Do you enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems?
Do you enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems?
Do you retain logs for all login attempts for a given time period or as required by the tenant?
Do you retain logs for all login attempts for a given time period or as required by the tenant?
Does the solution provide re-authentication at the time of an attempted change to authentication information?
Does the solution provide re-authentication at the time of an attempted change to authentication information?
Can you provide the capability to present with a login notice to the intended users before being given the opportunity to log onto a system?
Can you provide the capability to present with a login notice to the intended users before being given the opportunity to log onto a system?
Do you have controls in place to restrict any information beyond notification of an unsuccessful login attempt prior to successful login?
Do you have controls in place to restrict any information beyond notification of an unsuccessful login attempt prior to successful login?
Do you support use of, or integration with, existing customer-based Single Sign On (SSO) solutions to your service?
Do you support use of, or integration with, existing customer-based Single Sign On (SSO) solutions to your service?
What levels of isolation are used for virtual machines, physical machines, network, storage (e.g., storage area networks), management networks and management support systems, etc.?
What levels of isolation are used for virtual machines, physical machines, network, storage (e.g., storage area networks), management networks and management support systems, etc.?
Do you allow tenants to use third-party identity assurance services?
Do you allow tenants to use third-party identity assurance services?
Do you support tenant's access review policy?
Do you support tenant's access review policy?
Do you support password (minimum length, age, history, complexity, and expiration) and account lockout (lockout threshold, lockout duration) policy enforcement?
Do you support password (minimum length, age, history, complexity, and expiration) and account lockout (lockout threshold, lockout duration) policy enforcement?
Do you allow tenants/customers to define password and account lockout policies for their accounts?
Do you allow tenants/customers to define password and account lockout policies for their accounts?
Do you support the ability to force password changes upon first login?
Do you support the ability to force password changes upon first login?
Do you have mechanisms in place for unlocking accounts that have been locked out (e.g., self-service via email, defined challenge questions, manual unlock)?
Do you have mechanisms in place for unlocking accounts that have been locked out (e.g., self-service via email, defined challenge questions, manual unlock)?
Are audit logs reviewed on a regular basis for security events (e.g., with automated tools)?
Are audit logs reviewed on a regular basis for security events (e.g., with automated tools)?
Do you support the integration of audit logs with tenant Security Operations/SIEM (Security Information and Event Management) solution?
Do you support the integration of audit logs with tenant Security Operations/SIEM (Security Information and Event Management) solution?
Are audit logs centrally stored and retained?
Are audit logs centrally stored and retained?
Describe how event logs are protected from alteration including how access to these logs is controlled.
Describe how event logs are protected from alteration including how access to these logs is controlled.
Are file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation by root cause analysis, and response to incidents?
Are file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation by root cause analysis, and response to incidents?
Describe the process for investigating all data breaches and security violation events. Describe the process for informing TCCC of the breach, root cause analysis, and remediation.
Describe the process for investigating all data breaches and security violation events. Describe the process for informing TCCC of the breach, root cause analysis, and remediation.
Does your logging and monitoring framework allow isolation of an incident to specific tenants?
Does your logging and monitoring framework allow isolation of an incident to specific tenants?
Are policies and procedures established and measures implemented to strictly limit access to your sensitive data and tenant data from portable and mobile devices (e.g., laptops, cell phones, and personal digital assistants (PDAs)), which are generally higher-risk than non-portable devices (e.g., desktop computers at the provider organization's facilities)?
Are policies and procedures established and measures implemented to strictly limit access to your sensitive data and tenant data from portable and mobile devices (e.g., laptops, cell phones, and personal digital assistants (PDAs)), which are generally higher-risk than non-portable devices (e.g., desktop computers at the provider organization's facilities)?
Does the solution support disabling of dormant accounts (User accounts that have not been used within a minimum of 90 days)?
Does the solution support disabling of dormant accounts (User accounts that have not been used within a minimum of 90 days)?
Does the solution maintain a password history technique in order to disallow use of any cyclic passwords?
Does the solution maintain a password history technique in order to disallow use of any cyclic passwords?
Is there an approval process for access requests to systems handling personal data?
Is there an approval process for access requests to systems handling personal data?
Is access to systems containing personal data granted using a role-based criteria?
Is access to systems containing personal data granted using a role-based criteria?
Is all Personal Data registered in a standard repository?
Is all Personal Data registered in a standard repository?
Are credentials stored in a centralized system that is TCCC approved?
Are credentials stored in a centralized system that is TCCC approved?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?
Do you support tenant's multifactor authentication (e.g., RSA Secure ID, PKI Certificates, out of band pin comprised of at least 6 digits, etc.)?
Do you support tenant's multifactor authentication (e.g., RSA Secure ID, PKI Certificates, out of band pin comprised of at least 6 digits, etc.)?
Do you support access to tenant-sensitive data by only tenant's managed devices?
Do you support access to tenant-sensitive data by only tenant's managed devices?
Do you have a formal process to manage the termination and or transfer of employees? i.e. All equipment is returned, user ID's disabled in systems, Windows, badges, and/or keys returned. On Transfer is existing access reviewed for relevance?
Do you have a formal process to manage the termination and or transfer of employees? i.e. All equipment is returned, user ID's disabled in systems, Windows, badges, and/or keys returned. On Transfer is existing access reviewed for relevance?
Are employees required to use a VPN when accessing the organization's systems from all remote locations?
Are employees required to use a VPN when accessing the organization's systems from all remote locations?
Is a security operations center implemented to monitor the software solution?
Is a security operations center implemented to monitor the software solution?
Are employees required to use a VPN when accessing the organisation's systems from all remote locations? (2)
Are employees required to use a VPN when accessing the organisation's systems from all remote locations? (2)
Is wireless access allowed in your organisation?
Is wireless access allowed in your organisation?
Is there a role based access control & structured process for creation of new user account for the customer operations? Are all users identified to the system by a unique User ID?
Is there a role based access control & structured process for creation of new user account for the customer operations? Are all users identified to the system by a unique User ID?
Is there a well-defined process for removing the user account and access rights at the time of an employee leaving the vendors the customer processing facility?
Is there a well-defined process for removing the user account and access rights at the time of an employee leaving the vendors the customer processing facility?
Is there a periodic audit of the user access profile by the SPOC / system administrator?
Is there a periodic audit of the user access profile by the SPOC / system administrator?
Is there an automatic lockout for predefined number of unsuccessful attempts?
Is there an automatic lockout for predefined number of unsuccessful attempts?
Are different accounts used for applications and OS level access?
Are different accounts used for applications and OS level access?
Does the system prompt the change of user passwords at predefined intervals?
Does the system prompt the change of user passwords at predefined intervals?
How does the password reset process work? Is a secure password distribution mechanism in place?
How does the password reset process work? Is a secure password distribution mechanism in place?
Is there a defined process for installing & encrypting wireless access points, if any used by vendor?
Is there a defined process for installing & encrypting wireless access points, if any used by vendor?
Is an inventory of all information assets (e.g. documents, USB devices, passwords etc) provided to employees tracked? Is the return of assets tracked?
Is an inventory of all information assets (e.g. documents, USB devices, passwords etc) provided to employees tracked? Is the return of assets tracked?
Is there a mechanism for different levels of administrator privileges for system access on the customer specific servers? Is it configured in a secure manner?
Is there a mechanism for different levels of administrator privileges for system access on the customer specific servers? Is it configured in a secure manner?
Is inactivity timeout period specified for the customer applications?
Is inactivity timeout period specified for the customer applications?
Is development area segregated from work area? Are proper access controls implemented for development areas?
Is development area segregated from work area? Are proper access controls implemented for development areas?
Are all production hardware, including, but not limited to, network devices, storage, database servers, and application equipment, located in a restricted area with physical access controls?
Are all production hardware, including, but not limited to, network devices, storage, database servers, and application equipment, located in a restricted area with physical access controls?
Groups of information services, users and information systems shall be segregated on networks.
Groups of information services, users and information systems shall be segregated on networks.
a) Whether Desktop/ Laptop sharing is allowed? b) Whether data card is accessible on desktop/ laptop? c) Whether software installation permissions present on desktop/ laptop?
a) Whether Desktop/ Laptop sharing is allowed? b) Whether data card is accessible on desktop/ laptop? c) Whether software installation permissions present on desktop/ laptop?
How vendor is performing logging and monitoring of privilege access (if any) at Cloud environment?
How vendor is performing logging and monitoring of privilege access (if any) at Cloud environment?
By any mean, does the vendor/ CSP having access to the customer data? For what purpose?
By any mean, does the vendor/ CSP having access to the customer data? For what purpose?
Are external drives such as CDs and USB drives disabled on all desktops and laptops, servers containing personal data, customer data, business data?
Are external drives such as CDs and USB drives disabled on all desktops and laptops, servers containing personal data, customer data, business data?
Are photographic, video, audio or other recording equipment, such as cameras in mobile restricted to be carried inside secure areas/ work areas/ information processing facilities? Are vacant secure areas physically locked and periodically reviewed?
Are photographic, video, audio or other recording equipment, such as cameras in mobile restricted to be carried inside secure areas/ work areas/ information processing facilities? Are vacant secure areas physically locked and periodically reviewed?
Are procedures defined and followed for employees for removal of all access rights (Logical Access and Physical Access) provided to them during course of employment?
Are procedures defined and followed for employees for removal of all access rights (Logical Access and Physical Access) provided to them during course of employment?
Are the system utility programs that could be used to override system and application controls strictly controlled and their use restricted and that admin privileges are not assigned to all users?
Are the system utility programs that could be used to override system and application controls strictly controlled and their use restricted and that admin privileges are not assigned to all users?
Are there documented procedures in place regarding steps to be followed for voluntary and involuntary employee terminations (unnecessary user entitlements) including access revocations? Are cases of voluntary or involuntary terminations addressed immediately and access is revoked immediately? Do you agree to inform BSLI incase of any involuntary termination of an employee working on client account immediately or within a reasonable timeframe incase of voluntary termination or reassignment of staff member?
Are there documented procedures in place regarding steps to be followed for voluntary and involuntary employee terminations (unnecessary user entitlements) including access revocations? Are cases of voluntary or involuntary terminations addressed immediately and access is revoked immediately? Do you agree to inform BSLI incase of any involuntary termination of an employee working on client account immediately or within a reasonable timeframe incase of voluntary termination or reassignment of staff member?
Are user access provisions monitored and reviewed on an ongoing basis (Access reconciliation review) to ensure additions, deletions and changes to the accounts and access rights are properly tracked?
Are user access provisions monitored and reviewed on an ongoing basis (Access reconciliation review) to ensure additions, deletions and changes to the accounts and access rights are properly tracked?
Are Users Handling BSLI data given access to Corporate / Public Mails? If Yes, Are there any restrictions on domains to which the mails can be sent?
Are Users Handling BSLI data given access to Corporate / Public Mails? If Yes, Are there any restrictions on domains to which the mails can be sent?
Are users handling BSLI data provided access to Internet? Is there a Proxy / Content Filtering Solution in place for cotrolled access to Internet? Are Proxy / Content Filtering Solution logs monitored and reviewed?
Are users handling BSLI data provided access to Internet? Is there a Proxy / Content Filtering Solution in place for cotrolled access to Internet? Are Proxy / Content Filtering Solution logs monitored and reviewed?
Do you have a documented procedure in place for user access management? Whether access to system and data is granted exclusively on a need to know/access and Principle of Least privilege and that the approvals are documented by accountable party?
Do you have a documented procedure in place for user access management? Whether access to system and data is granted exclusively on a need to know/access and Principle of Least privilege and that the approvals are documented by accountable party?
Does patch management process ensure all system are installed with latest security patches (OS layer, Application layer, Data base layer, Network layer)? Do you have a formal vulnerability assessment and penetration testing (VAPT) process / procedure / policy / manual is documented and operational? Do you have security hardening (technical specification, minimum baseline security MBSS guidelines for all infrastructure elements such as Application, OS, Network and Database)? Are external drives such as CDs and USB drives disabled on all desktops and laptops, servers containing personal data, customer data, business data?
Does patch management process ensure all system are installed with latest security patches (OS layer, Application layer, Data base layer, Network layer)? Do you have a formal vulnerability assessment and penetration testing (VAPT) process / procedure / policy / manual is documented and operational? Do you have security hardening (technical specification, minimum baseline security MBSS guidelines for all infrastructure elements such as Application, OS, Network and Database)? Are external drives such as CDs and USB drives disabled on all desktops and laptops, servers containing personal data, customer data, business data?
Have you deployed controls to protect computer systems against virus and spywares, malwares, Trojans, malicious codes, etc.? Do you log the Anti-Virus compliance status of all systems?
Have you deployed controls to protect computer systems against virus and spywares, malwares, Trojans, malicious codes, etc.? Do you log the Anti-Virus compliance status of all systems?
Does the Vendor support on-premise / in the Cloud Third Party Cloud Access Security Broker (CASB) services
Does the Vendor support on-premise / in the Cloud Third Party Cloud Access Security Broker (CASB) services
Ability to have clearly defined roles with fine grained accesses to be created as per Functional roles and maintain SoD when creating the same
Ability to have clearly defined roles with fine grained accesses to be created as per Functional roles and maintain SoD when creating the same
Ability to rename / disable default IDs within application
Ability to rename / disable default IDs within application
Data Confidentiality is compromised (Misuse of the customer Policyholder / Employee information, leakage of critical customer personal / policy details resulting in financial or reputational loss for the customer)
Data Confidentiality is compromised (Misuse of the customer Policyholder / Employee information, leakage of critical customer personal / policy details resulting in financial or reputational loss for the customer)
Describe the mechanisms in place (processes, tools, etc.) to check for vulnerabilities at the application, Operating System, middleware and the network layers both internally and externally and how frequently these controls are performed.
Describe the mechanisms in place (processes, tools, etc.) to check for vulnerabilities at the application, Operating System, middleware and the network layers both internally and externally and how frequently these controls are performed.
Describe the Access management process in place at the provider's end pointing out how you ensure timely removal of accesses that are no longer required and how you control the adequacy of the privileges to the job role. Also describe the revalidation processes and the frequency of its execution.
Describe the Access management process in place at the provider's end pointing out how you ensure timely removal of accesses that are no longer required and how you control the adequacy of the privileges to the job role. Also describe the revalidation processes and the frequency of its execution.
Describe the process to ensure and monitor that Segregation of Duties is respected and how frequently it is controlled
Describe the process to ensure and monitor that Segregation of Duties is respected and how frequently it is controlled
Do employees have a unique log-in ID when accessing data?
Do employees have a unique log-in ID when accessing data?
Are employees required to use a VPN when accessing the organisation's systems from all remote locations? (3)
Are employees required to use a VPN when accessing the organisation's systems from all remote locations? (3)
Does your organisation provide any web applications used by the customer or containing the customer data?
Does your organisation provide any web applications used by the customer or containing the customer data?
Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?
Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?
If an employee no longer requires remote access to the customer network, is there a process to inform the the customer in a timely manner to revoke access?
If an employee no longer requires remote access to the customer network, is there a process to inform the the customer in a timely manner to revoke access?
In case of any exceptions due to which anti-malware activities fail (e.g. antivirus scans cannot be conducted or patches cannot not be applied), are alternative controls implemented to reduce the exposure on remote endpoints?
In case of any exceptions due to which anti-malware activities fail (e.g. antivirus scans cannot be conducted or patches cannot not be applied), are alternative controls implemented to reduce the exposure on remote endpoints?
Do fourth-parties, (e.g., subcontractors, sub-processors, sub-service organizations) have access to or process client scoped data?
Do fourth-parties, (e.g., subcontractors, sub-processors, sub-service organizations) have access to or process client scoped data?
Is proper access control implemented for secure access to the customer data?
Is proper access control implemented for secure access to the customer data?
Are there necessary controls for securing sensitive information according to the data classification (like Identity access management, access rights)?
Are there necessary controls for securing sensitive information according to the data classification (like Identity access management, access rights)?
Do you have a SIEM for monitoring and maintaining logs over security incidents from various components (e.g. IDS, IPS, firewall logs)?
Do you have a SIEM for monitoring and maintaining logs over security incidents from various components (e.g. IDS, IPS, firewall logs)?
Will vendor employees be accessing any the customer application? How access to those applications is managed? (e.g. through SSO).
Will vendor employees be accessing any the customer application? How access to those applications is managed? (e.g. through SSO).
Are vendor Employees who are associated with the customer process are using their official email IDs for communication with the customer?
Are vendor Employees who are associated with the customer process are using their official email IDs for communication with the customer?
Who will have access to the customer users / customers data in your organization and if any Access Control (Role Base Access Control or any other) is imposed on server / database where the customer users / customers data will be stored?
Who will have access to the customer users / customers data in your organization and if any Access Control (Role Base Access Control or any other) is imposed on server / database where the customer users / customers data will be stored?
Supplier applies security controls and measures on remote access.
Supplier applies security controls and measures on remote access.
Supplier has a security monitoring process in place.
Supplier has a security monitoring process in place.
The solution provides possibilities for identity integration with the customer Microsoft Azure AD, and supports Single Sign On (SSO). SSO may be achieved either through a SAML 2.0 federated trust setup or through Microsoft Azure SaaS integration. Additional factors may be used in authentication as well (MFA).
The solution provides possibilities for identity integration with the customer Microsoft Azure AD, and supports Single Sign On (SSO). SSO may be achieved either through a SAML 2.0 federated trust setup or through Microsoft Azure SaaS integration. Additional factors may be used in authentication as well (MFA).
- Xoxoday application has a rich set of integrations with HRMS, HRIS, CRM, Survey, Marketing automation, SSO, SAML tools like SAP SuccessFactors, Zoho People, Darwin Box, Hubspot, Freshworks, Zapier, Hubspot, Type Form, Survey Monkey, Survey Gizmo, SAML 2.0, etc 2. SSO SSO Redirection - The client has to generate temporary token for SSO and redirect the user to Xoxoday with this temporary token. Please click here - https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints/sso-redirection#sso-token-from-company-session
Vendor has privileged identity and access management policies in place, by ensuring that there are multiple access layers and requiring multi-factor authentication for superuser/administrator access.
Vendor has privileged identity and access management policies in place, by ensuring that there are multiple access layers and requiring multi-factor authentication for superuser/administrator access.
Privileged accounts are terminated when not required for use, and this process ensures that the change is propagated throughout the services provided to the customer.
Privileged accounts are terminated when not required for use, and this process ensures that the change is propagated throughout the services provided to the customer.
Whenever user access to the customer data is to be maintained by the vendor, access to the customer services is provided on a need-to-have basis and according to users' roles (RBAC) and by notifying the customer in advance. Access rights are continuously reviewed.
Whenever user access to the customer data is to be maintained by the vendor, access to the customer services is provided on a need-to-have basis and according to users' roles (RBAC) and by notifying the customer in advance. Access rights are continuously reviewed.
Roles and responsibilities of the customer as a customer are clearly specified in the incident handling process.
Roles and responsibilities of the customer as a customer are clearly specified in the incident handling process.
Which security protocols and standards do the cloud vendor adhere to?
Which security protocols and standards do the cloud vendor adhere to?
Does the solution supports role based access control to enable separation of duties
Does the solution supports role based access control to enable separation of duties
Is there a Web UI available? What browsers are supported?
Is there a Web UI available? What browsers are supported?
Access Control - Is there an access control mechanism like RBAC built in the application?
Access Control - Is there an access control mechanism like RBAC built in the application?
Does the application support for SCIM based automated User Provisioning and Deprovisioning?
Does the application support for SCIM based automated User Provisioning and Deprovisioning?
Does the application support AD Integration?
Does the application support AD Integration?
Does the application allow users to set/reset password and login with password even when SSO is enabled?
Does the application allow users to set/reset password and login with password even when SSO is enabled?
Access to data by your employees:
Access to data by your employees:
What is the set of security configuration / features implemented for standard employee issued device? (full disk encryption, firewall, etc.)
What is the set of security configuration / features implemented for standard employee issued device? (full disk encryption, firewall, etc.)
Does the company allow its employees to work remotely? If so:
Does the company allow its employees to work remotely? If so:
How do you secure your APIs? Which methodology is followed for API security and its testing?
How do you secure your APIs? Which methodology is followed for API security and its testing?
Does the platform support SSO with PwC Indentity
Does the platform support SSO with PwC Indentity
Authentication requirements - what is the software. PwC uses SAML 2.0, OpenAm authentication
Authentication requirements - what is the software. PwC uses SAML 2.0, OpenAm authentication
Products should support user directory integration via LDAP or Microsoft Active Directory to simplify the user provisioning process
Products should support user directory integration via LDAP or Microsoft Active Directory to simplify the user provisioning process
Is Multi-Factor Authentication supported?
Is Multi-Factor Authentication supported?
Does this mean they do not store passwords hashed?
Does this mean they do not store passwords hashed?
Is 2FA required when logging in? If required, which types of 2FA are supported? (E.g. Google Authenticator?)
Is 2FA required when logging in? If required, which types of 2FA are supported? (E.g. Google Authenticator?)
Is SSO and OKTA integration supported?
Is SSO and OKTA integration supported?
Is there detection for concurrent logins? When there is multiple logins using the same username, do account holders have awareness of this?
Is there detection for concurrent logins? When there is multiple logins using the same username, do account holders have awareness of this?
How long will the account be invalid when it is deleted? After how long will the user be kicked off when logged in, if his/her account has been deleted?
How long will the account be invalid when it is deleted? After how long will the user be kicked off when logged in, if his/her account has been deleted?
For customer support, what is the process for password reset? Could you identify correctly if the requestor is from our company? How?
For customer support, what is the process for password reset? Could you identify correctly if the requestor is from our company? How?
For customer support, what is the process for 2FA reset? Could you identify correctly if the requestor is from our company? How?
For customer support, what is the process for 2FA reset? Could you identify correctly if the requestor is from our company? How?
Does the account management system support role-based permissions and access control?
Does the account management system support role-based permissions and access control?
When Okta/SSO is enabled, whether the login method for the original system is technically prohibited?
When Okta/SSO is enabled, whether the login method for the original system is technically prohibited?
When only enabling username and password login, is it possible to customize password complexity requirements (upper case, lower case, special character)? Also, is it possible to force users to change their password at regular intervals - every 90 days for example.
When only enabling username and password login, is it possible to customize password complexity requirements (upper case, lower case, special character)? Also, is it possible to force users to change their password at regular intervals - every 90 days for example.
Multi factor authentication shall be implemented for all access to NSE's data.
Multi factor authentication shall be implemented for all access to NSE's data.
All access to NSE's data, managed by NSE shall be as per the Access Control policy of NSE.
All access to NSE's data, managed by NSE shall be as per the Access Control policy of NSE.
NSE shall ensure all web applications are accessible only via Web Application Firewall (WAF) to the internet with appropriate policies.
NSE shall ensure all web applications are accessible only via Web Application Firewall (WAF) to the internet with appropriate policies.
Describe the controls in place that monitor and record user access to systems that store or support UP data.
Describe the controls in place that monitor and record user access to systems that store or support UP data.
Does the Supplier support SAML 2 (Browser POST profile) to enable Single Sign-On for Union Pacific users?
Does the Supplier support SAML 2 (Browser POST profile) to enable Single Sign-On for Union Pacific users?
Describe how your organization decides who does and does not have access to sensitive data
Describe how your organization decides who does and does not have access to sensitive data
Do employees/contractors have ability to remotely connect to your production systems? (i.e. VPN)
Do employees/contractors have ability to remotely connect to your production systems? (i.e. VPN)
Is MFA required for employees/contractors to log in to production systems?
Is MFA required for employees/contractors to log in to production systems?
Do internal applications leverage SSO for authentication?
Do internal applications leverage SSO for authentication?
Are documented procedures followed to govern change in employment and/or termination including for timely revocation of access and return of assets?
Are documented procedures followed to govern change in employment and/or termination including for timely revocation of access and return of assets?
Is all network traffic over public networks to the production infrastructure sent over cryptographically sound encrypted connections? (TLS, VPN, IPSEC, etc). If there are plaintext connections, what is sent unencrypted?
Is all network traffic over public networks to the production infrastructure sent over cryptographically sound encrypted connections? (TLS, VPN, IPSEC, etc). If there are plaintext connections, what is sent unencrypted?
What cryptographic frameworks are used to secure data at rest?
What cryptographic frameworks are used to secure data at rest?
What cryptographic frameworks are used to store passwords?
What cryptographic frameworks are used to store passwords?
How are crytographic keys(key management system, etc) managed within your system?
How are crytographic keys(key management system, etc) managed within your system?
Does application allow user MFA to be enforced by admins?
Does application allow user MFA to be enforced by admins?
Does application support IP whitelisting for user authentication?
Does application support IP whitelisting for user authentication?
Does your application support standardized roles and permissions for users (ie admin, user)?
Does your application support standardized roles and permissions for users (ie admin, user)?
Does your application enable custom granular permissions and roles to be created?
Does your application enable custom granular permissions and roles to be created?
How does your application store API keys?
How does your application store API keys?
Are your confidential data acess controls in line with your data classification matrix?
Are your confidential data acess controls in line with your data classification matrix?
Are user/ privileged access rights for your staff regularly reviewed?
Are user/ privileged access rights for your staff regularly reviewed?
Will the customer staff be able to manage the customer system access and data? If so what controls are in place to restrict and control privileged access rights?
Will the customer staff be able to manage the customer system access and data? If so what controls are in place to restrict and control privileged access rights?
Please state what system enforced password settings are active for: Password Minimum Length/Complexity, Password Change Interval, Lockout (after incorrect password entries), Password aging/history
Please state what system enforced password settings are active for: Password Minimum Length/Complexity, Password Change Interval, Lockout (after incorrect password entries), Password aging/history
Have all default passwords been changed in regard to hardware identified in the architectural details section in 3.5?
Have all default passwords been changed in regard to hardware identified in the architectural details section in 3.5?
How long will logs be retained?
How long will logs be retained?
All users shall be assigned a unique ID (user account) for access to system components, information or network files or sensitive data following clear user naming convention standards.
All users shall be assigned a unique ID (user account) for access to system components, information or network files or sensitive data following clear user naming convention standards.
User accounts shall keep historical uniqueness and will not be reused by other people in the future.
User accounts shall keep historical uniqueness and will not be reused by other people in the future.
Centralised directory services shall be provided for the customer systems, where applicable, to effectively manage the users and computers.
Centralised directory services shall be provided for the customer systems, where applicable, to effectively manage the users and computers.
Ensure that all privileged access is logged and periodically audited
Ensure that all privileged access is logged and periodically audited
Where technically feasible implement network and/or host-based technical controls that detect access and/or attempt to use diagnostic and configuration ports and services.
Where technically feasible implement network and/or host-based technical controls that detect access and/or attempt to use diagnostic and configuration ports and services.
Role-based user accounts shall be implemented for users (operators, supervisors, shift controller, engineer, domain administrator etc.) with specific and defined privileges based on the principle of least privilege for each role.
Role-based user accounts shall be implemented for users (operators, supervisors, shift controller, engineer, domain administrator etc.) with specific and defined privileges based on the principle of least privilege for each role.
Access to programming source code shall be granted on need to know basis.
Access to programming source code shall be granted on need to know basis.
Remote access shall be granted based on business need and approved by Information owner.
Remote access shall be granted based on business need and approved by Information owner.
Multi factor authentication should be used, where technically feasible, for all remote access (network-level access originating from internet) by employees, Administrators and third parties.
Multi factor authentication should be used, where technically feasible, for all remote access (network-level access originating from internet) by employees, Administrators and third parties.
Access for vendors for remote maintenance or support must only be enabled during a limited time period and should be discontinued immediately after the task is completed. Vendors' access shall be auditable.
Access for vendors for remote maintenance or support must only be enabled during a limited time period and should be discontinued immediately after the task is completed. Vendors' access shall be auditable.
Remote access activities shall be logged, monitored and analysed.
Remote access activities shall be logged, monitored and analysed.
Third Parties are only granted logical access after verification that any contract or agreement with third parties addresses all aspects of the the customer information security requirements regarding accessing, processing, communicating or managing the the customer information or information systems, or adding products or services to information systems.
Third Parties are only granted logical access after verification that any contract or agreement with third parties addresses all aspects of the the customer information security requirements regarding accessing, processing, communicating or managing the the customer information or information systems, or adding products or services to information systems.
All unnecessary ports, services and applications that are not required for normal operations have been disabled or uninstalled, following the least functionality principle.
All unnecessary ports, services and applications that are not required for normal operations have been disabled or uninstalled, following the least functionality principle.
If additional security controls are required within a security zone, a sub-security zone should be created (e.g. different vendors or systems might require limited data access between production areas).
If additional security controls are required within a security zone, a sub-security zone should be created (e.g. different vendors or systems might require limited data access between production areas).
Document network services (e.g. provision of optical fibre connections between sites), whether these services are provided in-house or outsourced, management requirements, service levels, and needed security mechanisms.
Document network services (e.g. provision of optical fibre connections between sites), whether these services are provided in-house or outsourced, management requirements, service levels, and needed security mechanisms.
Configuration baselines should ensure that components are configured to the most restrictive mode consistent with technical and entity operational requirements.
Configuration baselines should ensure that components are configured to the most restrictive mode consistent with technical and entity operational requirements.
All software and functionality not required for the intended functional purpose of the system shall be disabled or uninstalled.
All software and functionality not required for the intended functional purpose of the system shall be disabled or uninstalled.
Auto-play of audio CD/DVD and USB drives shall be disabled on all systems.
Auto-play of audio CD/DVD and USB drives shall be disabled on all systems.
As a minimum, contracts with third parties for provision of third parties with access to the customer information assets shall include (but not be limited to) confidentiality, non-disclosure and the customer security policies compliance clauses. Following requirements must be consider: The level of physical and logical security controls that shall be provided to maintain the confidentiality, integrity and availability of the customer information assets. Provision for confidentiality, non-disclosure and acceptable use relating to the customer information assets managed by the outsourced function or service. The customer rights to review, monitor and audit compliance with the security terms of contract
As a minimum, contracts with third parties for provision of third parties with access to the customer information assets shall include (but not be limited to) confidentiality, non-disclosure and the customer security policies compliance clauses. Following requirements must be consider: The level of physical and logical security controls that shall be provided to maintain the confidentiality, integrity and availability of the customer information assets. Provision for confidentiality, non-disclosure and acceptable use relating to the customer information assets managed by the outsourced function or service. The customer rights to review, monitor and audit compliance with the security terms of contract
Service Provider shall use two-factor authentication for administrative activities.
Service Provider shall use two-factor authentication for administrative activities.
Infrastructure components such as network devices, servers, workstations should be hardened based on least functionality and least privilege perspective
Infrastructure components such as network devices, servers, workstations should be hardened based on least functionality and least privilege perspective
Is the communication between client and server encrypted in order to prevent eavesdropping, man in the middle or similar attacks?
Is the communication between client and server encrypted in order to prevent eavesdropping, man in the middle or similar attacks?
Does the infrastructure provide mechanisms for access control lists or capabilities?
Does the infrastructure provide mechanisms for access control lists or capabilities?
How does the vendor control and monitor access to customer's data by their administrators?
How does the vendor control and monitor access to customer's data by their administrators?
Is SSO provided out of box?
Is SSO provided out of box?
What type of SSO options are available? SAML, HTTP-Fed etc.
What type of SSO options are available? SAML, HTTP-Fed etc.
What other type of user authentication options do you provide?
What other type of user authentication options do you provide?
Integration to TSL It Systems
Integration to TSL It Systems
Will any detected security violations and incidents be reported to the X Company Information Security Manager?
Will any detected security violations and incidents be reported to the X Company Information Security Manager?
Explain how the system supports single sign-on and an external roles based access control system.
Explain how the system supports single sign-on and an external roles based access control system.
Does a list of accepted mobile devices (e.g., smart phones, cell phones) exist based on testing? Are accepted mobile devices tested prior to production use?
Does a list of accepted mobile devices (e.g., smart phones, cell phones) exist based on testing? Are accepted mobile devices tested prior to production use?
Is sensitive information (e.g., opportunities and sales contracts) removed from, or encrypted within, documents and or websites before it is distributed? i.e. de-identifying of sensitive information prior to being distributed.
Is sensitive information (e.g., opportunities and sales contracts) removed from, or encrypted within, documents and or websites before it is distributed? i.e. de-identifying of sensitive information prior to being distributed.
Is software installation restricted for desktops, laptops and servers? i.e. Restricted User access to workstations, Group Policy enforcement, AD privileges on servers
Is software installation restricted for desktops, laptops and servers? i.e. Restricted User access to workstations, Group Policy enforcement, AD privileges on servers
Will vendor employees be accessing any the customer application? How access to those applications is managed? (e.g. through SSO). (2)
Will vendor employees be accessing any the customer application? How access to those applications is managed? (e.g. through SSO). (2)
Are vendor Employees who are associated with the customer process are using their official email IDs for communication with the customer? (2)
Are vendor Employees who are associated with the customer process are using their official email IDs for communication with the customer? (2)
Who will have access to the customer users / customers data in your organization and if any Access Control (Role Base Access Control or any other) is imposed on server / database where the customer users / customers data will be stored? (2)
Who will have access to the customer users / customers data in your organization and if any Access Control (Role Base Access Control or any other) is imposed on server / database where the customer users / customers data will be stored? (2)
Is proper access control implemented for secure access to the customer data? (2)
Is proper access control implemented for secure access to the customer data? (2)
What kind of access the vendor employees will have on the application and how access to the customer data in the application is restricted from being accessed by Vendor employees?
What kind of access the vendor employees will have on the application and how access to the customer data in the application is restricted from being accessed by Vendor employees?
Is user access controlled and has limited access to the data and configuration settings on cloud?
Is user access controlled and has limited access to the data and configuration settings on cloud?
Does the SAAS support MFA such as OTP or security tokens or biometrics?
Does the SAAS support MFA such as OTP or security tokens or biometrics?
Are there necessary controls for securing sensitive information according to the data classification (like Identity access management, access rights)? (2)
Are there necessary controls for securing sensitive information according to the data classification (like Identity access management, access rights)? (2)
Does access provided to users and administrators are based on Need to Know basis?
Does access provided to users and administrators are based on Need to Know basis?
Does access to privilege users / admin has MFA enabled?
Does access to privilege users / admin has MFA enabled?
Have you implemented Physical and Logical access controls to protect Personal Data?
Have you implemented Physical and Logical access controls to protect Personal Data?
Is there any way for the system administrator to terminate an active user who is suspected performing malicious action? Please describe the mechanism
Is there any way for the system administrator to terminate an active user who is suspected performing malicious action? Please describe the mechanism
Is the security services provided by the system integrate ready and able to be integrated to Active Directory or LDAP system?
Is the security services provided by the system integrate ready and able to be integrated to Active Directory or LDAP system?
Does the solution use open source 3rd party application framework? If yes, does it uses latest/stable patch? Please describe the libraries and its patch version.
Does the solution use open source 3rd party application framework? If yes, does it uses latest/stable patch? Please describe the libraries and its patch version.
Is there a Single User ID/ Password access to all the systems?
Is there a Single User ID/ Password access to all the systems?
The number of unsuccessful attempts
The number of unsuccessful attempts
Can the system check for over-simplified passwords (e.g., inclusion of UserID into the password itself) or force passwords to use more than just plain text, and numbers? Dictionary searches etc?
Can the system check for over-simplified passwords (e.g., inclusion of UserID into the password itself) or force passwords to use more than just plain text, and numbers? Dictionary searches etc?
Can the solution disable the User ID automatically if the unsuccessful attempts exceeds the maximum of trial?
Can the solution disable the User ID automatically if the unsuccessful attempts exceeds the maximum of trial?
Do passwords have an expiry date?
Do passwords have an expiry date?
Are passwords always stored in an encrypted form?
Are passwords always stored in an encrypted form?
Are passwords never shown in the clear on screen, or sent via e-mails?
Are passwords never shown in the clear on screen, or sent via e-mails?
Describe the recommended mechanism/process for resetting passwords (should a supervisor forgets his/her password) and the mechanism/process of setting the initial password
Describe the recommended mechanism/process for resetting passwords (should a supervisor forgets his/her password) and the mechanism/process of setting the initial password
Describe the recommended mechanism/process for resetting passwords (should a user forgets his/her password) and setting the initial password
Describe the recommended mechanism/process for resetting passwords (should a user forgets his/her password) and setting the initial password
Describe the role-based security mechanism provided!
Describe the role-based security mechanism provided!
Does the solution provide the centralized access control management tool?
Does the solution provide the centralized access control management tool?
Can the solution logged-off a terminal automatically; i.e. time-out feature during idle state?
Can the solution logged-off a terminal automatically; i.e. time-out feature during idle state?
Can the security module support to create the same user with different roles but validating the dual control rule (e.g. transaction imitator should not be the same as transaction approver)? If yes, please describe the mechanism?
Can the security module support to create the same user with different roles but validating the dual control rule (e.g. transaction imitator should not be the same as transaction approver)? If yes, please describe the mechanism?
Does solution have the capability to set up a user based on another user's profile?
Does solution have the capability to set up a user based on another user's profile?
Does the solution provide the centralized access control management tool? (2)
Does the solution provide the centralized access control management tool? (2)
Does your solution support multiple choices of authentication? What are they?
Does your solution support multiple choices of authentication? What are they?
Does your solution provide Token authentication? Please provide detail
Does your solution provide Token authentication? Please provide detail
What is the FTE allocation for Information and IT security functions and roles?
What is the FTE allocation for Information and IT security functions and roles?
What are the access management policies, procedures and processes?
What are the access management policies, procedures and processes?
How is user data provided to the system? (AAD integration/data loads/manually created)
How is user data provided to the system? (AAD integration/data loads/manually created)
How are user roles provisioned?
How are user roles provisioned?
Does the product support modern web-based integration methods? Please provide details.
Does the product support modern web-based integration methods? Please provide details.
Does CSP provide Identity and Access Management (IAM) with extensive Role Based Access Control (RBAC) support (who, what, when, where, how, etc.) for all provided services and What is your key management process for encryption
Does CSP provide Identity and Access Management (IAM) with extensive Role Based Access Control (RBAC) support (who, what, when, where, how, etc.) for all provided services and What is your key management process for encryption
User and User access provisioning, de-provisioning process
User and User access provisioning, de-provisioning process
Does the application allow users to set/reset password and login with password even when SSO is enabled? (2)
Does the application allow users to set/reset password and login with password even when SSO is enabled? (2)
How many key custodians are there?
How many key custodians are there?
If SSO is not technically feasible, every case of not using SSO shall be reviewed & approved by EIS Security Architecture, ISRA. Access is to be provisioned and tracked to all users via unique usernames and passwords. Follow standard password protection guidelines of Providence. IAM team shall be consulted.
If SSO is not technically feasible, every case of not using SSO shall be reviewed & approved by EIS Security Architecture, ISRA. Access is to be provisioned and tracked to all users via unique usernames and passwords. Follow standard password protection guidelines of Providence. IAM team shall be consulted.
Inactive logon sessions are to be locked and require the user to re-authenticate after 15 minutes of inactivity.
Inactive logon sessions are to be locked and require the user to re-authenticate after 15 minutes of inactivity.
Default accounts must be removed or (disabled/ renamed and passwords reset).
Default accounts must be removed or (disabled/ renamed and passwords reset).
Passwords must be masked during entry rendering contents in the password field unreadable. Passwords must be hashed with salt by using Providence approved algorithm.
Passwords must be masked during entry rendering contents in the password field unreadable. Passwords must be hashed with salt by using Providence approved algorithm.
The least amount of privilege necessary for user to perform their required functions will be provided to users. Access to be provisioned based on user roles (RBAC) and align with job function.
The least amount of privilege necessary for user to perform their required functions will be provided to users. Access to be provisioned based on user roles (RBAC) and align with job function.
Following 6 failed login attempts, the system or service shall be configured to either disable an account for 15 minutes or lock users out for at least 30 minutes.
Following 6 failed login attempts, the system or service shall be configured to either disable an account for 15 minutes or lock users out for at least 30 minutes.
Initial/ default password must be changed upon first login.
Initial/ default password must be changed upon first login.
Any user-defined routes must be requested and approved by PSJH Cloud Engineering. Subscription owners/ contributors must never add their own Routes.
Any user-defined routes must be requested and approved by PSJH Cloud Engineering. Subscription owners/ contributors must never add their own Routes.
Access to the subscription is coordinated by IAM team, privileged access should be determined by business justification, and granted by IAM.
Access to the subscription is coordinated by IAM team, privileged access should be determined by business justification, and granted by IAM.
Implement authenticated session tokens with secure settings.
Implement authenticated session tokens with secure settings.
Non-interactive identities (eg. service accounts) used to authenticate with any upstream/downstream systems (e.g. database) must be identified by the design. The design must adopt a policy of using least-privileged accounts. This needs to be reviewed by Security Architecture on a case to case basis.
Non-interactive identities (eg. service accounts) used to authenticate with any upstream/downstream systems (e.g. database) must be identified by the design. The design must adopt a policy of using least-privileged accounts. This needs to be reviewed by Security Architecture on a case to case basis.
Periodic review of access to be performed, to monitor priviliges.
Periodic review of access to be performed, to monitor priviliges.
Remove/disable inactive user accounts according to organizational defined frequency. eg., disables information system access within defined hours of termination and within defined hours of adverse circumstances termination. Terminates/revokes any authenticators/credentials associated with the individual;
Remove/disable inactive user accounts according to organizational defined frequency. eg., disables information system access within defined hours of termination and within defined hours of adverse circumstances termination. Terminates/revokes any authenticators/credentials associated with the individual;
On-demand access reviews to be performed whenever there is a change to the existing RBAC, eg., when a caregiver moves from one department to other, or takes more responsibilities, or assuming reduced responsibilities that may warrent limiting existing access to sensitive systems.
On-demand access reviews to be performed whenever there is a change to the existing RBAC, eg., when a caregiver moves from one department to other, or takes more responsibilities, or assuming reduced responsibilities that may warrent limiting existing access to sensitive systems.
If application is exposed to internet (upon review and approval from Security Architecture). The application's admin console must only be allowed to be accessed from a PSJH managed endpoint by a enabling conditional remote access policy.
If application is exposed to internet (upon review and approval from Security Architecture). The application's admin console must only be allowed to be accessed from a PSJH managed endpoint by a enabling conditional remote access policy.
The mobile application must require users to enter a password, PIN, and/or biometric authentication mechanism in order to access mobile application content.
The mobile application must require users to enter a password, PIN, and/or biometric authentication mechanism in order to access mobile application content.
If external, non-PSJH support is required and the vendor must agree to conduct remote support using a PSJH-provided remote access tools rather than vendor tools. Support activites shall be carried out under supervison of Providence's representative and sessions to be recorded.
If external, non-PSJH support is required and the vendor must agree to conduct remote support using a PSJH-provided remote access tools rather than vendor tools. Support activites shall be carried out under supervison of Providence's representative and sessions to be recorded.
The solution must be configured so that end users do not need local administrative privileges on workstations or systems running the application.
The solution must be configured so that end users do not need local administrative privileges on workstations or systems running the application.
Implement controls to restrict export of data based on role and the availability and implementation of controls to protect the information once exported.
Implement controls to restrict export of data based on role and the availability and implementation of controls to protect the information once exported.
Web Services must be authenticated using a service account/ managed identity principal.
Web Services must be authenticated using a service account/ managed identity principal.
Implement controls to ensure that service response script code is not directly executable.
Implement controls to ensure that service response script code is not directly executable.
Is the system accessed via a direct Internet connection, VPN, or dedicated network circuit?
Is the system accessed via a direct Internet connection, VPN, or dedicated network circuit?
Detail out the different roles configured and the privileges associated with each role. Also, please specify how user access management (access provisioning and de-provisioning) is being performed
Detail out the different roles configured and the privileges associated with each role. Also, please specify how user access management (access provisioning and de-provisioning) is being performed
Are admin or privilege accounts are separate from user accounts in application?
Are admin or privilege accounts are separate from user accounts in application?
Do access rights follow need-to-know, need-to-use and least privilege concepts?
Do access rights follow need-to-know, need-to-use and least privilege concepts?
Are the roles and access rights are reviewed atleast annually?
Are the roles and access rights are reviewed atleast annually?
Is the account authenticated before access?
Is the account authenticated before access?
Are critical roles and privilege accounts login enforced by 2-FA?
Are critical roles and privilege accounts login enforced by 2-FA?
Are users accounts locked after a successive failure login attempts?
Are users accounts locked after a successive failure login attempts?
Are users enforced to change password periodically?
Are users enforced to change password periodically?
Are the password are hashed and not mentioned as clear text in code?
Are the password are hashed and not mentioned as clear text in code?
Is the application server comply with identity and access control policy?
Is the application server comply with identity and access control policy?
Is the application server comply with password policy?
Is the application server comply with password policy?
Is the database comply with identity & access control policy?
Is the database comply with identity & access control policy?
Is the database comply with password policy?
Is the database comply with password policy?
Who all have access to the hosted environment and/ or data? (Include the third party access if applicable)
Who all have access to the hosted environment and/ or data? (Include the third party access if applicable)
How is their access controlled?
How is their access controlled?
How does the provider segregate the the customer environment from other tenants?
How does the provider segregate the the customer environment from other tenants?
How is data integrity assured? What controls exist over internal processing?
How is data integrity assured? What controls exist over internal processing?
Does the application support multi-factor authentication (MFA / 2FA)? If yes, please elaborate.
Does the application support multi-factor authentication (MFA / 2FA)? If yes, please elaborate.
Does the provider have access to the customer data, and if so, what restrictions are there over this level of access?
Does the provider have access to the customer data, and if so, what restrictions are there over this level of access?
Who has access to these logs?
Who has access to these logs?
