Do you have a disciplinary process for non-compliance with information security policy, and are employees made aware of the consequences for non-compliance?
Do you have a disciplinary process for non-compliance with information security policy, and are employees made aware of the consequences for non-compliance?
Do you have an employee termination or change of status process?
Do you have an employee termination or change of status process?
Do you have documented information security baselines for component of your infrastructure (e.g., hypervisors, operating systems, routers, DNS servers, etc.)?
Do you have documented information security baselines for component of your infrastructure (e.g., hypervisors, operating systems, routers, DNS servers, etc.)?
Do you have documented policies and procedures demonstrating adherence to data retention periods as per legal, statutory or regulatory compliance requirements?
Do you have documented policies and procedures demonstrating adherence to data retention periods as per legal, statutory or regulatory compliance requirements?
Do you perform, at minimum, annual reviews to your privacy and security policies?
Do you perform, at minimum, annual reviews to your privacy and security policies?
Are formal risk assessments aligned with the enterprise-wide framework and performed at least annually, or at planned intervals, determining the likelihood and impact of all identified risks, using qualitative and quantitative methods?
Are formal risk assessments aligned with the enterprise-wide framework and performed at least annually, or at planned intervals, determining the likelihood and impact of all identified risks, using qualitative and quantitative methods?
Do you have documentation establishing and defining your encryption management policies, procedures, and guidelines?
Do you have documentation establishing and defining your encryption management policies, procedures, and guidelines?
Are policies and procedures established, and supporting business processes and technical measures implemented, for maintaining complete, accurate, and relevant agreements (e.g., SLAs) between providers and customers?
Are policies and procedures established, and supporting business processes and technical measures implemented, for maintaining complete, accurate, and relevant agreements (e.g., SLAs) between providers and customers?
Is classification inclusive of all media types (electronic, hard copy)?
Is classification inclusive of all media types (electronic, hard copy)?
Does your organization have policies and standards in place for the handling of Media?
Does your organization have policies and standards in place for the handling of Media?
Is there capability to support client media handling policies and standards?
Is there capability to support client media handling policies and standards?
Are there policies and standard in place for the secure storage of hard copy media? Internal repository? Third-party contractor?
Are there policies and standard in place for the secure storage of hard copy media? Internal repository? Third-party contractor?
Are there policies and standards in place for the secure destruction of media?
Are there policies and standards in place for the secure destruction of media?
Does the organisation have written information security policies?
Does the organisation have written information security policies?
How often the policy are been reviewed?
How often the policy are been reviewed?
Does the organisation have a written password policy that details the required structure of passwords?
Does the organisation have a written password policy that details the required structure of passwords?
Have the information security policy and standards been approved by senior management?
Have the information security policy and standards been approved by senior management?
Has the organisation implemented an IT Governance framework such as ITIL, ISO 27001/22301, SSAE18 (SOC) and others?
Has the organisation implemented an IT Governance framework such as ITIL, ISO 27001/22301, SSAE18 (SOC) and others?
Is access restricted to systems that contain sensitive data?
Is access restricted to systems that contain sensitive data?
Does the software development lifecycle in the organisation specifically focus on security?
Does the software development lifecycle in the organisation specifically focus on security?
Is code review performed on all changes to the source code with an emphasis on secure coding principles?
Is code review performed on all changes to the source code with an emphasis on secure coding principles?
As per the customer policy, personal devices (BYOD) are restricted. If BYOD is permitted to process/access/storethe customer scoped data, are there appropriate approval obtained from the customer for the same?
As per the customer policy, personal devices (BYOD) are restricted. If BYOD is permitted to process/access/storethe customer scoped data, are there appropriate approval obtained from the customer for the same?
Is there a process to perform modify / change the access review process for additional focus on remote access connections to client (the customer) network?
Is there a process to perform modify / change the access review process for additional focus on remote access connections to client (the customer) network?
Is there a documented third-party risk management program in place for the selection, oversight and risk assessment of Subcontractors (e.g. service providers, dependent service providers, sub-processors)?
Is there a documented third-party risk management program in place for the selection, oversight and risk assessment of Subcontractors (e.g. service providers, dependent service providers, sub-processors)?
Is there a Documented Information Security Policy approved by management? If yes, is the same communicated to all employees?
Is there a Documented Information Security Policy approved by management? If yes, is the same communicated to all employees?
Are the key roles and responsibilities of the organizations Information Security Processes covered as a part of IS policy for the customer activities?
Are the key roles and responsibilities of the organizations Information Security Processes covered as a part of IS policy for the customer activities?
Is the Information Security Policy reviewed at regular intervals & on changes in the customer scope of work?
Is the Information Security Policy reviewed at regular intervals & on changes in the customer scope of work?
Is there a role based access control for accessing critical facilities used for the customer operations?
Is there a role based access control for accessing critical facilities used for the customer operations?
Has the vendor documented detailed procedure for identifying of changes to be notified to the customer, sending an approval request & communication process?
Has the vendor documented detailed procedure for identifying of changes to be notified to the customer, sending an approval request & communication process?
Does the vendor provider have a management approved change management process for activities of the customer?
Does the vendor provider have a management approved change management process for activities of the customer?
Does the vendor's change management / change control process include some of the following: Request, review and approval of proposed changes; Review for potential security impact; Security approval; Review for potential operational impact; Approval from the customer (when applicable); Documentation of changes; Pre-implementation testing; Post-implementation testing; Rollback procedures
Does the vendor's change management / change control process include some of the following: Request, review and approval of proposed changes; Review for potential security impact; Security approval; Review for potential operational impact; Approval from the customer (when applicable); Documentation of changes; Pre-implementation testing; Post-implementation testing; Rollback procedures
Has provider documented a process for handling emergency changes in the customer operations to ensure that these types of changes are carried out in controlled & timely manner?
Has provider documented a process for handling emergency changes in the customer operations to ensure that these types of changes are carried out in controlled & timely manner?
Does the organization has a mechanism to classify & protect the customer data?
Does the organization has a mechanism to classify & protect the customer data?
Does the vendor follow a defined retention period for the customer data? Does it follow a structured mechanism to remove the customer data once retention period is expired?
Does the vendor follow a defined retention period for the customer data? Does it follow a structured mechanism to remove the customer data once retention period is expired?
What is your retention policy for retaining these logs? (30 days, 60 days, 1 year, etc)
What is your retention policy for retaining these logs? (30 days, 60 days, 1 year, etc)
Does the organization have controls implemented for monitoring the use of all information processing facilities handling sensitive data?
Does the organization have controls implemented for monitoring the use of all information processing facilities handling sensitive data?
Are roles & responsibilities defined clearly for reporting suspected security incidents to the customer? Is root cause analysis performed?
Are roles & responsibilities defined clearly for reporting suspected security incidents to the customer? Is root cause analysis performed?
Is a list of Emergency contact names and phone numbers of your company, client and Vendor clearly defined and readily accessible to allow prompt escalation?
Is a list of Emergency contact names and phone numbers of your company, client and Vendor clearly defined and readily accessible to allow prompt escalation?
Is there adequate segregation of duties to protect the the customer operations network where appropriate?
Is there adequate segregation of duties to protect the the customer operations network where appropriate?
Is 2-factor authentication used for very critical applications?
Is 2-factor authentication used for very critical applications?
Does the development team have access to production environment?
Does the development team have access to production environment?
Please explain your Software Development Lifecycle. Do you have a process for the review of applications source code for security flaws and backdoors? Describe who performs this process. Describe when in the software development life cycle is it performed
Please explain your Software Development Lifecycle. Do you have a process for the review of applications source code for security flaws and backdoors? Describe who performs this process. Describe when in the software development life cycle is it performed
Is a media labelling procedure in place, with sufficient information?
Is a media labelling procedure in place, with sufficient information?
Do you have a documented password management policy? Have you deployed password security controls within the environment on application, OS, database and network layers?
Do you have a documented password management policy? Have you deployed password security controls within the environment on application, OS, database and network layers?
Do you have a policy/procedure on change management? Are all changes to production environment recorded and follows the change management procedure?
Do you have a policy/procedure on change management? Are all changes to production environment recorded and follows the change management procedure?
Do you maintain an asset classification schema at par with BSLI Information classification policy and maintain a mapping of the same?
Do you maintain an asset classification schema at par with BSLI Information classification policy and maintain a mapping of the same?
Has a formal policy been developed that addresses the risks of working with mobile computing facilities, including requirements for physical protection, access controls, cryptographic techniques, back-up, and virus protection?
Has a formal policy been developed that addresses the risks of working with mobile computing facilities, including requirements for physical protection, access controls, cryptographic techniques, back-up, and virus protection?
Is the acceptable use of assets policy documented?
Is the acceptable use of assets policy documented?
Is there a clear desk and clear screen policy in force in the organization?
Is there a clear desk and clear screen policy in force in the organization?
Whether the Information Security Policy is reviewed at planned intervals, or if significant changes occur to ensure its continuing suitability, adequacy and effectiveness? Whether the management review of the information security policy documentation is recorded?
Whether the Information Security Policy is reviewed at planned intervals, or if significant changes occur to ensure its continuing suitability, adequacy and effectiveness? Whether the management review of the information security policy documentation is recorded?
Has your organisation identified employees and resources (e.g., suppliers, subcontractors, products, and logistics) that are critical for business continuity in the event of a pandemic.
Has your organisation identified employees and resources (e.g., suppliers, subcontractors, products, and logistics) that are critical for business continuity in the event of a pandemic.
Describe the backup and retention policy proposed, including the possible capacity to restore a VM to a previous state in time. Also detail how frequently backup/restore tests are performed.
Describe the backup and retention policy proposed, including the possible capacity to restore a VM to a previous state in time. Also detail how frequently backup/restore tests are performed.
Provide your Endpoint Security Policy
Provide your Endpoint Security Policy
Provide the technical security policies implemented on all components of your infrastructure (microcode vulnerabilities, HSM management, Management of the virtualization, Hypervisors, OS, network elements, etc…) inclusive of custom changes or solution-specific modifications of these elements (especially hypervisors). Also describe the management system in place to monitor continuous compliance to these policies.
Provide the technical security policies implemented on all components of your infrastructure (microcode vulnerabilities, HSM management, Management of the virtualization, Hypervisors, OS, network elements, etc…) inclusive of custom changes or solution-specific modifications of these elements (especially hypervisors). Also describe the management system in place to monitor continuous compliance to these policies.
Describe how you implement Segregation of Duties and monitor potential conflict of interests
Describe how you implement Segregation of Duties and monitor potential conflict of interests
Provide the standard contractual RACI between your teams and the tenants'.
Provide the standard contractual RACI between your teams and the tenants'.
What file integrity (host) and network intrusion detection (IDS/IPS/WAF) systems using signatures, lists or behavioural patterns have you implemented to help facilitate timely detection, investigation by root cause analysis and response to incidents. Provide an overview of how these tools are updated and controled.
What file integrity (host) and network intrusion detection (IDS/IPS/WAF) systems using signatures, lists or behavioural patterns have you implemented to help facilitate timely detection, investigation by root cause analysis and response to incidents. Provide an overview of how these tools are updated and controled.
Describe the change management in place and how changes performed on the infrastructure (virtual or physical) are monitored and logged
Describe the change management in place and how changes performed on the infrastructure (virtual or physical) are monitored and logged
Does the organisation have written information security policies? (2)
Does the organisation have written information security policies? (2)
How often the policy are been reviewed? (2)
How often the policy are been reviewed? (2)
Does the organisation have a formal change control process for IT changes?
Does the organisation have a formal change control process for IT changes?
Are all systems security configuration standards documented and based on external industry or vendor guidance?
Are all systems security configuration standards documented and based on external industry or vendor guidance?
Is there formal control of access to System Administrator privileges?
Is there formal control of access to System Administrator privileges?
Does the organisation have have a established business continuity / Disaster recovery management framework?
Does the organisation have have a established business continuity / Disaster recovery management framework?
Does the oragnisation has Business Continuity / DR Plans?
Does the oragnisation has Business Continuity / DR Plans?
Is code review performed on all changes to the source code with an emphasis on secure coding principles? (2)
Is code review performed on all changes to the source code with an emphasis on secure coding principles? (2)
Is there a formal change control policy or process within your organisation supported by source code and release management tools?
Is there a formal change control policy or process within your organisation supported by source code and release management tools?
Does your organisation have a formal vendor management program that evaluates information security for your suppliers? (for example attestation reports / SOC 2 Type 2 reports review, site assessments)
Does your organisation have a formal vendor management program that evaluates information security for your suppliers? (for example attestation reports / SOC 2 Type 2 reports review, site assessments)
As per the customer policy, personal devices (BYOD) are restricted. If BYOD is permitted to process/access/storethe customer scoped data, are there appropriate approval obtained from the customer for the same? (2)
As per the customer policy, personal devices (BYOD) are restricted. If BYOD is permitted to process/access/storethe customer scoped data, are there appropriate approval obtained from the customer for the same? (2)
Is there a process to perform modify / change the access review process for additional focus on remote access connections to client (the customer) network? (2)
Is there a process to perform modify / change the access review process for additional focus on remote access connections to client (the customer) network? (2)
Is there collection of, access to, processing of, or retention of any client scoped Data that includes any classification of non-public personal information or personal data of individuals?
Is there collection of, access to, processing of, or retention of any client scoped Data that includes any classification of non-public personal information or personal data of individuals?
Is a Training and Awareness Program maintained that addresses data privacy and data protection obligations based on role?
Is a Training and Awareness Program maintained that addresses data privacy and data protection obligations based on role?
Is there a mechanism to classify data as per the criticality and requirement?
Is there a mechanism to classify data as per the criticality and requirement?
What backup and disaster recovery plans are in place to avoid data loss / service loss in the time of contingency
What backup and disaster recovery plans are in place to avoid data loss / service loss in the time of contingency
There is a proper change management process in place to protect the customer data integrity, for addressing changes to the common environment, and that all tenants are notified about in advance.
There is a proper change management process in place to protect the customer data integrity, for addressing changes to the common environment, and that all tenants are notified about in advance.
There is a Software Development LifeCycle (SDLC) process in place for the development of the software providing services to the customer, where security is incorporated in each phase.
There is a Software Development LifeCycle (SDLC) process in place for the development of the software providing services to the customer, where security is incorporated in each phase.
- We have implimented the systems development life cycle (SDLC) and atatched the same for your referrence. 2. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. 3. We also conduct vulnerability and penetration testing and fix the identified observations. 4. Upon passing all the security and quality checks the new version of the product will be released.
Does the cloud provider have a disaster recovery plan? Does the plan say what triggers a recovery, how long does it take to recover or restore data from backup?
Does the cloud provider have a disaster recovery plan? Does the plan say what triggers a recovery, how long does it take to recover or restore data from backup?
Does the contract empower the customer to audit processing operations on personal data performed by Supplier and its sub-contractors?
Does the contract empower the customer to audit processing operations on personal data performed by Supplier and its sub-contractors?
Describe procedures used for business continuity and disaster recovery that would include your applications and all data, as well as evidence that you have tested those procedures during the past 12 months.
Describe procedures used for business continuity and disaster recovery that would include your applications and all data, as well as evidence that you have tested those procedures during the past 12 months.
Are business continuity plans subject to testing at planned intervals or upon significant organizational or environmental changes to ensure continuing effectiveness?
Are business continuity plans subject to testing at planned intervals or upon significant organizational or environmental changes to ensure continuing effectiveness?
The vendor should detail their HA and DR plans, including recovery point objective (RPO) and recovery time objective (RTO) targets, geographic diversity in their hosting arrangements, and any periodic testing that takes place.
The vendor should detail their HA and DR plans, including recovery point objective (RPO) and recovery time objective (RTO) targets, geographic diversity in their hosting arrangements, and any periodic testing that takes place.
If the answer for #6 is yes, then how often is it? Also, do you make testing backups a routine task to ensure that the data is valid and accessible as intended?
If the answer for #6 is yes, then how often is it? Also, do you make testing backups a routine task to ensure that the data is valid and accessible as intended?
Do you have a Business Continuity Plan to ensure service availability under extreme situations such as power outages/natural disasters?
Do you have a Business Continuity Plan to ensure service availability under extreme situations such as power outages/natural disasters?
How is a planned and unplanned service disruption communicated?
How is a planned and unplanned service disruption communicated?
Do you have a procedure for securely destroying hard copy sensitive data?
Do you have a procedure for securely destroying hard copy sensitive data?
Please ensure your documented information security policy has been uploaded in section in 'Service Overview'
Please ensure your documented information security policy has been uploaded in section in 'Service Overview'
Do your information security and privacy policies align with industry standards (ISO-27001, NIST Cyber Security Framework, ISO-22307, CoBIT, etc.)?
Do your information security and privacy policies align with industry standards (ISO-27001, NIST Cyber Security Framework, ISO-22307, CoBIT, etc.)?
Do you have a policy exception process?
Do you have a policy exception process?
Is a formal disciplinary or sanction policy established for employees who have violated security policies and procedures?
Is a formal disciplinary or sanction policy established for employees who have violated security policies and procedures?
Are all personnel required to sign an Acceptable Use Policy? Please attach
Are all personnel required to sign an Acceptable Use Policy? Please attach
Do you have a policy exception process? (2)
Do you have a policy exception process? (2)
Is a formal disciplinary or sanction policy established for employees who have violated security policies and procedures? (2)
Is a formal disciplinary or sanction policy established for employees who have violated security policies and procedures? (2)
Protecting against non-human sources of risks
Protecting against non-human sources of risks
Are these policies, approved by the senior management within your organisation, regularly reviewed and communicated to all your staff?
Are these policies, approved by the senior management within your organisation, regularly reviewed and communicated to all your staff?
How will you decide which of your staff (support, development etc.) need access to the the customer system and data? How will you manage that access and what controls are in place, to ensure that privileged access rights will be restricted and controlled?
How will you decide which of your staff (support, development etc.) need access to the the customer system and data? How will you manage that access and what controls are in place, to ensure that privileged access rights will be restricted and controlled?
Who will have access to log files and how is access controlled?
Who will have access to log files and how is access controlled?
Do you have an information security incident response plan in place to ensure effective response and management of information security incidents?
Do you have an information security incident response plan in place to ensure effective response and management of information security incidents?
Will password hashing be used within the system? If so to what standard and will any salting be used?
Will password hashing be used within the system? If so to what standard and will any salting be used?
Ensure that change control procedures are in place to maintain program source code and associated items.
Ensure that change control procedures are in place to maintain program source code and associated items.
Security shall be considered at all stages of the life cycle of an information asset (i.e. feasibility, planning, development, implementation, maintenance, and retirement) in order to: ensure conformance with all appropriate security requirements, protect sensitive information throughout its life cycle, facilitate efficient implementation of security controls, prevent introduction of new risks associated with systems modifications, ensure proper removal of the customer data when the system is retired or disposed.
Security shall be considered at all stages of the life cycle of an information asset (i.e. feasibility, planning, development, implementation, maintenance, and retirement) in order to: ensure conformance with all appropriate security requirements, protect sensitive information throughout its life cycle, facilitate efficient implementation of security controls, prevent introduction of new risks associated with systems modifications, ensure proper removal of the customer data when the system is retired or disposed.
Information security requirements for Systems and Assets shall be identified and documented.
Information security requirements for Systems and Assets shall be identified and documented.
Systems and application development ether performed internally or by third party shall: Follow a Secure Software Development Life Cycle (S-SDLC). Perform Threat Modelling throughout Secure Software Development Life Cycle. Include Quality Assurance (QA) process. Include thorough and rigorous testing and verification of security functionality during the development processes for new and updated systems. Detailed schedule of activities and test inputs and expected outputs under a range of conditions, in proportion to the importance and nature of the system shall be included. Ensure that secure coding (code reviews, static/dynamic code analysis, vulnerability scans, industry certifications etc.) and development practices are utilized. Ensure it has the capability to perform security risk assessment of software and hardware components and shall be able to support the customer when security information is needed. Provide a list of third-party components and libraries used in system or application and ensure no inherited risk is been introduced by this use. Ensure control and document changes within the development lifecycle: Through the use of a formal change control process. Maintaining an audit trail of all change requests. Mandating a risk assessment, analysis of the impacts of changes and specification of security controls needed. Ensuring that any change does not compromise existing security and control measures. Ensuring that existing documentation is updated as needed to remain appropriate. Ensuring that testing is performed in an environment segregated from both the production and development environments and results are documented. Considering, based on change perceived risk, an extra independent acceptance testing to validate if the system behaves only as expected.
Systems and application development ether performed internally or by third party shall: Follow a Secure Software Development Life Cycle (S-SDLC). Perform Threat Modelling throughout Secure Software Development Life Cycle. Include Quality Assurance (QA) process. Include thorough and rigorous testing and verification of security functionality during the development processes for new and updated systems. Detailed schedule of activities and test inputs and expected outputs under a range of conditions, in proportion to the importance and nature of the system shall be included. Ensure that secure coding (code reviews, static/dynamic code analysis, vulnerability scans, industry certifications etc.) and development practices are utilized. Ensure it has the capability to perform security risk assessment of software and hardware components and shall be able to support the customer when security information is needed. Provide a list of third-party components and libraries used in system or application and ensure no inherited risk is been introduced by this use. Ensure control and document changes within the development lifecycle: Through the use of a formal change control process. Maintaining an audit trail of all change requests. Mandating a risk assessment, analysis of the impacts of changes and specification of security controls needed. Ensuring that any change does not compromise existing security and control measures. Ensuring that existing documentation is updated as needed to remain appropriate. Ensuring that testing is performed in an environment segregated from both the production and development environments and results are documented. Considering, based on change perceived risk, an extra independent acceptance testing to validate if the system behaves only as expected.
Protection of physical media and any device in transit carrying information/data must be according to the highest level of information sensitivity it will contain. This may include physical locking mechanisms, digital encryption and/or packaging sufficient to prevent harm from environmental (e.g. extreme heat/cold, moisture), electromagnetic, or radiation exposure.
Protection of physical media and any device in transit carrying information/data must be according to the highest level of information sensitivity it will contain. This may include physical locking mechanisms, digital encryption and/or packaging sufficient to prevent harm from environmental (e.g. extreme heat/cold, moisture), electromagnetic, or radiation exposure.
Physical media carrying Secret information shall be documented.
Physical media carrying Secret information shall be documented.
Receipt notifications or other tracking mechanisms shall be implemented.
Receipt notifications or other tracking mechanisms shall be implemented.
For each asset, document the entity's required maintenance designed to support the availability and integrity of the equipment.
For each asset, document the entity's required maintenance designed to support the availability and integrity of the equipment.
Any hardware/software change in the systems, assets and networks shall follow the Management of Change (MoC)/Change Request.
Any hardware/software change in the systems, assets and networks shall follow the Management of Change (MoC)/Change Request.
Security aspects shall be taken in consideration for reviewing of all major software changes and upgrades to the systems.
Security aspects shall be taken in consideration for reviewing of all major software changes and upgrades to the systems.
System capacity requirements shall be identified and aligned with business goals, objectives and criticality.
System capacity requirements shall be identified and aligned with business goals, objectives and criticality.
Physical Access Controls: Allow access on a need-to-access basis; Adopt single or double authentication; Adopt alarms.
Physical Access Controls: Allow access on a need-to-access basis; Adopt single or double authentication; Adopt alarms.
Physical security level associated with information asset's location shall be identified based on information asset's criticality, vulnerabilities, and threats to that particular information asset.
Physical security level associated with information asset's location shall be identified based on information asset's criticality, vulnerabilities, and threats to that particular information asset.
Monitoring and review of third parties' services shall ensure that the security terms and conditions of the agreements are being adhered to and that information security incidents and problems are managed properly.
Monitoring and review of third parties' services shall ensure that the security terms and conditions of the agreements are being adhered to and that information security incidents and problems are managed properly.
All changes communicated by the external/third party to the customer shall be performed in accordance with the customer Change Management processes.
All changes communicated by the external/third party to the customer shall be performed in accordance with the customer Change Management processes.
Each critical system shall have a recovery procedure with defined RTO/RPO. This shall be decided based on business impact analysis (HSE, financial, operational or reputational impacts to the business and customers).
Each critical system shall have a recovery procedure with defined RTO/RPO. This shall be decided based on business impact analysis (HSE, financial, operational or reputational impacts to the business and customers).
Any changes or updates to the Disaster Recovery Plans shall be communicated to all concerned stakeholders internal and external to organisation.
Any changes or updates to the Disaster Recovery Plans shall be communicated to all concerned stakeholders internal and external to organisation.
The management of information security incidents in the customer shall follow an established process: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-incident Activity.
The management of information security incidents in the customer shall follow an established process: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-incident Activity.
Information security incident documentation shall include: All information security events identified and their characterisation (entry points, spread methods, services/data/assets impacted, etc.). Lessons learned from real incidents and from the training exercises. Collection and preservation of forensics analysis data, to serve as evidence.
Information security incident documentation shall include: All information security events identified and their characterisation (entry points, spread methods, services/data/assets impacted, etc.). Lessons learned from real incidents and from the training exercises. Collection and preservation of forensics analysis data, to serve as evidence.
Employees and third parties shall note and report any observed or suspected information security event or weaknesses in the customer environment.
Employees and third parties shall note and report any observed or suspected information security event or weaknesses in the customer environment.
Service Provider shall have solid security incident management process, including a computer security incident response team (CSIRT) that has been trained to handle security incidents. This process should in line with the customer security incident management requirements
Service Provider shall have solid security incident management process, including a computer security incident response team (CSIRT) that has been trained to handle security incidents. This process should in line with the customer security incident management requirements
Are the processes for User Administration (including user identification and adding / removing user accounts) compliant with ISO27002?
Are the processes for User Administration (including user identification and adding / removing user accounts) compliant with ISO27002?
What type of DR options do your provide for my data within your offering?
What type of DR options do your provide for my data within your offering?
Are the processes for User Administration (including user identification and adding / removing user accounts) compliant with ISO27002? (2)
Are the processes for User Administration (including user identification and adding / removing user accounts) compliant with ISO27002? (2)
Do you have a formal information classification procedure? Please describe it. In particular, how would sensitive data be categorised? For example, critical, essential, and normal.
Do you have a formal information classification procedure? Please describe it. In particular, how would sensitive data be categorised? For example, critical, essential, and normal.
Have formal acceptable use rules been established for assets? Example assets include data assets, computer equipment, communications equipment, etc. Do you have formal processes in place for security policy maintenance and deviation?
Have formal acceptable use rules been established for assets? Example assets include data assets, computer equipment, communications equipment, etc. Do you have formal processes in place for security policy maintenance and deviation?
Do you have a process that addresses: the identification and measurement of potential risks, mitigating controls (measures taken to reduce risk), and the acceptance or transfer (Insurance policies, warranties for example) of the remaining (residual) risk after mitigation steps have been applied?
Do you have a process that addresses: the identification and measurement of potential risks, mitigating controls (measures taken to reduce risk), and the acceptance or transfer (Insurance policies, warranties for example) of the remaining (residual) risk after mitigation steps have been applied?
Is there a facility security plan?
Is there a facility security plan?
Do you have a mechanism to back up critical IT systems and sensitive data? i.e. nightly, weekly, quarterly backups? Taken offsite? Have you had to restore files after a systems outage? Does a Disaster Recovery plan exist for the organization and does it consider interruption to, or failure of, critical IT systems? Are disaster recovery plans updated at least annually? If not, has the backup and restoration process been tested?
Do you have a mechanism to back up critical IT systems and sensitive data? i.e. nightly, weekly, quarterly backups? Taken offsite? Have you had to restore files after a systems outage? Does a Disaster Recovery plan exist for the organization and does it consider interruption to, or failure of, critical IT systems? Are disaster recovery plans updated at least annually? If not, has the backup and restoration process been tested?
Is the data classified top secret/ confidential /PII stored separately from public data / data of other organizations residing on same cloud?
Is the data classified top secret/ confidential /PII stored separately from public data / data of other organizations residing on same cloud?
Incident management policy and procedure
Incident management policy and procedure
Follow change control processes and procedures for all changes to system components, applies information system security engineering principles in the specification, design, development, implementation, and modification of the information system.
Follow change control processes and procedures for all changes to system components, applies information system security engineering principles in the specification, design, development, implementation, and modification of the information system.
Formally define and approve process controls for implementing minimum security requirements.
Formally define and approve process controls for implementing minimum security requirements.
Enforce controls over external file sharing.
Enforce controls over external file sharing.
Is a cybersecurity policy & standard defined, approved and implemented?
Is a cybersecurity policy & standard defined, approved and implemented?
Is application development follow change management process?
Is application development follow change management process?
Is the data is classified within database as per data classification Policy?
Is the data is classified within database as per data classification Policy?
Do you have a disaster recovery plan?
Do you have a disaster recovery plan?
Describe the provider's process to report an incident involving the customer environment/data to the customer
Describe the provider's process to report an incident involving the customer environment/data to the customer
Describe the provider's reporting mechanism for security and/or other incidents. In what format do notifications go out, and what information do they contain?
Describe the provider's reporting mechanism for security and/or other incidents. In what format do notifications go out, and what information do they contain?
Will the area be developing a business continuity plan for when the solution/service or data is not available? If so, by when? If not, why not?
Will the area be developing a business continuity plan for when the solution/service or data is not available? If so, by when? If not, why not?
Is the database comply with identity & access control policy?
Is the database comply with identity & access control policy?
