Skip to main content
We have the disciplinary process in place for Non-compliance with Information security Policy and we have communicated and made aware of the consequences for non-compliance.
We have the employee termination process in place.
We have implemented the information security policy and Hardening Guidelines.
All our Privacy and security policies are reviewed every year and approved by the management.
At Xoxoday we have developed a Risk Management Framework as part of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013 standard and SOC II attestation. The information security team assesses security risks annually and on an ongoing basis when major changes occur or when industry changes occur.
Yes. We have implemented the Data Encryption policy
Yes. We have the policies and procesures in place as per the compliane requirements.
Yes. classification inclusive of all media types.
Yes. we have implemented the Media handling procedures.
We follow Xoxoday media handling procedure.
Yes. It’s a part of Media handling procedure and Information security policy implemented.
Yes. we have implemented the Data Retention and Disposal Policy.
Yes. We have a written Information security policy.
These policies are reviewed anually or whenever changes made to it and approved by the management as per the compliance requirements.
Yes. We have implemented the Password Management Policy
All the information security policy and standards been approved by senior management.
Yes. Xoxoday is ISO 27001:2013, SOC 2, CCPA/CPRA, HIPAA, CSA START, GDPR certified organization.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
We focus on the security while producting the softwares.
It’s a part of our system devolopment life cycle.
We have implemented the BYOD policy and all our employees follow the Xoxoday Information security and IT Policies.
Yes. we have implemented the access control policy.
We have implemented the Risk Management Procedure
Yes. Its approved by the management and communicated to all the employees.
Yes. Aattached the Information security policy, Roles and responsibilities policies.
Yes. All the policies have been reviewed at regular intervals.
Yes. We have implemented the role based access control mechanism and only authorised individual will get access.
Yes, we have the policies and procedures in place and we will notify the customer if there is any changes took place in terms of security and privacy.
Yes. We have a Change Management process and approved by the management.
Yes. We have implemented the change management procedure.
Yes. We implemented the the change management procedure.
Yes. We have implemented the Data clasification policy.
Yes. We have the data retension and disposal policy. We will have the data till you use our platform and will be deleted upon termnination of the contracts and will confirm.
1 year
Yes. We have implemented data security policy and have controls in place to monitor the processing of personal information. Since we have deployed our application of AWS cloud only authorised individual have an access.
Yes. We have the incident management response team and roles and responsibilities has been clearly defined. As per our policies and procedure we condut Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have communicated on this to a concerned parties.
Yes, we segregated the duties.
Yes, our policies and procedures are established and implemented to enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems.
We have segregated the teams according to their roles and responsibilites.
We have the SDLC Procedure and attached the same for your reference. We have defined rules and guidelines for secure development of software and systems.
Yes. We have implemented the media protection procedure.
At Xoxoday we have implemented the password management policy. Attached the same for your referrence. We have deployed password security controls accross the organization for maximum security.
Attached the Change Management Procedure. All the chnages to production environment is recorded and followed the change management procedure.
We have implemented the Asset classification policy. Attached the policy for your referrence.
We have the policies in place and audited during the internal and external audits. We have the policies with regards to Access control, Ceyptography, Anti virus protection, Back up and recovery etc..
Yes. We have implemented the Acceptable Usage Policy
Yes. We have implemented Clear Screen and Clear Desk Policy
All the information security policies has been reviewed annually or upon any changes to the policies. All the management review and approvals has been recorded.
Attached the Business continuity documents.
Data backups are done daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
Attache the Information Security Policy and Data Security policy.
Attached the policies with regards to - IT, Virtual Private Network, Threat and vulnerabilities, Virus management, patch management, access control, logging and monitoring etc.
Attached the below mentioned policies - 1. Cloud Computing Security Policy 2. Encryption Policy 3. Password Management Policy 4. Threat and Vulnerability Management 5. Infrastructure Change Control Procedure 6. Virtual Private Network Policy 7. Information Classification Policy 8. Cyber Crisis Management Plan 9. Network Access Control and Security Procedure 10. Information System Acquisition Development and Maintenance Procedure
The policy, process, and procedure is implemented to ensure proper segregation of duties.
Attached the Roles Responsibilities_Authorities Policy.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
We have implemented the change management procedure. Attached the Change Management Procedure
Yes. We have a written Information security policy. Attached the same for your reference.
These policies are reviewed anually or whenever changes made to it and approved by the management as per the compliance requirements.
We have implemented the change management Procedure. All the IT changes takes place as per the Change management procedure. Attached the same for your reference.
Attached the IT policy. We also have communicated these to all the employees to spread awareness among them.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
Attached the Business continuity policy.
Attached the Business continuity plan
It’s a part of our system devolopment life cycle. Attached the policy.
Attached the Change management process.
Attached the Supplier Management Procedure
We have implemented the BYOD policy. Attached the same for your reference.
Attached the Change management process.
Please find attached Data Protection Policy and Data Retention and Disposal Policy
Data privay and Data protection is a part of our Infoarmation security awareness training.
Yes. Attached the Information Classification Policy
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also, our Policies has been reviewed and Audited annually. Attached the Business continuity policy, plan and procedures. We have test the BCP every 12 months and this has been reviewed as a part of Internal and external Audits.
Attached the Information security Policy
Attached the business continuity documents.
Attached the Information Security Policy and Risk Management Procedure
Yes, We have implemented the change management procedure and atatched the same for your referrence. The changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications.
  1. We have implimented the systems development life cycle (SDLC) and atatched the same for your referrence. 2. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. 3. We also conduct vulnerability and penetration testing and fix the identified observations. 4. Upon passing all the security and quality checks the new version of the product will be released.
Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements.
We provide applicable compliance Policies/Procedures, Audit/attestation reports, certifications etc.. on need basis.
Attached the Change Management Procedure
Attached the Security Incident Reporting & Response Procedure.
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also, our Policies have been reviewed and Audited annually. Attached the Business continuity policy, plan and procedures. We have tested the BCP every 12 months and this has been reviewed as a part of Internal and external Audits.
As per the compliance requirement and Business continuity policy we test the BCP plan every 12 months or upon significant organizational or environmental changes.
We conduct the BCP/DR Test on an annual basis as per the compliance requirements and audited during the internal and external audits. Our RTO & RPO is 60 minutes, Attached to the BCP/DR Policy.
Data backups are done daily and in a secured way in AWS. We also do test to comply with the business continuity plan.
Yes. We have Business continuity plan.
We communicate as per the BCP or the agreements or contracts
Yes. We have Media handling procedure.
Sure. We will provide the same.
Yes
We adhere to all the policies and procedures of the organization.
Yes. We have disciplinary policy
Yes. See Acceptable Use Policy attached.
We adhere to all the policies and procedures of the organization.
Yes. We have disciplinary policy
We are ISO 27001:2013 and GDPR Compliant organization. We have policies and procedures in place to comply with all the requirements and working effectively. We have Information security policy, Mobile Device Management Policy, Encryption Policy, Password Management Policy, Risk Management Procedure, Email Security Policy, Access control policy etc as per the compliance requirements. We also have implemented end point security in all our computers and servers to make sure that the data stored are safe, secure, and Protecting against non-human sources of risks.
Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with
Yes.
We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data.
Authorised Xoxoday employees only will have access controlled per the relevant policies attached
Yes
YesWe store password hashed. We have SHA512 hash with unique salt for every password
We have implemented the Password Management Policy. Only verified or authorised users can reset the password. No one can reset the password on behalf of somebody. We also follow the best practices for Password Protection and incorporated the same in the Password Management Policy.
All the changes takes place as per the change management procedure.
We have implemented the SDLC policy and made applicable to all the development and maintenance services, architecture, software and systems that are part of the Information Security Management System.
Implemeted the asset management policy
We are compliant. Attached the SDLC procedure. We folow General Coding Practice, test the information security features, Vulnerability scanning, Penetration Testing etc and mitigate all the risks identified.
We have implemented the Media protection procedures in order to make surer that the data is protected if we store it in any external drives.
We have implemented the Media protection procedures in order to make surer that the data is protected.
We have asset management policy and Media protection procedure to track the customer maintain the records.
It’s a part of of Asset management policy.
We have implemented the change management procedure
We have implemented the change management procedure
Capacity management has been well defined in our IT Policy
It’s a part of our change management and IT Policy.
We have Implemented the Physical security Policy and allowed access to only an authorised individual.
We have protected all the area as per the physical security Policy and allowed access to only an authorised individual.
We have implemented the Security Incident Reporting & Response Procedure
Attached the application Change management procedure
Our RPO/RTO is 6 mins. Attached the Business continuity documents
The BCP Test and lessons learned has been documented.
We have implemented the Incident Management Procedure and attached the same for your reference
Its part of our Incident Management Procedure
We report the incidents
Attached our Incident management procedure.
Yes. We have Policies and procedures in place. Our application also support for adding and removing users.
We have implemented policies and procedure with regards to DR. Since we have deployed our application on AWS cloud they only provide DR Services.
Yes. We have Policies and procedures in place. Our application also support for adding and removing users.
Yes. We have an Information Classification Policy and attached the same for your referrence. Information classification policy is primarily concerned with the management of information to ensure that sensitive information is handled well with respect to the threat it poses to an organization. It also demonstrates how gathered data is being used and structured within an organization to allow authorized personnel to get the right pieces of information at the right time, while also ensuring that only those who are authorized can view or access information. Sensitive data has been categorised as Confidential, Restricted, Internal, Public etc..
Yes. We have implemented the Acceptable Usage Policy and attached the same for your referrence. The policy outline the usage of Email, Computer Resources, Internet, Clean Desk and Clean Screen, Punitive actions, General guidelines etc.. We have a formal processess in place for security policies review and approval by the top level management as per the compliance requirements.
Yes. Xoxoday has developed a Risk Management Framework as part of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013 standard and SOC II compliance. The information security team assesses security risks annually and on an ongoing basis when major changes occur or when industry changes occur. Xoxoday Risk management process includes Risk Treatment, Mitigating Actions, Action Owners, Action Due Dates, Risk Acceptance, Risk Mitigation, Risk Avoiding, Risk Transfer, exceptins etc.. We also conduct the Risk assessment on annual basis and this has been audited as a part of an internal and external Audits.
Yes. Attached the Physical and Environmental Security Procedure.
Yes. Data backups are done daily and in a secured way in AWS. All the data backup will be stored on AWS virtual platform cloud. We also have implemented the Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Out DR/BCP plans are reviewed and approved by the management and tested on annual basis as per the compliance requirements. DR/BCP controls are validated during the internal and external audits.
Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
Yes
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles
Attached the Information security Policy
Yes. we have implemented the Business Continuity Plan to ensure that the data is managed during the conduct of business in a safe and secure manner in delivering the business values to the interested parties. Attached the BCP/DR policies and procedures.
Yes. we have Acceptable usage policy to outline the acceptable use of Information Security at Xoxoday.This policy applies to all employees – part time or full time, temporary or permanent, service providers with in-house engineers or consultants, contractors, and other workers at Xoxoday, including all personnel affiliated with third parties. This policy applies to all Information Security that is owned or leased by Xoxoday. Attached the Acceptable Usage Policy
Attached the Security Incident Reporting & Response Procedure and ncident Management Procedure
We adhered to the change management procedure and all the changes to the production systems will be upon review and approval of Chief Technology Officer (CTO) Attached change management procedures.
We have implemented the change management policy and all the changes to the platform takes palce as per the compliance process.
At Xoxoday we have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions. Appropriate roles and responsibilities have been defined and documented as part of the BC plan. At Xoxoday the BCP and DR Plan is tested and reviewed on a yearly basis. The BCP and DR plan of Xoxoday is reviewed and audited as part of internal and external audits.
We have implemente the Software Development Life Cycle (SDLC) procedures and attached the same for your reference. We have controls on external file sharing.
Sure. We will provide our Incident Management Procedure
Attached the Cyber Crisis Management Plan
We adhered to the change management procedure and all the changes to the production systems will be upon review and approval of Chief Technology Officer (CTO)
Attached the data classificaiton policy.
Yes. A formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions.
Yes. At Xoxoday we have implemented the Physical and Environmental Security Procedure. Physical entries have been restricted based on the role of the personnel within the organization. The restriction will be enforced using electronic locks with access through access cards and biometric machines. Third-party Access - The entrance premise of Xoxoday has been manned by security guards on a 24-hour basis. The guards shall verify all the visitors and direct them to the reception and provide temporary access cards. At the reception, the concerned employee shall be intimated, and he/she will escort the visitor on premises always. CCTVs has been placed at strategic points inside the facility Reception lobby, Entry and exit doors of the Xoxoday office, Entry and exit to parking areas, delivery, and dispatch areas etc. and monitored 24x7x365.
Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions
Attached the Incident Management Procedure
We have implemented the Business Continuity Policy and Business Continuity Management Procedure and BCP controls has been tested annually as per the compliance requirements and reviewed during the internal and external audits.
We have implemented the Identity access management and follow the Access control policy.