Are all personnel required to sign NDA or Confidentiality Agreements as a condition of employment to protect customer/tenant information?
Are all personnel required to sign NDA or Confidentiality Agreements as a condition of employment to protect customer/tenant information?
Do you specifically train your employees, contractors, and third-party users regarding their specific role and the information security controls they must fulfill?
Do you specifically train your employees, contractors, and third-party users regarding their specific role and the information security controls they must fulfill?
Are personnel trained and provided with awareness programs at least once a year?
Are personnel trained and provided with awareness programs at least once a year?
Do you have an information security awareness training program? Do you perform phishing tests on your employees? Please describe frequency of the security awareness training, phishing exercises, and subjects addressed in your training.
Do you have an information security awareness training program? Do you perform phishing tests on your employees? Please describe frequency of the security awareness training, phishing exercises, and subjects addressed in your training.
Do all staff receive information security awareness training?
Do all staff receive information security awareness training?
Are all systems security configuration standards documented and based on external industry or vendor guidance?
Are all systems security configuration standards documented and based on external industry or vendor guidance?
Is a Training and Awareness Program maintained that addresses data privacy and data protection obligations based on role?
Is a Training and Awareness Program maintained that addresses data privacy and data protection obligations based on role?
Does the organization conduct pre-joining & periodic information security trainings & awareness programs to convey criticality of the customer data?
Does the organization conduct pre-joining & periodic information security trainings & awareness programs to convey criticality of the customer data?
Describe your security awareness program for personnel
Describe your security awareness program for personnel
Third parties should ensure its personnel have role-based training programme for information security on an annual basis.
Third parties should ensure its personnel have role-based training programme for information security on an annual basis.
What kind of cloud security awareness you provide to your administrators?
What kind of cloud security awareness you provide to your administrators?
Do all staff formally complete annual end user security awareness training?
Do all staff formally complete annual end user security awareness training?
Are data privacy compliance taken into consideration in the design of new and/or redevelopment of existing systems or business processes? (If so please detail how and when)
Are data privacy compliance taken into consideration in the design of new and/or redevelopment of existing systems or business processes? (If so please detail how and when)
