with non-payment? If yes, is there a notice period or other important conditions to be observed?
Does the cloud provider have right to suspend services for specific reasons? As an example, in a situation with non-payment? If yes, is there a notice period or other important conditions to be observed?
Which law is the contract subject to? What are the legal venue for disputes arising under the contract? What are the regulations around dispute resolution?
Which law is the contract subject to? What are the legal venue for disputes arising under the contract? What are the regulations around dispute resolution?
Do you perform a regular information security risk assessment?
Do you perform a regular information security risk assessment?
Do you provide customers with ongoing visibility and reporting of your SLA performance?
Do you provide customers with ongoing visibility and reporting of your SLA performance?
Do you have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
Do you have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
Are there policies and procedures in place to triage and remedy reported bugs and security vulnerabilities for product and service offerings?
Are there policies and procedures in place to triage and remedy reported bugs and security vulnerabilities for product and service offerings?
Do you specifically train your employees regarding their specific role and the information security controls they must fulfil?
Do you specifically train your employees regarding their specific role and the information security controls they must fulfil?
Name and description of the software/service.
Name and description of the software/service.
Is there a respondent information security function responsible for security initiatives?
Is there a respondent information security function responsible for security initiatives?
Can the respondent do Creation, review and approve of information security policies?
Can the respondent do Creation, review and approve of information security policies?
What are your data leak prevention capabilities?
What are your data leak prevention capabilities?
Do you have a policy that requires endpoints (laptops,desktops,etc) to have anti-malware software? What capabilities does the anti-malware solution has? (Signature based detections, NGAV, EDR, etc.)
Do you have a policy that requires endpoints (laptops,desktops,etc) to have anti-malware software? What capabilities does the anti-malware solution has? (Signature based detections, NGAV, EDR, etc.)
Does your IT provide remote wipe or corporate data wipe for all endpoints (laptops,desktops,etc) and company-accepted BYOD devices?
Does your IT provide remote wipe or corporate data wipe for all endpoints (laptops,desktops,etc) and company-accepted BYOD devices?
Is the solution provided to Customer part of a valid ISO 27001 certification? If so, please provide a valid ISO/IEC 27001 certificate with corresponding SOA - Statement of Applicability
Is the solution provided to Customer part of a valid ISO 27001 certification? If so, please provide a valid ISO/IEC 27001 certificate with corresponding SOA - Statement of Applicability
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports? (2)
Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports? (2)
Does the Company use Software Development Life Cycle (SDLC) process to ensure quality and correctness of the solution built?
Does the Company use Software Development Life Cycle (SDLC) process to ensure quality and correctness of the solution built?
What is the strategy around application Secure Code Scanning & management?
What is the strategy around application Secure Code Scanning & management?
Is there a status page available for communication about the application's untime status, or any ongoing and past incidents?
Is there a status page available for communication about the application's untime status, or any ongoing and past incidents?
Are the retained logs sufficient to permit forensic analysis on security events?
Are the retained logs sufficient to permit forensic analysis on security events?
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants?
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants?
What is your SLA - uptime and availability?
What is your SLA - uptime and availability?
What is the penalty offered to the customers for SLA violations?
What is the penalty offered to the customers for SLA violations?
What level of support is provided to the clients? Mention the time slots where support is available
What level of support is provided to the clients? Mention the time slots where support is available
Please provide support covered under standard annual license and annual maintenance where applicable
Please provide support covered under standard annual license and annual maintenance where applicable
Details of certifications Which includes for each certification: Certification Body First Certification Date Current Certification date
Details of certifications Which includes for each certification: Certification Body First Certification Date Current Certification date
The vendor should detail how frequently backups of customer data are made, how long they are retained, and how soon customer data is purged following deletion by an end user
The vendor should detail how frequently backups of customer data are made, how long they are retained, and how soon customer data is purged following deletion by an end user
Define Service monitoring.
Define Service monitoring.
Does the role of Quality unit during product development and/or during service provision define?
Does the role of Quality unit during product development and/or during service provision define?
When our company needs to access the logs of Vendor and our company or that of our company's users for case investigation, how long does it take Vendor to provide complete logs to our company? (1-24 hours is appropriate)
When our company needs to access the logs of Vendor and our company or that of our company's users for case investigation, how long does it take Vendor to provide complete logs to our company? (1-24 hours is appropriate)
In the admin console, is there an interactive interface to look up our company's user's detailed information?
In the admin console, is there an interactive interface to look up our company's user's detailed information?
What kind of permission request process do Vendor's O&M personnel, including DBAs, would go through if they want to refer to our company's data stored in the Vendor backend system?
What kind of permission request process do Vendor's O&M personnel, including DBAs, would go through if they want to refer to our company's data stored in the Vendor backend system?
When the Vendor's operation and maintenance personnel, including the DBA, try to refer to our company's data stored in the Vendor backend system, is there an audit log record of the entire operation process?
When the Vendor's operation and maintenance personnel, including the DBA, try to refer to our company's data stored in the Vendor backend system, is there an audit log record of the entire operation process?
When the logs which described above are needed, whether or not can it be completely provided to our company when there is a need for case investigation?
When the logs which described above are needed, whether or not can it be completely provided to our company when there is a need for case investigation?
When the logs which described above are needed, how long does it take Vendor to provide them to our company? (1-24 hours is appropriate)
When the logs which described above are needed, how long does it take Vendor to provide them to our company? (1-24 hours is appropriate)
Are there any other compliance qualifications? If so, please list out in detail
Are there any other compliance qualifications? If so, please list out in detail
Summary of key risks based on risk assessment reports
Summary of key risks based on risk assessment reports
A risk management process shall be used to balance the benefits of cloud computing with the security risks associated before engaging with a Cloud Service provider.
A risk management process shall be used to balance the benefits of cloud computing with the security risks associated before engaging with a Cloud Service provider.
The risk assessment framework adopted by NSE may be used for the cloud service risk assessment.
The risk assessment framework adopted by NSE may be used for the cloud service risk assessment.
The outcome of the risk management process shall determine the model and controls that shall be adopted.
The outcome of the risk management process shall determine the model and controls that shall be adopted.
The Cloud Service Provider shall ensure that it will demonstrate compliance with NSE policy requirements and regulatory requirements.
The Cloud Service Provider shall ensure that it will demonstrate compliance with NSE policy requirements and regulatory requirements.
The Cloud Service Provider shall conduct annual audit by an independent third-party auditor to check the design effectiveness as well as their operating effectiveness of their internal controls covering the principles of Security, Availability, Confidentiality, and Privacy.
The Cloud Service Provider shall conduct annual audit by an independent third-party auditor to check the design effectiveness as well as their operating effectiveness of their internal controls covering the principles of Security, Availability, Confidentiality, and Privacy.
NSE shall be provided access to these reports as and when required.
NSE shall be provided access to these reports as and when required.
The Cloud Service Provider shall provide complete visibility to ensure NSE's services are being processes and delivered in a secure manner.
The Cloud Service Provider shall provide complete visibility to ensure NSE's services are being processes and delivered in a secure manner.
NSE shall have all the Service Level arrangements documented in the agreement/ contract with the Cloud Service provider guided by NSE's Outsourcing Policy.
NSE shall have all the Service Level arrangements documented in the agreement/ contract with the Cloud Service provider guided by NSE's Outsourcing Policy.
NSE shall review the Service Level Agreements (SLA) for amendments, annually or as when required.
NSE shall review the Service Level Agreements (SLA) for amendments, annually or as when required.
Cloud Service Provider shall provide regular reports on the SLA achieved and compliance to the agreement/contract to NSE. The frequency of reporting shall be mandated in the agreement / contract.
Cloud Service Provider shall provide regular reports on the SLA achieved and compliance to the agreement/contract to NSE. The frequency of reporting shall be mandated in the agreement / contract.
Any breach in the SLA by Cloud Service provider shall be reported as mandated by NSE.
Any breach in the SLA by Cloud Service provider shall be reported as mandated by NSE.
In a multi-tenant cloud architecture, the Cloud Service Provider shall ensure that NSE's data shall be isolated and inaccessible to any other tenants.
In a multi-tenant cloud architecture, the Cloud Service Provider shall ensure that NSE's data shall be isolated and inaccessible to any other tenants.
Any access by other tenants to NSE's data shall be considered as a breach and the Cloud Service Provider shall ensure the breach notification process is followed.
Any access by other tenants to NSE's data shall be considered as a breach and the Cloud Service Provider shall ensure the breach notification process is followed.
Cloud Service provider shall notify NSE of any potential breach incident or any actual breach as mandated by NSE.
Cloud Service provider shall notify NSE of any potential breach incident or any actual breach as mandated by NSE.
NSE shall ensure that the cloud computing services can be ported to any other Cloud Service Provider or to other data centres with least impact to business.
NSE shall ensure that the cloud computing services can be ported to any other Cloud Service Provider or to other data centres with least impact to business.
On completion of the transfer, the Cloud Service Provider shall delete all the data and information from its infrastructure and provide a certificate to NSE that the data has been securely deleted and the same cannot be recovered by any means.
On completion of the transfer, the Cloud Service Provider shall delete all the data and information from its infrastructure and provide a certificate to NSE that the data has been securely deleted and the same cannot be recovered by any means.
Wherever applicable, NSE shall maintain an up to date inventory of hardware, software and virtual assets hosting NSE's applications and data.
Wherever applicable, NSE shall maintain an up to date inventory of hardware, software and virtual assets hosting NSE's applications and data.
The inventory shall be reviewed and updated as per the Asset Management Policy of NSE.
The inventory shall be reviewed and updated as per the Asset Management Policy of NSE.
Cloud Service Provider shall ensure that no database server, application server or storage devices hosting NSE's data & information be made publicly available over the internet.
Cloud Service Provider shall ensure that no database server, application server or storage devices hosting NSE's data & information be made publicly available over the internet.
When is live (standard service) phone technical support available? Is backup (phone or email) available for off-hours?
When is live (standard service) phone technical support available? Is backup (phone or email) available for off-hours?
Describe the training that is available with the initial system installation.
Describe the training that is available with the initial system installation.
What type of training does your company recommend, require, and offer?
What type of training does your company recommend, require, and offer?
Do you provide on-demand training over the Internet? If so, what training is available to users? Is there an associated cost?
Do you provide on-demand training over the Internet? If so, what training is available to users? Is there an associated cost?
What is your escalation process for support issues? Describe in detail.
What is your escalation process for support issues? Describe in detail.
Who will have access to UP data? (Just Supplier employees? Contractors? Employees and contingent employees?)
Who will have access to UP data? (Just Supplier employees? Contractors? Employees and contingent employees?)
Describe your employee and contractor background checks
Describe your employee and contractor background checks
How do you monitor third parties that have access to UP data?
How do you monitor third parties that have access to UP data?
Does the cloud service provider require the use of two-factor authentication for the administrative control of servers, routers, switches and firewalls?
Does the cloud service provider require the use of two-factor authentication for the administrative control of servers, routers, switches and firewalls?
How is user access monitored and documented?
How is user access monitored and documented?
Network IDS?
Network IDS?
Host IDS?
Host IDS?
SIEM?
SIEM?
Are security controls audited on an annual basis?
Are security controls audited on an annual basis?
Can documentation be provided that can show how UP data cannot be compromised by other customers or non-customers of the Supplier?
Can documentation be provided that can show how UP data cannot be compromised by other customers or non-customers of the Supplier?
What is the size and relevant experience (in years) of the security and incident response teams?
What is the size and relevant experience (in years) of the security and incident response teams?
How is the data stored?
How is the data stored?
Is planned/scheduled maintenance included in the calculated uptime? Will it count against the SLA?
Is planned/scheduled maintenance included in the calculated uptime? Will it count against the SLA?
Does planned/scheduled maintenance count against the SLA?
Does planned/scheduled maintenance count against the SLA?
What is your resiliency, reliability, back-up and disaster recovery strategy?
What is your resiliency, reliability, back-up and disaster recovery strategy?
How often are these processes tested?
How often are these processes tested?
Describe your established maintenance window.
Describe your established maintenance window.
Describe in detail your service or mitigation plans to continue to make the service available to customers during a denial of service attack.
Describe in detail your service or mitigation plans to continue to make the service available to customers during a denial of service attack.
Does the architecture of the provided service include redundancy of security systems, including firewalls, IDS/IPS, any other critical security service?
Does the architecture of the provided service include redundancy of security systems, including firewalls, IDS/IPS, any other critical security service?
Does Supplier have established procedures for cooperating with local government and law enforcement requesting customer data?
Does Supplier have established procedures for cooperating with local government and law enforcement requesting customer data?
Describe your established procedures for cooperating with local government and law enforcement requesting customer data.
Describe your established procedures for cooperating with local government and law enforcement requesting customer data.
Which cloud providers do you rely on?
Which cloud providers do you rely on?
Does the penetration test follow an industry approved methodology, please describe
Does the penetration test follow an industry approved methodology, please describe
Please describe the company/user data you require to provide your service: personal information, financial data, confidential/sensitive data, government data
Please describe the company/user data you require to provide your service: personal information, financial data, confidential/sensitive data, government data
Do you have capabilities to anonymize data?
Do you have capabilities to anonymize data?
Do you keep sensitive data (as defined by your data classification matrix) in hard copy (e.g. paper copies)? If so, please describe.
Do you keep sensitive data (as defined by your data classification matrix) in hard copy (e.g. paper copies)? If so, please describe.
How do you regularly audit your critical vendors?
How do you regularly audit your critical vendors?
Do you have a formal Information Security Program (InfoSec SP) in place?
Do you have a formal Information Security Program (InfoSec SP) in place?
Do you review your Information Security Policies at least once a year?
Do you review your Information Security Policies at least once a year?
Do you have a Information security risk management program (InfoSec RMP)?
Do you have a Information security risk management program (InfoSec RMP)?
Do you have management support or a security management forum to evaluate and take action on security risks?
Do you have management support or a security management forum to evaluate and take action on security risks?
Do you have a dedicated information security team? If so, what is the composition and reporting structure?
Do you have a dedicated information security team? If so, what is the composition and reporting structure?
Do you publish a path for responisble disclosure of security vulnerabilities (ie security@ or /security)?
Do you publish a path for responisble disclosure of security vulnerabilities (ie security@ or /security)?
Do you have an established bug bounty program?
Do you have an established bug bounty program?
Are all endpoint laptops that connect directly to production networks centrally managed?
Are all endpoint laptops that connect directly to production networks centrally managed?
Describe standard employee issued device security configuration/features. (Login Password, antimalware, Full Disk Encryption, Administrative Privileges, Firewall, Auto-lock, etc.)
Describe standard employee issued device security configuration/features. (Login Password, antimalware, Full Disk Encryption, Administrative Privileges, Firewall, Auto-lock, etc.)
Does sensitive or private data ever reside on endpoint devices? How is this policy enforced?
Does sensitive or private data ever reside on endpoint devices? How is this policy enforced?
How do you keep aware of potential security vulnerabilities and threats that may affect your service?
How do you keep aware of potential security vulnerabilities and threats that may affect your service?
How is your Incident Response Plan tested? Include how often.
How is your Incident Response Plan tested? Include how often.
Describe how threat modelling is incorporated in the design phase of development?
Describe how threat modelling is incorporated in the design phase of development?
How do you train developers in SSDLC / Secure Coding Practices?
How do you train developers in SSDLC / Secure Coding Practices?
How do you monitor vulnerabilities in dependencies?
How do you monitor vulnerabilities in dependencies?
Do you outsource development? (contracted with a 3rd party? open source project inclusion?)
Do you outsource development? (contracted with a 3rd party? open source project inclusion?)
What types of security reviews do you perform on custom-built software?
What types of security reviews do you perform on custom-built software?
Does application support IP whitelisting for API access?
Does application support IP whitelisting for API access?
How do you conduct internal audits (audits lead by your personnel) of the service? please describe the scope, remediation process and frequency of audits.
How do you conduct internal audits (audits lead by your personnel) of the service? please describe the scope, remediation process and frequency of audits.
How do you conduct external (third-party) audits of the service? please describe the scope and frequency of audits.
How do you conduct external (third-party) audits of the service? please describe the scope and frequency of audits.
Please provide a copy of the most recent report.
Please provide a copy of the most recent report.
Do you seek a right to use or own customer derived data for your own purposes?
Do you seek a right to use or own customer derived data for your own purposes?
Do your information security and privacy policies align with industry standards (ISO-27001, NIST Cyber Security Framework, ISO-22307, CoBIT, etc.)?
Do your information security and privacy policies align with industry standards (ISO-27001, NIST Cyber Security Framework, ISO-22307, CoBIT, etc.)?
Are all personnel required to sign Confidentiality Agreements to protect customer information, as a condition of employment?
Are all personnel required to sign Confidentiality Agreements to protect customer information, as a condition of employment?
Hardware security
Hardware security
Paper Document Security
Paper Document Security
Physical access control
Physical access control
Maintenance - Describe here how physical maintenance of hardware is managed
Maintenance - Describe here how physical maintenance of hardware is managed
Backups - Indicate here how backups are managed. Clarify whether they are stored in safe place
Backups - Indicate here how backups are managed. Clarify whether they are stored in safe place
Governance - Describe the documentary base setting out data protection objectives and rules
Governance - Describe the documentary base setting out data protection objectives and rules
Managing Privacy Risk - Describe processes to control the risks that processing operations performed by the organisation
Managing Privacy Risk - Describe processes to control the risks that processing operations performed by the organisation
If the customer data will be held by a subcontractor to your organisation, how will you ensure that their Information Security meets required standards?
If the customer data will be held by a subcontractor to your organisation, how will you ensure that their Information Security meets required standards?
Will an asset register be completed to log all assets holding the customer data and who is responsible for updating it?
Will an asset register be completed to log all assets holding the customer data and who is responsible for updating it?
How will you decide which of your staff (support, development etc.) need access to the the customer system and data? How will you manage that access and what controls are in place, to ensure that privileged access rights will be restricted and controlled?
How will you decide which of your staff (support, development etc.) need access to the the customer system and data? How will you manage that access and what controls are in place, to ensure that privileged access rights will be restricted and controlled?
Is your organisation ISO/IEC 27001 or similarly certified or compliant? Please provide details. If yes please provide evidence and skip section 5.
Is your organisation ISO/IEC 27001 or similarly certified or compliant? Please provide details. If yes please provide evidence and skip section 5.
When a person working with the customer data no longer performs that role, are their permissions to the customer data revoked?
When a person working with the customer data no longer performs that role, are their permissions to the customer data revoked?
Is your organisation's Information Security Management System (i.e. control objectives, controls, policies, processes and procedures for information security) reviewed, internally and independently audited for compliance at planned intervals or when significant changes to the security implementation occurs?
Is your organisation's Information Security Management System (i.e. control objectives, controls, policies, processes and procedures for information security) reviewed, internally and independently audited for compliance at planned intervals or when significant changes to the security implementation occurs?
Have all relevant statutory, regulatory, contractual requirements, (including: intellectual property rights, protection of records, protection of personally identifiable information and cryptographic controls) and the organisation's approach to meet these requirements, been explicitly identified, documented and kept up to date, for the/each the customer information system?
Have all relevant statutory, regulatory, contractual requirements, (including: intellectual property rights, protection of records, protection of personally identifiable information and cryptographic controls) and the organisation's approach to meet these requirements, been explicitly identified, documented and kept up to date, for the/each the customer information system?
Describe how and when media containing the customer data would be securely destroyed and how you would evidence this?
Describe how and when media containing the customer data would be securely destroyed and how you would evidence this?
Will any physical media containing the customer data, be transferred outside your organisation and if so, what procedures will be in place to protect the media from compromise?
Will any physical media containing the customer data, be transferred outside your organisation and if so, what procedures will be in place to protect the media from compromise?
Is there a documented standard procedure followed for building and hardening host machines? If so please attach a copy.
Is there a documented standard procedure followed for building and hardening host machines? If so please attach a copy.
Are these procedures periodically reviewed and kept in line with current best practice?
Are these procedures periodically reviewed and kept in line with current best practice?
How will security incidents relating to the customer data be reported to the customer?
How will security incidents relating to the customer data be reported to the customer?
What physical measures (e.g. CCTV, Coded Locks, Guards) will be in place to protect the customer data that is stored: At your offices/location At the data centre How will these controls be managed and monitored?
What physical measures (e.g. CCTV, Coded Locks, Guards) will be in place to protect the customer data that is stored: At your offices/location At the data centre How will these controls be managed and monitored?
Emergency, temporary or test accounts should be documented, have a specified period of validity and terminated immediately after validity period expires.
Emergency, temporary or test accounts should be documented, have a specified period of validity and terminated immediately after validity period expires.
Responsibilities and duties for system users shall be segregated based on the defined roles.
Responsibilities and duties for system users shall be segregated based on the defined roles.
There should be a minimum three types of user groups for systems and applications (e.g. operator, supervisor, engineer, domain administrator, etc.) where technically feasible.
There should be a minimum three types of user groups for systems and applications (e.g. operator, supervisor, engineer, domain administrator, etc.) where technically feasible.
Role based user accounts shall be implemented for operation users (operators, supervisors, shift controller, engineer, etc.) with specific and defined privileges based on the principle of least privilege for each role.
Role based user accounts shall be implemented for operation users (operators, supervisors, shift controller, engineer, etc.) with specific and defined privileges based on the principle of least privilege for each role.
Privileges for all accounts used with the customer assets shall be identified and documented.
Privileges for all accounts used with the customer assets shall be identified and documented.
Where strong authentication and identity verification is required, authentication methods alternative, or additional, to passwords, such as cryptographic means, smart cards, tokens or biometric means, shall be used.
Where strong authentication and identity verification is required, authentication methods alternative, or additional, to passwords, such as cryptographic means, smart cards, tokens or biometric means, shall be used.
Temporary account user name and passwords shall be communicated in a secure manner following these practices: When users are required to change the passwords, they should initially be provided with secure temporary authentication information, which they are immediately forced to change. Verify the identity of a user prior to providing a new, replacement or temporary password. Temporary authentication information shall be unique to a user. Users shall acknowledge the receipt of temporary passwords.
Temporary account user name and passwords shall be communicated in a secure manner following these practices: When users are required to change the passwords, they should initially be provided with secure temporary authentication information, which they are immediately forced to change. Verify the identity of a user prior to providing a new, replacement or temporary password. Temporary authentication information shall be unique to a user. Users shall acknowledge the receipt of temporary passwords.
All users and access to the customer networks and services shall be documented.
All users and access to the customer networks and services shall be documented.
Where technically feasible, ensure all authentication attempts (successful and unsuccessful) are logged up to the capabilities of the authentication system.
Where technically feasible, ensure all authentication attempts (successful and unsuccessful) are logged up to the capabilities of the authentication system.
Only protocol ports and services required for proper functioning of the system or application shall be allowed on each system.
Only protocol ports and services required for proper functioning of the system or application shall be allowed on each system.
All network filtering mechanisms (e.g. firewalls) shall apply an opt-in principle with a fail-safe mechanism (i.e. default deny rule that drops all traffic, except that which is explicitly allowed and if an error/failure occurs the system should fail in a secure manner: security controls and settings remain in effect and are enforced).
All network filtering mechanisms (e.g. firewalls) shall apply an opt-in principle with a fail-safe mechanism (i.e. default deny rule that drops all traffic, except that which is explicitly allowed and if an error/failure occurs the system should fail in a secure manner: security controls and settings remain in effect and are enforced).
All equipment connected to the customer networks shall be identified and classified based on the defined classification scheme. All equipment connected to the customer networks should have appropriate technical and/or business justifications supporting the need for that connection.
All equipment connected to the customer networks shall be identified and classified based on the defined classification scheme. All equipment connected to the customer networks should have appropriate technical and/or business justifications supporting the need for that connection.
Unique identifiers shall be developed in, or attached to, the equipment to indicate whether the asset is permitted to connect to the network.
Unique identifiers shall be developed in, or attached to, the equipment to indicate whether the asset is permitted to connect to the network.
Where technically feasible, implement network-based technical controls that detect and prevent connections and/or attempts to connect equipment to the customer networks.
Where technically feasible, implement network-based technical controls that detect and prevent connections and/or attempts to connect equipment to the customer networks.
Detection capabilities should be augmented with event correlation (e.g. SIEM) used to correlate approved and expected connections of equipment to the customer networks.
Detection capabilities should be augmented with event correlation (e.g. SIEM) used to correlate approved and expected connections of equipment to the customer networks.
Network devices shall be securely configured taking following measures into consideration: Source and address violation rules. Router protection (e.g. hardening). Specific sub-netting for publicly accessible systems. Boundary protection device for external connections. Monitoring for suspicious traffic.
Network devices shall be securely configured taking following measures into consideration: Source and address violation rules. Router protection (e.g. hardening). Specific sub-netting for publicly accessible systems. Boundary protection device for external connections. Monitoring for suspicious traffic.
Wherever feasible, vendor-supplied software packages shall be used without any changes.
Wherever feasible, vendor-supplied software packages shall be used without any changes.
When changes to software packages are required, the following shall be considered: Responsibility for future maintenance of the software. Compatibility with existing application software. Risks of existing application controls being altered or compromised.
When changes to software packages are required, the following shall be considered: Responsibility for future maintenance of the software. Compatibility with existing application software. Risks of existing application controls being altered or compromised.
Where technically feasible, any changes to software shall be tested in a non-production/test environment before moving it to a production environment.
Where technically feasible, any changes to software shall be tested in a non-production/test environment before moving it to a production environment.
Based on the information asset's classification, controls shall be applied to restrict access to information and applications.
Based on the information asset's classification, controls shall be applied to restrict access to information and applications.
Service account passwords or application hard-coded passwords that cannot be changed shall be documented and additional compensating controls shall be identified to protect and monitor such systems.
Service account passwords or application hard-coded passwords that cannot be changed shall be documented and additional compensating controls shall be identified to protect and monitor such systems.
Contracts with vendors shall include the requirements for secure design, coding, testing practices and a warranty clause that the software/system is free from security vulnerabilities.
Contracts with vendors shall include the requirements for secure design, coding, testing practices and a warranty clause that the software/system is free from security vulnerabilities.
Document/guide for secure use or operation of the supplied system or component shall be provided
Document/guide for secure use or operation of the supplied system or component shall be provided
Patch management policy and process is in place to cover patch qualification, patch distribution, update and auditing process
Patch management policy and process is in place to cover patch qualification, patch distribution, update and auditing process
Third parties shall address security vulnerabilities brought to its attention by the customer in a timely manner.
Third parties shall address security vulnerabilities brought to its attention by the customer in a timely manner.
For any hardware, software or firmware, supplied, a quality certificate (QC) ensuring that all provided hardware, software or firmware is free from any dormant malicious programmes should be provided.
For any hardware, software or firmware, supplied, a quality certificate (QC) ensuring that all provided hardware, software or firmware is free from any dormant malicious programmes should be provided.
All systems shall be tested prior to acquisition and prior to accepting new systems into operational environment based on predefined criteria.
All systems shall be tested prior to acquisition and prior to accepting new systems into operational environment based on predefined criteria.
Identify and document criteria for testing new features or enhancements to existing systems or assets.
Identify and document criteria for testing new features or enhancements to existing systems or assets.
Define criteria for accepting products (e.g. in terms of their functionality), to ensure identified security requirements are met.
Define criteria for accepting products (e.g. in terms of their functionality), to ensure identified security requirements are met.
Ensure tests are performed and results are documented.
Ensure tests are performed and results are documented.
Where the functionality in a proposed product does not satisfy the specified requirement, the risk introduced, and associated controls should be documented and reconsidered prior to purchasing the product.
Where the functionality in a proposed product does not satisfy the specified requirement, the risk introduced, and associated controls should be documented and reconsidered prior to purchasing the product.
All system vendors and third parties shall follow security test processes outlined in the system and services acquisition process document (e.g. FAT, SAT, unit testing, integration testing and UAT)
All system vendors and third parties shall follow security test processes outlined in the system and services acquisition process document (e.g. FAT, SAT, unit testing, integration testing and UAT)
the customer responsible staff shall sign-off and certify that all relevant security requirements have been tested satisfactorily before turn-over to operations.
the customer responsible staff shall sign-off and certify that all relevant security requirements have been tested satisfactorily before turn-over to operations.
Any variation between system design and system implementation shall be recorded and security risk assessment shall be conducted to determine mitigation strategies.
Any variation between system design and system implementation shall be recorded and security risk assessment shall be conducted to determine mitigation strategies.
All software and hardware acquisition contracts shall include identified rules and requirements and require compliance and the possibility to audit the development processes.
All software and hardware acquisition contracts shall include identified rules and requirements and require compliance and the possibility to audit the development processes.
Only licensed third-party libraries and components shall be used.
Only licensed third-party libraries and components shall be used.
Formal change control processes shall be used to manage changes to software code, taking into account that: Impacts of changes to software are understood using risk assessment methodologies. Changes do not compromise exiting security and control measures. Existing documentation is updated. Acceptance testing is performed to validate if system behaves only as expected.
Formal change control processes shall be used to manage changes to software code, taking into account that: Impacts of changes to software are understood using risk assessment methodologies. Changes do not compromise exiting security and control measures. Existing documentation is updated. Acceptance testing is performed to validate if system behaves only as expected.
Vendors and third parties shall provide documented artefacts to ensure that security controls as requested within this manual are instituted in the system.
Vendors and third parties shall provide documented artefacts to ensure that security controls as requested within this manual are instituted in the system.
All supply chain requirements are also applicable to work subcontracted by vendors and third parties to develop, test or integrate systems for the customer.
All supply chain requirements are also applicable to work subcontracted by vendors and third parties to develop, test or integrate systems for the customer.
All conditions under which the transfer of information/data must be protected shall be documented and maintained.
All conditions under which the transfer of information/data must be protected shall be documented and maintained.
Actions to be taken when issues arise regarding the transfer of information/data must be identified and documented.
Actions to be taken when issues arise regarding the transfer of information/data must be identified and documented.
To ensure information is adequately protected during transfer, specific controls and procedures shall be identified. Security controls shall be appropriate to the strictest classification level of the information/data to be handled. Such countermeasures may include encryption and/or cryptographic signatures, physical restriction to assets and/or access control mechanisms.
To ensure information is adequately protected during transfer, specific controls and procedures shall be identified. Security controls shall be appropriate to the strictest classification level of the information/data to be handled. Such countermeasures may include encryption and/or cryptographic signatures, physical restriction to assets and/or access control mechanisms.
An exchange of information agreement with each external party outlining clear roles and responsibilities of each party must be established. Consider security conditions such as: Ensuring traceability and non-repudiation. Responsibilities for tracking message transmission, dispatch, and receipt. Licensing and escrow agreements. Ownership and responsibilities for data protection, copyright, license compliance, etc. Responsibilities and liabilities in the event of security incidents, such as loss or disclosure of data. Selection and audit criteria for couriers or escrow agents. Maintaining chains of custody for information being stored or transferred, including documentation and management of access control levels.
An exchange of information agreement with each external party outlining clear roles and responsibilities of each party must be established. Consider security conditions such as: Ensuring traceability and non-repudiation. Responsibilities for tracking message transmission, dispatch, and receipt. Licensing and escrow agreements. Ownership and responsibilities for data protection, copyright, license compliance, etc. Responsibilities and liabilities in the event of security incidents, such as loss or disclosure of data. Selection and audit criteria for couriers or escrow agents. Maintaining chains of custody for information being stored or transferred, including documentation and management of access control levels.
Records of media transfer shall be kept.
Records of media transfer shall be kept.
Monitor and audit the log records to ensure requirements are being met.
Monitor and audit the log records to ensure requirements are being met.
Document and maintain up-to-date all points of interconnection between information/data systems and the types of information/data to be protected regarding the identified interconnections.
Document and maintain up-to-date all points of interconnection between information/data systems and the types of information/data to be protected regarding the identified interconnections.
A security risk assessment shall be conducted to determine which message's authenticities and integrities are critical to prevent unacceptable impacts to the customer.
A security risk assessment shall be conducted to determine which message's authenticities and integrities are critical to prevent unacceptable impacts to the customer.
Monitor message tampering and source spoofing for messages for which authenticity and/or integrity need to be ensured.
Monitor message tampering and source spoofing for messages for which authenticity and/or integrity need to be ensured.
Appropriate compensating controls shall be in place to protect against security threats to weak protocols (e.g. protocols lacking encryption or authentication mechanisms).
Appropriate compensating controls shall be in place to protect against security threats to weak protocols (e.g. protocols lacking encryption or authentication mechanisms).
Any traffic between OT/IT networks shall to be officially approved after a security risk assessment on the suggested traffic, and documented with business justification, the risk it represents and the controls that will be used to reduce the risk to an acceptable level.
Any traffic between OT/IT networks shall to be officially approved after a security risk assessment on the suggested traffic, and documented with business justification, the risk it represents and the controls that will be used to reduce the risk to an acceptable level.
Serial Interfaces shall be secured based on security risk taking in consideration the following: Employ protection and detection capabilities where applicable and subject to vendor's confirmation of proven performance. Compensating/alternate security controls shall be employed where mitigation measures cannot be applied due to technical or operational infeasibility.
Serial Interfaces shall be secured based on security risk taking in consideration the following: Employ protection and detection capabilities where applicable and subject to vendor's confirmation of proven performance. Compensating/alternate security controls shall be employed where mitigation measures cannot be applied due to technical or operational infeasibility.
Ensure security requirements and service outages are captured in service level agreements for network services. Include auditable security requirements.
Ensure security requirements and service outages are captured in service level agreements for network services. Include auditable security requirements.
Audit network services provider as defined in the service agreement.
Audit network services provider as defined in the service agreement.
All systems and equipment shall be maintained to assure that security has not been degraded below the accepted level. Preventive maintenance shall be performed at least once a year.
All systems and equipment shall be maintained to assure that security has not been degraded below the accepted level. Preventive maintenance shall be performed at least once a year.
Identify all products and components (e.g. physical and logical) used within the entity that are programmable/configurable (this may be acquired through, and documented within, the asset inventory).
Identify all products and components (e.g. physical and logical) used within the entity that are programmable/configurable (this may be acquired through, and documented within, the asset inventory).
Define and document mandatory products and components configuration baselines based on security best practices and the customer defined standards.
Define and document mandatory products and components configuration baselines based on security best practices and the customer defined standards.
Any deviations to the the customer defined configuration baseline (e.g. application/system incompatibility, lack of vendor approval, etc.) should be recorded and appropriate compensating controls shall be implemented.
Any deviations to the the customer defined configuration baseline (e.g. application/system incompatibility, lack of vendor approval, etc.) should be recorded and appropriate compensating controls shall be implemented.
Potential adverse impacts to the customer environment associated with the use of troubleshooting and other tools shall be evaluated through security risk assessment before approving the use of these tools.
Potential adverse impacts to the customer environment associated with the use of troubleshooting and other tools shall be evaluated through security risk assessment before approving the use of these tools.
Security health checks shall also be carried out and documented during each maintenance cycle. Include topics such as: Inventory register check for any inconsistencies. Inter-communication architecture. Open ports and services. System hardening. Protection from malicious code. Up-to-date security patches. Equipment backup. Performance and capacity monitoring. Renewal of subscription licenses.
Security health checks shall also be carried out and documented during each maintenance cycle. Include topics such as: Inventory register check for any inconsistencies. Inter-communication architecture. Open ports and services. System hardening. Protection from malicious code. Up-to-date security patches. Equipment backup. Performance and capacity monitoring. Renewal of subscription licenses.
If during security health checks changes to approved baselines are discovered a report shall be generated and reviewed.
If during security health checks changes to approved baselines are discovered a report shall be generated and reviewed.
Records shall be maintained, for a period of five years or as legal, regulatory or operationally required, of all suspected and actual faults, and all preventive and corrective maintenance activities.
Records shall be maintained, for a period of five years or as legal, regulatory or operationally required, of all suspected and actual faults, and all preventive and corrective maintenance activities.
All test and development environments shall be required to meet specifically defined security requirements designed to support the integrity of these environments and prevent introduction of threats to the production environment.
All test and development environments shall be required to meet specifically defined security requirements designed to support the integrity of these environments and prevent introduction of threats to the production environment.
Obsolete systems shall not be used and plans to replace/refresh must be established to reach an acceptable risk level and support.
Obsolete systems shall not be used and plans to replace/refresh must be established to reach an acceptable risk level and support.
Upgrade plan for OS obsolescence, HW/SW obsolescence etc. for all systems, assets and components shall be based on the criteria that it is obsolete and/or resulting high maintenance costs and no system vendor support is available.
Upgrade plan for OS obsolescence, HW/SW obsolescence etc. for all systems, assets and components shall be based on the criteria that it is obsolete and/or resulting high maintenance costs and no system vendor support is available.
Where technically feasible, employ anti-malicious code protection mechanisms for the network devices as well as servers, workstations, laptops and other devices connected to the the customer environment.
Where technically feasible, employ anti-malicious code protection mechanisms for the network devices as well as servers, workstations, laptops and other devices connected to the the customer environment.
Anti-malicious code protection (including supported anti-malware products, configuration settings, etc.) for IT\OT assets shall be endorsed by the vendor.
Anti-malicious code protection (including supported anti-malware products, configuration settings, etc.) for IT\OT assets shall be endorsed by the vendor.
Any deviations to the entity-defined anti-malicious code requirements (e.g. application/system incompatibility, lack of vendor approval, etc.) shall be recorded. Risks due to deviations shall be managed to entity acceptable levels through compensating controls.
Any deviations to the entity-defined anti-malicious code requirements (e.g. application/system incompatibility, lack of vendor approval, etc.) shall be recorded. Risks due to deviations shall be managed to entity acceptable levels through compensating controls.
Anti-malicious code protection tools shall be monitored for detection events and alerts.
Anti-malicious code protection tools shall be monitored for detection events and alerts.
Anti-malicious code shall be deployed with defined scanning, update, and monitoring requirements across OT/IT assets.
Anti-malicious code shall be deployed with defined scanning, update, and monitoring requirements across OT/IT assets.
All new system/asset shall not be considered in production until a vulnerability assessment has been conducted and vulnerabilities addressed.
All new system/asset shall not be considered in production until a vulnerability assessment has been conducted and vulnerabilities addressed.
In the absence of an approved entity-specific retention schedule, data backup shall be retained as per defined logging standard, after which tapes or another storage backup media may be overwritten.
In the absence of an approved entity-specific retention schedule, data backup shall be retained as per defined logging standard, after which tapes or another storage backup media may be overwritten.
Periodically verification if the customer sensitive information is exposed to the general public and/or exposed to internal network shall be conducted.
Periodically verification if the customer sensitive information is exposed to the general public and/or exposed to internal network shall be conducted.
Information regarding potential security issues shall be collected, analysed and reported in a timely manner.
Information regarding potential security issues shall be collected, analysed and reported in a timely manner.
Time distribution/clock synchronization shall be implemented in all environments from a secure and accurate source that uses an accepted secure standard protocol (e.g. IEEE 1588-2008/IEC 61588:2009).
Time distribution/clock synchronization shall be implemented in all environments from a secure and accurate source that uses an accepted secure standard protocol (e.g. IEEE 1588-2008/IEC 61588:2009).
Requirements for monitoring shall be identified: Types of systems and assets. Outline which aspects must be monitored. How monitoring is to be performed. Account for instances where automated monitoring is not technically feasible. Logs and realtime traffic shall be monitored and analysed.
Requirements for monitoring shall be identified: Types of systems and assets. Outline which aspects must be monitored. How monitoring is to be performed. Account for instances where automated monitoring is not technically feasible. Logs and realtime traffic shall be monitored and analysed.
A Security Incident and Event Management (SIEM) solution, or equivalent, shall be implemented.
A Security Incident and Event Management (SIEM) solution, or equivalent, shall be implemented.
Does the CSP agreement include security requirements that address the following security controls? 1. Data ownership 2. Data protection and storage 3. Information security incidents handling 4. Change, Recovery and Restoration 5. Data handling and storing location 6. Portability and continuity 7. Compliance and monitoring rights and methods
Does the CSP agreement include security requirements that address the following security controls? 1. Data ownership 2. Data protection and storage 3. Information security incidents handling 4. Change, Recovery and Restoration 5. Data handling and storing location 6. Portability and continuity 7. Compliance and monitoring rights and methods
Supporting Utilities: Short-term UPS to facilitate an orderly shutdown of critical in the event of primary power source loss. Long-term alternate power supply capable of maintaining minimum operational capability in case of long term power loss. Primary and alternate telecommunications equipment to support reliable operations.
Supporting Utilities: Short-term UPS to facilitate an orderly shutdown of critical in the event of primary power source loss. Long-term alternate power supply capable of maintaining minimum operational capability in case of long term power loss. Primary and alternate telecommunications equipment to support reliable operations.
Cabling Security: Power, system and communication cables shall be secured. Based on information security risk, communication cables might need to be monitored against network tap attempts and network tampering, specifically when protective technical controls are not technically feasible.
Cabling Security: Power, system and communication cables shall be secured. Based on information security risk, communication cables might need to be monitored against network tap attempts and network tampering, specifically when protective technical controls are not technically feasible.
Third party compliance to the customer security policies and procedures shall be ensured and addressed by formal contract and signed Non-Disclosure Agreement (NDA) between the customer and the third party
Third party compliance to the customer security policies and procedures shall be ensured and addressed by formal contract and signed Non-Disclosure Agreement (NDA) between the customer and the third party
Service Level Agreements shall be documented and agreed upon by all parties to ensure there is no possibility for misunderstanding between the customer and the third party regarding each party's obligations to fulfil relevant information security requirements set forth by the customer security policies and procedures.
Service Level Agreements shall be documented and agreed upon by all parties to ensure there is no possibility for misunderstanding between the customer and the third party regarding each party's obligations to fulfil relevant information security requirements set forth by the customer security policies and procedures.
External Parties shall be responsible for ensuring its personnel uphold and upkeep the customer Security Policies. All software/hardware used by the External Parties personnel inside/outside the customer premises for accessing the customer information shall be declared and may be subjected to an audit. The External Parties shall co-operate with the customer and its entities in ensuring the same.
External Parties shall be responsible for ensuring its personnel uphold and upkeep the customer Security Policies. All software/hardware used by the External Parties personnel inside/outside the customer premises for accessing the customer information shall be declared and may be subjected to an audit. The External Parties shall co-operate with the customer and its entities in ensuring the same.
Any exceptions to the entity defined Supplier Service Delivery requirements shall be recorded. Risks due to exceptions shall be managed to acceptable levels through application of compensating controls.
Any exceptions to the entity defined Supplier Service Delivery requirements shall be recorded. Risks due to exceptions shall be managed to acceptable levels through application of compensating controls.
Service agreements shall include a methodology for communicating change management issues between the customer and the external/third party.
Service agreements shall include a methodology for communicating change management issues between the customer and the external/third party.
the customer shall conduct audits of external/third parties in conjunction with review of independent auditor's reports, if available, and follow-up on issues identified.
the customer shall conduct audits of external/third parties in conjunction with review of independent auditor's reports, if available, and follow-up on issues identified.
Entities shall maintain appropriate reports and records, to monitor and measure the compliance with the security requirements as documented in the agreements with the third-parties.
Entities shall maintain appropriate reports and records, to monitor and measure the compliance with the security requirements as documented in the agreements with the third-parties.
Changes to the provision of services provided by third parties shall be managed through risk assessment taking into consideration the criticality of business process, systems and security requirements. The following aspects should be taken into considerations: Changes to third-party agreements; Changes to the third parity organisational structure; Sub-contracting; Modifications or updates of the third party's policies and procedures; Changes to the third-party risk profile.
Changes to the provision of services provided by third parties shall be managed through risk assessment taking into consideration the criticality of business process, systems and security requirements. The following aspects should be taken into considerations: Changes to third-party agreements; Changes to the third parity organisational structure; Sub-contracting; Modifications or updates of the third party's policies and procedures; Changes to the third-party risk profile.
Disaster Recovery plans and procedures shall be in place to prevent and recover from any major breakdown or disaster.
Disaster Recovery plans and procedures shall be in place to prevent and recover from any major breakdown or disaster.
Disaster recovery plans and procedures shall take into account information security requirements applicable to adverse situations.
Disaster recovery plans and procedures shall take into account information security requirements applicable to adverse situations.
Disaster recovery plan shall include a full recovery and reconstitution of the customer assets.
Disaster recovery plan shall include a full recovery and reconstitution of the customer assets.
Recovery procedures shall be reviewed on a yearly basis.
Recovery procedures shall be reviewed on a yearly basis.
Disaster recovery plan and procedures shall be communicated to all stakeholders internal and external to the organisation (employees, third parties).
Disaster recovery plan and procedures shall be communicated to all stakeholders internal and external to the organisation (employees, third parties).
Contingency roles, responsibilities shall be documented with contact information, and activities associated with restoring the system after a disruption or failure, in the disaster recovery plans.
Contingency roles, responsibilities shall be documented with contact information, and activities associated with restoring the system after a disruption or failure, in the disaster recovery plans.
Continuity plans shall be tested periodically, and the lessons learned documented.
Continuity plans shall be tested periodically, and the lessons learned documented.
When changes occur, disaster recovery plans shall be reviewed and updated, such as: Acquisition of new equipment or upgrading of systems, assets or components; Personnel; Addresses or telephone numbers; Business strategy; Location, facilities and resources; Legislation; Contractors, suppliers and key customers; Processes, or new or withdrawn ones; Risk (HSE, operational and financial, etc.).
When changes occur, disaster recovery plans shall be reviewed and updated, such as: Acquisition of new equipment or upgrading of systems, assets or components; Personnel; Addresses or telephone numbers; Business strategy; Location, facilities and resources; Legislation; Contractors, suppliers and key customers; Processes, or new or withdrawn ones; Risk (HSE, operational and financial, etc.).
Following corrective action shall be taken when non-compliance is identified: Identify the immediate and underlying causes of the non-compliance. Assess and document the risks introduced by non-compliance. Evaluate actions to be taken to attain compliance. Implement the proper corrective action.
Following corrective action shall be taken when non-compliance is identified: Identify the immediate and underlying causes of the non-compliance. Assess and document the risks introduced by non-compliance. Evaluate actions to be taken to attain compliance. Implement the proper corrective action.
Review whether the corrective action taken is effective shall be conducted: Document results generated from reviews and corrective actions. Observe those results over time in order to identify trends and implement further corrective action.
Review whether the corrective action taken is effective shall be conducted: Document results generated from reviews and corrective actions. Observe those results over time in order to identify trends and implement further corrective action.
Security assessments shall be conducted only by resources identified by the relevant the customer department/role and shall be carefully planned and agreed upon when performed against operational environment.
Security assessments shall be conducted only by resources identified by the relevant the customer department/role and shall be carefully planned and agreed upon when performed against operational environment.
Measures taken to ensure assessment activities minimise the risk of disruptions to the environment and business processes shall be documented and communicated. In particular, assessment activities shall not include network scanning or penetration testing on OT systems, as it may degrade the performance and impact the plant operations.
Measures taken to ensure assessment activities minimise the risk of disruptions to the environment and business processes shall be documented and communicated. In particular, assessment activities shall not include network scanning or penetration testing on OT systems, as it may degrade the performance and impact the plant operations.
Sensitive information shall be verified or assessed in-site and shall not be handed out or distributed.
Sensitive information shall be verified or assessed in-site and shall not be handed out or distributed.
An action plan that describes how the identified non-conformities will be addressed shall be developed and maintained on regular basis.
An action plan that describes how the identified non-conformities will be addressed shall be developed and maintained on regular basis.
the customer shall plan and conduct assessments of the information security controls in place through an established assurance process which will be continuously identifying technical and non-technical gaps.
the customer shall plan and conduct assessments of the information security controls in place through an established assurance process which will be continuously identifying technical and non-technical gaps.
Performance improvement plans shall consider and develop strategies to identify the suitability, adequacy and effectiveness of information security controls in place.
Performance improvement plans shall consider and develop strategies to identify the suitability, adequacy and effectiveness of information security controls in place.
Performance improvement plan shall leverage and document security metrics and measurements from incident reports, and audits for future improvement.
Performance improvement plan shall leverage and document security metrics and measurements from incident reports, and audits for future improvement.
The implementation of performance improvement plan shall be monitored on a regular basis: Document and maintain corrective and/or continuous improvement actions taken. Review and report the effectiveness of corrective and/or continuous improvement actions.
The implementation of performance improvement plan shall be monitored on a regular basis: Document and maintain corrective and/or continuous improvement actions taken. Review and report the effectiveness of corrective and/or continuous improvement actions.
Service shall have acceptable clause regarding data ownership and intellectual property rights as per UAE regulations and the customer policies
Service shall have acceptable clause regarding data ownership and intellectual property rights as per UAE regulations and the customer policies
Contract / statement of work / order form clearly details the services to be provided.
Contract / statement of work / order form clearly details the services to be provided.
Contract includes service levels or a separate SLA has been signed (with uptime and support response at the minimum) and consequences if service levels are not met (e.g. rebates; liquidated damages).
Contract includes service levels or a separate SLA has been signed (with uptime and support response at the minimum) and consequences if service levels are not met (e.g. rebates; liquidated damages).
Service provider shall have clear and secure controls associated with approving access to the customer data or systems by service provider staff for support and/or troubleshooting purposes.
Service provider shall have clear and secure controls associated with approving access to the customer data or systems by service provider staff for support and/or troubleshooting purposes.
Service provider should have cyber insurance covering security breaches.
Service provider should have cyber insurance covering security breaches.
Detailed access and audit logs shall be available for the customer to obtain via an API or other means, which should align with the customer security monitoring requirements
Detailed access and audit logs shall be available for the customer to obtain via an API or other means, which should align with the customer security monitoring requirements
Service Provider shall have solid DR and Business continuity plan in line with the customer requirements
Service Provider shall have solid DR and Business continuity plan in line with the customer requirements
Service Provider shall have solid endpoint security controls such as AV, EDR, exploitation protection, HIPS, App whitelisting IDS, DDOS, malware sandboxing, etc.
Service Provider shall have solid endpoint security controls such as AV, EDR, exploitation protection, HIPS, App whitelisting IDS, DDOS, malware sandboxing, etc.
Service Provider should allow the customer to preform technical and compliance audits on provider infrastructure that host the customer systems
Service Provider should allow the customer to preform technical and compliance audits on provider infrastructure that host the customer systems
Describe your security model, including network, data, and application security; data center security; application and system support; upgrades and maintenance; and personnel access rights.
Describe your security model, including network, data, and application security; data center security; application and system support; upgrades and maintenance; and personnel access rights.
How often is the platform scheduled for software patches and updates?
How often is the platform scheduled for software patches and updates?
Does the vendor allow security audits by the customer or by agents of the customer (e.g. an appointed Audit firm)?
Does the vendor allow security audits by the customer or by agents of the customer (e.g. an appointed Audit firm)?
Is there security accreditation in place such as SAS70/SSAE 16 Type II, ISO 27002 etc?
Is there security accreditation in place such as SAS70/SSAE 16 Type II, ISO 27002 etc?
What processes does the vendor have to detect and prevent viruses and other malicious software from damaging the service and the customer's data?
What processes does the vendor have to detect and prevent viruses and other malicious software from damaging the service and the customer's data?
What are the security and malpractice escalation processes?
What are the security and malpractice escalation processes?
What are the controls over interruption to the service? (SLA). What is the RPO (recovery point objective) and RTO (recovery time objective) for the service?
What are the controls over interruption to the service? (SLA). What is the RPO (recovery point objective) and RTO (recovery time objective) for the service?
What security standards are used for application development?
What security standards are used for application development?
Describe the network topology.
Describe the network topology.
Describe your approach to ensuring data security in the SaaS environment.
Describe your approach to ensuring data security in the SaaS environment.
TSL IT Security Compliance?
TSL IT Security Compliance?
Data Governance & Management features?
Data Governance & Management features?
Intelligence to predict failures and auto-corrections? Failures can be Infrastructure / Process transaction with validations as per TSL business rules
Intelligence to predict failures and auto-corrections? Failures can be Infrastructure / Process transaction with validations as per TSL business rules
What is the percentage that the SLA guarantees (in case the platform provides the services in a Saas Model)?
What is the percentage that the SLA guarantees (in case the platform provides the services in a Saas Model)?
Can evidence be provided of the processes that are implemented to guarantee the confidentiality of information, including a description of how our data is separated from other customer's data, and what controls are in place to prevent other customers from viewing our data?
Can evidence be provided of the processes that are implemented to guarantee the confidentiality of information, including a description of how our data is separated from other customer's data, and what controls are in place to prevent other customers from viewing our data?
Are there controls in place to prevent administrators and other staff from the Vendor's organisation from downloading customer data to removable storage (USB memory sticks, CD ROM etc)?
Are there controls in place to prevent administrators and other staff from the Vendor's organisation from downloading customer data to removable storage (USB memory sticks, CD ROM etc)?
Which databases are used in the backend? Which database optimization approaches are taken?
Which databases are used in the backend? Which database optimization approaches are taken?
Describe the hosting infrastructure.
Describe the hosting infrastructure.
How is system usage and performance monitored?
How is system usage and performance monitored?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
Can customers control the timing of software upgrades? What support do you provide during the upgrade process?
Is your DR plan based on active-active or active-passive?
Is your DR plan based on active-active or active-passive?
Does the application or solution have Access Control Mechanism to ensure restricted/controlled access to PII (as per business requirement)?
Does the application or solution have Access Control Mechanism to ensure restricted/controlled access to PII (as per business requirement)?
Are logs being maintained for processing activities performed on PII?
Are logs being maintained for processing activities performed on PII?
Is there an Access Control Mechanism to ensure restricted/controlled Third Party access to the application?
Is there an Access Control Mechanism to ensure restricted/controlled Third Party access to the application?
Does the application allow PII to be updated in case there is a requirement for the same?
Does the application allow PII to be updated in case there is a requirement for the same?
What is the services you are going to provide to Darwinbox
What is the services you are going to provide to Darwinbox
Has your organization formally appointed a central point of contact for security coordination? If so, whom, and what is their position within the organization? Are responsibilities clearly documented? i.e. job descriptions, information security policy
Has your organization formally appointed a central point of contact for security coordination? If so, whom, and what is their position within the organization? Are responsibilities clearly documented? i.e. job descriptions, information security policy
Have your employees been provided formal information security training? Have policies been communicated to your employees? Are periodic security reminders provided? i.e. New employee orientation, annual training, posters in public areas, email reminders, etc.
Have your employees been provided formal information security training? Have policies been communicated to your employees? Are periodic security reminders provided? i.e. New employee orientation, annual training, posters in public areas, email reminders, etc.
Are your employees required to sign a non-disclosure agreement? If so, are employees required to sign the non-disclosure agreement annually? Non-disclosure and/or confidentiality form at initial employment
Are your employees required to sign a non-disclosure agreement? If so, are employees required to sign the non-disclosure agreement annually? Non-disclosure and/or confidentiality form at initial employment
Do you have a formal process to manage the termination and or transfer of employees? i.e. All equipment is returned, user ID's disabled in systems, Windows, badges and/or keys returned. On Transfer is existing access reviewed for relevance?
Do you have a formal process to manage the termination and or transfer of employees? i.e. All equipment is returned, user ID's disabled in systems, Windows, badges and/or keys returned. On Transfer is existing access reviewed for relevance?
Has antivirus software been deployed and installed on your computers and supporting systems (e.g., desktops, servers and gateways)? 1) Product installed? Centrally managed? Updated daily? Reviewed for being current?
Has antivirus software been deployed and installed on your computers and supporting systems (e.g., desktops, servers and gateways)? 1) Product installed? Centrally managed? Updated daily? Reviewed for being current?
Whom do we contact if we identify a security issue or breach involving or impacting your product? Please provide an email address and/or full contact information b) What is their expected SLA to respond to initial contact? c) What is the definition of issue priority (ex: minor vs. major, 0-4 scale)? d) What is their expected SLA to implement changes needed to fix issues according to priority?
Whom do we contact if we identify a security issue or breach involving or impacting your product? Please provide an email address and/or full contact information b) What is their expected SLA to respond to initial contact? c) What is the definition of issue priority (ex: minor vs. major, 0-4 scale)? d) What is their expected SLA to implement changes needed to fix issues according to priority?
- Reach out to us at cs@xoxoday.com to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same.
Which all in-house or third party applications Vendor will use for the customer operations?
Which all in-house or third party applications Vendor will use for the customer operations?
Does the application support any APIs? And how are they consumed internally and externally? What controls are implemented for sharing such APIs externally?
Does the application support any APIs? And how are they consumed internally and externally? What controls are implemented for sharing such APIs externally?
How the security of the exposed APIs is managed?
How the security of the exposed APIs is managed?
Are your admins are cloud certified?
Are your admins are cloud certified?
Do you have a setup of processes for regular internal audit for data protection compliance?
Do you have a setup of processes for regular internal audit for data protection compliance?
A copy of the third-party information security program validation performed on the product/ environment, such as: SOC 2 Type II report and/or ISO 27001 certificate.
A copy of the third-party information security program validation performed on the product/ environment, such as: SOC 2 Type II report and/or ISO 27001 certificate.
A copy of audit reports from the data center where the production instance of your product is hosted (SOC1, SOC2, bridge Letters, ISO27001, other security certifications, etc.).
A copy of audit reports from the data center where the production instance of your product is hosted (SOC1, SOC2, bridge Letters, ISO27001, other security certifications, etc.).
Do you follow any particular internationally accepted best practices or standards?
Do you follow any particular internationally accepted best practices or standards?
Does the system have an international certification/award in System Security?
Does the system have an international certification/award in System Security?
Can a user login be prevented during non-office hours (e.g., off-shift, on leaves)?
Can a user login be prevented during non-office hours (e.g., off-shift, on leaves)?
Does solution provide/support remote procedure calls?
Does solution provide/support remote procedure calls?
Does solution provide/support message-oriented middleware?
Does solution provide/support message-oriented middleware?
Does solution use SSL (If use web service)?
Does solution use SSL (If use web service)?
Does solution support SFTP (both sending and receiving file)?
Does solution support SFTP (both sending and receiving file)?
Does solution support Data encryption/decryption?
Does solution support Data encryption/decryption?
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
Can the security module be integrated with Middleware to provide the security services? If yes, describe the mechanism?
Does your solution provide the CheckSum as data validation module?
Does your solution provide the CheckSum as data validation module?
CLIENT must have the ability to govern the data stored in cloud.
CLIENT must have the ability to govern the data stored in cloud.
CLOUD SERVICE PROVIDER (CSP) must have security policy, standard and procedure/guideline, which at least on the same level as CLIENT ISMS and must be uphold to protect CLIENT data from any security threats.
CLOUD SERVICE PROVIDER (CSP) must have security policy, standard and procedure/guideline, which at least on the same level as CLIENT ISMS and must be uphold to protect CLIENT data from any security threats.
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently? Are results communicated to clients? How often?
Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently? Are results communicated to clients? How often?
What arrangements are in place for return of data to customer upon contract conclusion or termination?
What arrangements are in place for return of data to customer upon contract conclusion or termination?
Can the service provider provide the latest copy of SOC 2 Type II report or equivalent?
Can the service provider provide the latest copy of SOC 2 Type II report or equivalent?
Provide information on your solutions/services BCP/DR.
Provide information on your solutions/services BCP/DR.
Please provide a copy of the incident management standard and procedures?
Please provide a copy of the incident management standard and procedures?
Has an independent security third party audit been completed on you? (If so, please name the auditing firm and last audit date in the comment box)
Has an independent security third party audit been completed on you? (If so, please name the auditing firm and last audit date in the comment box)
Do you take special measures to make sure the customer data is secure during the collection process? If so, describe the measures briefly.
Do you take special measures to make sure the customer data is secure during the collection process? If so, describe the measures briefly.
Have we implemented Email Gateway solution to block the SPAM emails? Have we implemented SPF/ DKIM/ DMARC effectively?
Have we implemented Email Gateway solution to block the SPAM emails? Have we implemented SPF/ DKIM/ DMARC effectively?
What is the password standard for the applications users, administrators, network users, etc. please describe in details. How are initial passwords communicated to users? Are all new users issued random initial passwords? Are users forced to change their password upon first logon? How is user's identity verified prior to resetting a password? What is the minimum password length? After how many days does a password expire? How many passwords are stored in the password history? What is the number of invalid password attempts prior to lockout? Can PINs or secret questions be used as a stand-alone method of authentication?
What is the password standard for the applications users, administrators, network users, etc. please describe in details. How are initial passwords communicated to users? Are all new users issued random initial passwords? Are users forced to change their password upon first logon? How is user's identity verified prior to resetting a password? What is the minimum password length? After how many days does a password expire? How many passwords are stored in the password history? What is the number of invalid password attempts prior to lockout? Can PINs or secret questions be used as a stand-alone method of authentication?
CSP ISO/IEC 27001/27002:2013 independent attestation, CSP ISO/IEC 27018:2014 independent attestation, CSP SOC 2 Type 2 independent attestation
CSP ISO/IEC 27001/27002:2013 independent attestation, CSP ISO/IEC 27018:2014 independent attestation, CSP SOC 2 Type 2 independent attestation
Will you notify FINCARE in case of any request to provide information, in the form of a subpoena, a warrant, or court order in which access to the FINCARE data is requested?
Will you notify FINCARE in case of any request to provide information, in the form of a subpoena, a warrant, or court order in which access to the FINCARE data is requested?
Do you include right to audit by consumer to your environment?
Do you include right to audit by consumer to your environment?
Will you make necessary audit logs and activity monitoring available when requested?
Will you make necessary audit logs and activity monitoring available when requested?
Do you encrypt sensitive data in PaaS applications and storage and sensitive volumes in IaaS
Do you encrypt sensitive data in PaaS applications and storage and sensitive volumes in IaaS
Do you have controls in place to prevent data leakage or intentional/accidental compromise between tenants in a multitenant environment?
Do you have controls in place to prevent data leakage or intentional/accidental compromise between tenants in a multitenant environment?
Does your data management policies and procedures address tenant and service level conflicts of interests?
Does your data management policies and procedures address tenant and service level conflicts of interests?
Can you demonstrate the data sovereignty and residency issues and provide details of jurisdiction of data storage and the local laws applicable?
Can you demonstrate the data sovereignty and residency issues and provide details of jurisdiction of data storage and the local laws applicable?
Are these datacenters are owned by you? If not, provide the details of the datacenter service provider
Are these datacenters are owned by you? If not, provide the details of the datacenter service provider
Datacenter security standard and procedure
Datacenter security standard and procedure
Third party assessment reports and attestations - ISO 27001, PCI DSS, etc
Third party assessment reports and attestations - ISO 27001, PCI DSS, etc
Any change to the design that impacts security posture of the system must be reviewed and approved by EIS Architecture Team, before a new component (e.g., custom built modules, 3rd party components, vendor supplied components) is released.
Any change to the design that impacts security posture of the system must be reviewed and approved by EIS Architecture Team, before a new component (e.g., custom built modules, 3rd party components, vendor supplied components) is released.
Minimum security standards and latest vendor security updates must be applied to all components. Wherever it is not supported or cannnot be applied, compensating controls must be evaluated with ISRA and implemented to reduce the risk.
Minimum security standards and latest vendor security updates must be applied to all components. Wherever it is not supported or cannnot be applied, compensating controls must be evaluated with ISRA and implemented to reduce the risk.
Project teams must maintain: Accurate (Create/Update/Delete) inventories of project components that are required for application to be up & running (including Production & Non-Production).
Project teams must maintain: Accurate (Create/Update/Delete) inventories of project components that are required for application to be up & running (including Production & Non-Production).
Implement version control practices (for Source code, binaries, container images) to govern development and provide auditing. Ensure versions are stored in a centralized repository, the change can be reversed/ rolled back during a security incident.
Implement version control practices (for Source code, binaries, container images) to govern development and provide auditing. Ensure versions are stored in a centralized repository, the change can be reversed/ rolled back during a security incident.
Applications should be architected with a minimum of three separate tiers: web, application, and storage/database.
Applications should be architected with a minimum of three separate tiers: web, application, and storage/database.
All remote system administrative functionality and remote access to an operating system (e.g., RDP, SSH, etc.) must be disabled and not directly accessible from the Internet, and only PSJH Information Security-approved remote access technologies are allowed.
All remote system administrative functionality and remote access to an operating system (e.g., RDP, SSH, etc.) must be disabled and not directly accessible from the Internet, and only PSJH Information Security-approved remote access technologies are allowed.
All public IP addresses must be removed from the subscription, except those that were coordinated with and approved by PSJH Cloud Engineering and Information Security Architecture.
All public IP addresses must be removed from the subscription, except those that were coordinated with and approved by PSJH Cloud Engineering and Information Security Architecture.
Access to the PaaS must be provisioned using PSJH IAM team, privileged access should be determined by business justification, and granted by IAM.
Access to the PaaS must be provisioned using PSJH IAM team, privileged access should be determined by business justification, and granted by IAM.
Ensure that all encryption and hashing methods comply with policies and organizational requirements for protection of information.
Ensure that all encryption and hashing methods comply with policies and organizational requirements for protection of information.
If Cryptographic keys have to be tranferred manually, then encrypted channels to be used Eg., use Secure Email of O365, ProofPoint Secure Email.
If Cryptographic keys have to be tranferred manually, then encrypted channels to be used Eg., use Secure Email of O365, ProofPoint Secure Email.
Ensure that the integrity of cryptographic key is protected while they are stored. Eg., use Hashing SHA256, Digital Signatures
Ensure that the integrity of cryptographic key is protected while they are stored. Eg., use Hashing SHA256, Digital Signatures
PHI, PII, and regulated or confidential data must use a minimum protocol of TLS 1.2, and an encryption algorithm and strength of AES-256 while in transit.
PHI, PII, and regulated or confidential data must use a minimum protocol of TLS 1.2, and an encryption algorithm and strength of AES-256 while in transit.
Application that handles PHI, PCI, PII (and other regulated data) must comply with applicable federal laws, Executive Orders, directives, policies, regulations.
Application that handles PHI, PCI, PII (and other regulated data) must comply with applicable federal laws, Executive Orders, directives, policies, regulations.
File-integrity monitoring tools should be in place to monitor modifications to critical system files, configuration files, and content files (leverage Crowdstrike as applicable).
File-integrity monitoring tools should be in place to monitor modifications to critical system files, configuration files, and content files (leverage Crowdstrike as applicable).
Application must ensure that the information used for authentication must be securely stored and transmitted in an encrypted form using algorithms in accordance to the Providence's information security policy.
Application must ensure that the information used for authentication must be securely stored and transmitted in an encrypted form using algorithms in accordance to the Providence's information security policy.
The application must be partitioned into public and restricted areas using separate folders for authenticated and non-authenticated users.
The application must be partitioned into public and restricted areas using separate folders for authenticated and non-authenticated users.
Mobile applications that are homegrown/ procured shall be released to caregivers via MDM & MAM solutions (such as Microsoft InTune).
Mobile applications that are homegrown/ procured shall be released to caregivers via MDM & MAM solutions (such as Microsoft InTune).
The mobile application must time out after 15 or fewer minutes of inactivity, requiring a user to re-enter a password, PIN, or re-initiate a biometric authentication mechanism before application content can be viewed again.
The mobile application must time out after 15 or fewer minutes of inactivity, requiring a user to re-enter a password, PIN, or re-initiate a biometric authentication mechanism before application content can be viewed again.
Code obfuscation is applied to native apps
Code obfuscation is applied to native apps
Roles must be assigned to manage updates on the server, resources, and/or other supporting assets.
Roles must be assigned to manage updates on the server, resources, and/or other supporting assets.
PSJH-managed EDR (running real-time scanning on a continuous basis) on the solution's servers, workstations, and/or other applicable devices is required.
PSJH-managed EDR (running real-time scanning on a continuous basis) on the solution's servers, workstations, and/or other applicable devices is required.
PSJH-managed host-based firewall client is required on the solution's servers, workstations, and/or other applicable devices.
PSJH-managed host-based firewall client is required on the solution's servers, workstations, and/or other applicable devices.
Ensure the user session is invalidated on the server-side when the user logs out.
Ensure the user session is invalidated on the server-side when the user logs out.
Implement REST and web services using session based authentication.
Implement REST and web services using session based authentication.
Require a standardized approach to structured exception and error handling across all layers.
Require a standardized approach to structured exception and error handling across all layers.
All input validation failures must result in input rejection and must be logged.
All input validation failures must result in input rejection and must be logged.
Product Owners must integrate compliance of security requirements in corresponding criteria in Definition of Done (DoD). Any requirement & recommendations provided by EIS that are not met by the application will need to have a security exception through ISRA
Product Owners must integrate compliance of security requirements in corresponding criteria in Definition of Done (DoD). Any requirement & recommendations provided by EIS that are not met by the application will need to have a security exception through ISRA
Implement generic error or notification messages in applications to limit information useful for attacks.
Implement generic error or notification messages in applications to limit information useful for attacks.
Manual input of file names and file paths must be avoided where possible.
Manual input of file names and file paths must be avoided where possible.
Vulnerabilities are to be identified, reported, and remediated through the software-development life cycle. Effective utilization of enterprise SAST, DAST, OSA, IaC Security, Penetration Testing etc., to be adopted throughout the lifecycle of system development (and periodically).
Vulnerabilities are to be identified, reported, and remediated through the software-development life cycle. Effective utilization of enterprise SAST, DAST, OSA, IaC Security, Penetration Testing etc., to be adopted throughout the lifecycle of system development (and periodically).
How do you handle data from Russia and China?
How do you handle data from Russia and China?
Description of your general Security concept including on how you handle Confidentiality, Integrity and Availability.
Description of your general Security concept including on how you handle Confidentiality, Integrity and Availability.
What are the security controls and restrictions implemented to control the upload, download, viewing and modification of Infosys data (including structured and unstructured data e.g. emails, databases etc.) by users within your organization, including admin users?
What are the security controls and restrictions implemented to control the upload, download, viewing and modification of Infosys data (including structured and unstructured data e.g. emails, databases etc.) by users within your organization, including admin users?
Specify the frequency of AV scans and list down the events/scenarios that triggers the scans
Specify the frequency of AV scans and list down the events/scenarios that triggers the scans
In a multi tenant model, please explain what controls are present to prevent infections spreading across to Infosys specific applications/infra from other tenants/customers sharing the same infrastructure?
In a multi tenant model, please explain what controls are present to prevent infections spreading across to Infosys specific applications/infra from other tenants/customers sharing the same infrastructure?
Have there been any information security breaches within the organization in the last 1 year (even if they did not impact Infosys)? If yes, please detail out the corrective and preventive actions taken by the organization to strengthen the information security program.
Have there been any information security breaches within the organization in the last 1 year (even if they did not impact Infosys)? If yes, please detail out the corrective and preventive actions taken by the organization to strengthen the information security program.
Provide details about the Information security framework and controls that are deployed within your organization to safeguard Infosys data and ensure compliance to applicable industry standards
Provide details about the Information security framework and controls that are deployed within your organization to safeguard Infosys data and ensure compliance to applicable industry standards
Is cyber security compliance review of application and risk assesement conducted atleast annually?
Is cyber security compliance review of application and risk assesement conducted atleast annually?
Are cyber security compliance review findings mitigated? Please highlight any open points.
Are cyber security compliance review findings mitigated? Please highlight any open points.
Are detected vulnerabilities patched timely?
Are detected vulnerabilities patched timely?
Is anti-malware and anti-virus installed on servers and development machines?
Is anti-malware and anti-virus installed on servers and development machines?
Is anti-malware and anti-virus updated regularly?
Is anti-malware and anti-virus updated regularly?
Is the code restricted from publicly available?
Is the code restricted from publicly available?
Is the application server are hardened for security and maintained?
Is the application server are hardened for security and maintained?
Is the database server comply with identity and access control policy?
Is the database server comply with identity and access control policy?
Is the database server comply with password policy?
Is the database server comply with password policy?
Is the database server have latest operating system, licensed and supported?
Is the database server have latest operating system, licensed and supported?
Is application server configuration is backed-up and can be restored within RPO and RTO?
Is application server configuration is backed-up and can be restored within RPO and RTO?
Is incidents are logged, investigated and reported timely?
Is incidents are logged, investigated and reported timely?
Explain the limitations to how the customer can use the service as outlined in the provider's acceptable usage policies, licensing rights or other providers usage restrictions.
Explain the limitations to how the customer can use the service as outlined in the provider's acceptable usage policies, licensing rights or other providers usage restrictions.
What advance notice will be provided by the provider for any change of terms?
What advance notice will be provided by the provider for any change of terms?
Does the contract/terms of service outline meaningful liability for the provider in the event that the the customer environment/data is breached?
Does the contract/terms of service outline meaningful liability for the provider in the event that the the customer environment/data is breached?
Does the provider have an active SLA in place that identifies minimum performance (e.g., uptime, etc.)?
Does the provider have an active SLA in place that identifies minimum performance (e.g., uptime, etc.)?
Describe the SLA
Describe the SLA
Does the provider provide regular service management reports (e.g., SLA performance)? If so, state the frequency of such reporting.
Does the provider provide regular service management reports (e.g., SLA performance)? If so, state the frequency of such reporting.
Describe penalties associated with SLA non-compliance.
Describe penalties associated with SLA non-compliance.
Does the provider monitor service continuity with upstream providers in the event of provider failure?
Does the provider monitor service continuity with upstream providers in the event of provider failure?
Do we have the planed downtime scheduled (e.g., service, upgrade, patch, etc.)?
Do we have the planed downtime scheduled (e.g., service, upgrade, patch, etc.)?
Are the same security controls implemented at the failover site as that of primary site?
Are the same security controls implemented at the failover site as that of primary site?
Are the provider's routine maintenance windows manageable for the customer?
Are the provider's routine maintenance windows manageable for the customer?
Describe the process to terminate the service
Describe the process to terminate the service
Can the customer data and the service be moved/transferred to another provider at any time?
Can the customer data and the service be moved/transferred to another provider at any time?
Does the customer have the right to terminate if the provider introduces material modifications to service terms?
Does the customer have the right to terminate if the provider introduces material modifications to service terms?
What standards does the provider follow for application development? Do these include rigorous testing and acceptance protocols?
What standards does the provider follow for application development? Do these include rigorous testing and acceptance protocols?
Where and how will the customer data be stored? Are there impacts on security in light of the differences in legal/regulatory compliance requirements depending on storage location?
Where and how will the customer data be stored? Are there impacts on security in light of the differences in legal/regulatory compliance requirements depending on storage location?
Does the provider have a cyber plan in place? If so, please provide details.
Does the provider have a cyber plan in place? If so, please provide details.
Have there been any major security incident(s) reported with the provider in the last two years? If so, detail the incident(s) and resolution(s)
Have there been any major security incident(s) reported with the provider in the last two years? If so, detail the incident(s) and resolution(s)
What activities are logged by the provider? Consider: Network traffic, file and server access, Security systems
What activities are logged by the provider? Consider: Network traffic, file and server access, Security systems
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants? (2)
Does the provider's logging and monitoring framework allow isolation of an incident to specific tenants? (2)
Who can set up activities to be logged?
Who can set up activities to be logged?
What is the provider's incident response procedure for handling a security or data breach?
What is the provider's incident response procedure for handling a security or data breach?
Does the provider's incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
Does the provider's incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
When are audits conducted (i.e., frequency)? What standard/certification is used to conduct audits (e.g., ISO 27001, SSAE 16 SOC 2, etc.)? Will the customer receive a copy of the audit report when finalized? Is this requirement outlined in the contract with the service provider?
When are audits conducted (i.e., frequency)? What standard/certification is used to conduct audits (e.g., ISO 27001, SSAE 16 SOC 2, etc.)? Will the customer receive a copy of the audit report when finalized? Is this requirement outlined in the contract with the service provider?
