Do you have the capability to rapidly patch vulnerabilities across all of your computing devices, applications, and systems?
Do you have the capability to rapidly patch vulnerabilities across all of your computing devices, applications, and systems?
Do you have anti-malware programs that support or connect to your cloud service offerings installed on all of your systems?
Do you have anti-malware programs that support or connect to your cloud service offerings installed on all of your systems?
Do you conduct local operating system-layer vulnerability scans regularly as prescribed by industry best practices?
Do you conduct local operating system-layer vulnerability scans regularly as prescribed by industry best practices?
Do you conduct network-layer vulnerability scans regularly as prescribed by industry best practices?
Do you conduct network-layer vulnerability scans regularly as prescribed by industry best practices?
Do you conduct application-layer vulnerability scans regularly as prescribed by industry best practices?
Do you conduct application-layer vulnerability scans regularly as prescribed by industry best practices?
Will you make the results of vulnerability scans available to tenants at their request?
Will you make the results of vulnerability scans available to tenants at their request?
Do you have controls and processes in place to perform host/file integrity monitoring for all systems storing and transmitting sensitive data?
Do you have controls and processes in place to perform host/file integrity monitoring for all systems storing and transmitting sensitive data?
Do you conduct daily vulnerability scans at the operating system layer?
Do you conduct daily vulnerability scans at the operating system layer?
Do you conduct daily vulnerability scans at the database layer?
Do you conduct daily vulnerability scans at the database layer?
Do you conduct daily vulnerability scans at the application layer?
Do you conduct daily vulnerability scans at the application layer?
Do you have external third-party services conduct vulnerability scans and periodic penetration tests on your applications and networks?
Do you have external third-party services conduct vulnerability scans and periodic penetration tests on your applications and networks?
Whom do we contact if we identify a security issue or breach involving or impacting your product? Please provide an email address and/or full contact information?
Whom do we contact if we identify a security issue or breach involving or impacting your product? Please provide an email address and/or full contact information?
Do you conduct application and infrastructure penetration tests of your infrastructure regularly as prescribed by industry best practices and guidance?
Do you conduct application and infrastructure penetration tests of your infrastructure regularly as prescribed by industry best practices and guidance?
Are the results of the penetration tests available to customers at their request?
Are the results of the penetration tests available to customers at their request?
Do you have external third party services conduct vulnerability scans and periodic penetration tests on production and publicly facing applications, systems and infrastructure?
Do you have external third party services conduct vulnerability scans and periodic penetration tests on production and publicly facing applications, systems and infrastructure?
What are your timelines for remediation on: Critical, High, Medium, and Low vulnerabilities?
What are your timelines for remediation on: Critical, High, Medium, and Low vulnerabilities?
Do you conduct application and network-layer vulnerability scans regularly as prescribed by industry best practices? What tool? Frequency? Provide evidence.
Do you conduct application and network-layer vulnerability scans regularly as prescribed by industry best practices? What tool? Frequency? Provide evidence.
Do you have a capability to patch vulnerabilities across all of your computing devices, applications, and systems?
Do you have a capability to patch vulnerabilities across all of your computing devices, applications, and systems?
Is VA / PT performed at regular intervals? If yes, what is the frequency
Is VA / PT performed at regular intervals? If yes, what is the frequency
How does vendor ensure Application Security for the customer services in Cloud?
How does vendor ensure Application Security for the customer services in Cloud?
How does vendor ensure Secure configurations of Operating System on cloud?
How does vendor ensure Secure configurations of Operating System on cloud?
How does vendor ensure Secure configurations of Database on cloud?
How does vendor ensure Secure configurations of Database on cloud?
Clearly defined responsibility for closure of observations as well as adherence to the customer remediation timeframes
Clearly defined responsibility for closure of observations as well as adherence to the customer remediation timeframes
Is there a defined process set by function to review critical transactions
Is there a defined process set by function to review critical transactions
Is regular network vulnerability scanning performed?
Is regular network vulnerability scanning performed?
Is application vulnerability scanning performed on regular intervals?
Is application vulnerability scanning performed on regular intervals?
Regular appraisals of security controls as well as security hardening and patching of systems is performed.
Regular appraisals of security controls as well as security hardening and patching of systems is performed.
Does the Company conduct technical security assessments (e.g. vulnerability, penetration tests) on its own IT environment?
Does the Company conduct technical security assessments (e.g. vulnerability, penetration tests) on its own IT environment?
How often do you scan for vulnerabilities on your network and applications?
How often do you scan for vulnerabilities on your network and applications?
What is your vulnerability remediation process?
What is your vulnerability remediation process?
Are all 3rd Party Libraries regularly reviewed and checked for potential vulnerabilities?
Are all 3rd Party Libraries regularly reviewed and checked for potential vulnerabilities?
Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?
Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?
Has an independent third party performed a Penetration Test covering the solution to be provided to Customer?
Has an independent third party performed a Penetration Test covering the solution to be provided to Customer?
The vendor should specify what ongoing security testing they perform on their product, such as static and / or dynamic code analysis and any automated or manual penetration testing.
The vendor should specify what ongoing security testing they perform on their product, such as static and / or dynamic code analysis and any automated or manual penetration testing.
Penetration Testing: Does the vendor perform penetration testing on a regular basis?
Penetration Testing: Does the vendor perform penetration testing on a regular basis?
Do you conduct regular vulnerability assessment to the service/platform you are providing for customers? For example, Asset Check/Vulnerability scan/Penetration test?
Do you conduct regular vulnerability assessment to the service/platform you are providing for customers? For example, Asset Check/Vulnerability scan/Penetration test?
NSE shall comply with the control requirements of Operations Security Policy of NSE for the Operating system, database and application, as applicable.
NSE shall comply with the control requirements of Operations Security Policy of NSE for the Operating system, database and application, as applicable.
How are these procedures validated?
How are these procedures validated?
How are security vulnerabilities identified in Supplier developed applications?
How are security vulnerabilities identified in Supplier developed applications?
What testing is done during a penetration test?
What testing is done during a penetration test?
How is your network security testing performed? Internal, third parties or both? If so, how often is it tested? Explain your methodology
How is your network security testing performed? Internal, third parties or both? If so, how often is it tested? Explain your methodology
Please summarise or attach your network vulnerability management processes and procedures?
Please summarise or attach your network vulnerability management processes and procedures?
What is your timeframe for patching critical vulnerabilities?
What is your timeframe for patching critical vulnerabilities?
What tools do you use for vulnerability managment?
What tools do you use for vulnerability managment?
Please summarise or attach your application vulnerability management processes and procedures?
Please summarise or attach your application vulnerability management processes and procedures?
What tools do you use for application vulnerability management?
What tools do you use for application vulnerability management?
Avoiding sources of risk
Avoiding sources of risk
All applications, third-party applications, software and firmware (for all provided system components such as network devices) are covered under patch and vulnerability management processes
All applications, third-party applications, software and firmware (for all provided system components such as network devices) are covered under patch and vulnerability management processes
Third parties shall have Incident management process to support the customer during information security incidents including, but not limited to: Information security incident of supplier-provided system at the customer. Vulnerability report on supplier provided systems for the customer.
Third parties shall have Incident management process to support the customer during information security incidents including, but not limited to: Information security incident of supplier-provided system at the customer. Vulnerability report on supplier provided systems for the customer.
Third parties shall have vulnerability management process for all its supplied systems.
Third parties shall have vulnerability management process for all its supplied systems.
Details on how to manage system vulnerabilities and inform the customer on start and resolution of security issue shall be provided.
Details on how to manage system vulnerabilities and inform the customer on start and resolution of security issue shall be provided.
Vulnerability assessments shall be conducted for all new information assets during testing and prior to production operations.
Vulnerability assessments shall be conducted for all new information assets during testing and prior to production operations.
Security and robustness testing of protocols shall be considered during procurement and installation phases in the lifecycle to discover and mitigate security vulnerabilities.
Security and robustness testing of protocols shall be considered during procurement and installation phases in the lifecycle to discover and mitigate security vulnerabilities.
As part of system tests (such as Factory Acceptance Test, Loop Test, Integrated Factory Acceptance Test, Functional Test and Site Acceptance Test), the functionality of input/output data validation, control of internal processing and data integrity of systems shall be verified.
As part of system tests (such as Factory Acceptance Test, Loop Test, Integrated Factory Acceptance Test, Functional Test and Site Acceptance Test), the functionality of input/output data validation, control of internal processing and data integrity of systems shall be verified.
Periodic Integrity verification methods shall be performed to detect, record, report, and protect against the effects of tampering.
Periodic Integrity verification methods shall be performed to detect, record, report, and protect against the effects of tampering.
All products and components shall be hardened as per the customer documented security and operational baselines taking in consideration vendor's specific recommendations and endorsement.
All products and components shall be hardened as per the customer documented security and operational baselines taking in consideration vendor's specific recommendations and endorsement.
Configuration baselines shall be continually managed to maintain applicability as software is updated or patched, security vulnerabilities are reported, or configurations are modified to allow the installation of new software or to support new operational requirements.
Configuration baselines shall be continually managed to maintain applicability as software is updated or patched, security vulnerabilities are reported, or configurations are modified to allow the installation of new software or to support new operational requirements.
Identify anti-malicious code protection requirements for networks and hosts.
Identify anti-malicious code protection requirements for networks and hosts.
Security risks associated with technical vulnerabilities, throughout the lifecycle, shall be managed through activities such as: Identification of potentially applicable technical vulnerabilities. Evaluation of applicability of technical vulnerabilities. Evaluation of risk to the customer from applicable technical vulnerabilities. Remediation of technical vulnerabilities based on criticality. Mitigation of technical vulnerabilities that remain un-remediated. Monitoring of risk associated with un-remediated technical vulnerabilities.
Security risks associated with technical vulnerabilities, throughout the lifecycle, shall be managed through activities such as: Identification of potentially applicable technical vulnerabilities. Evaluation of applicability of technical vulnerabilities. Evaluation of risk to the customer from applicable technical vulnerabilities. Remediation of technical vulnerabilities based on criticality. Mitigation of technical vulnerabilities that remain un-remediated. Monitoring of risk associated with un-remediated technical vulnerabilities.
Timelines for each phase of the technical vulnerability management lifecycle shall be defined: Timelines shall specify the maximum time between Identification, Evaluation, Remediation/Mitigation and Monitoring phases. Timelines shall be based on the risk to the entity. Timelines shall be defined in a standard specific to each entity or function.
Timelines for each phase of the technical vulnerability management lifecycle shall be defined: Timelines shall specify the maximum time between Identification, Evaluation, Remediation/Mitigation and Monitoring phases. Timelines shall be based on the risk to the entity. Timelines shall be defined in a standard specific to each entity or function.
Technical vulnerabilities shall be evaluated: Each relevant technical vulnerability shall be evaluated for both applicability and criticality. Applicable technical vulnerabilities shall be recorded against applicable assets. This may be incorporated into Asset Inventory. For all technical vulnerabilities determined to be applicable, the customer shall evaluate the risk to the OT and the customer through Risk Assessment Processes. Remediation/mitigation and compliance reports shall be produced including topics such as: List of Vulnerabilities - All discovered vulnerabilities, the severity, and the affected systems. Remediation and/or mitigation recommendation - Each listed vulnerability shall have detailed information on how the vulnerability will be remediated or mitigated. Non-compliance summary.
Technical vulnerabilities shall be evaluated: Each relevant technical vulnerability shall be evaluated for both applicability and criticality. Applicable technical vulnerabilities shall be recorded against applicable assets. This may be incorporated into Asset Inventory. For all technical vulnerabilities determined to be applicable, the customer shall evaluate the risk to the OT and the customer through Risk Assessment Processes. Remediation/mitigation and compliance reports shall be produced including topics such as: List of Vulnerabilities - All discovered vulnerabilities, the severity, and the affected systems. Remediation and/or mitigation recommendation - Each listed vulnerability shall have detailed information on how the vulnerability will be remediated or mitigated. Non-compliance summary.
Technical vulnerabilities shall be remediated or mitigated in timely manner following Change Management Processes: A phased rollout can be used to minimise impact. Establish expected remediation/mitigation timelines based on the criticality rating level. Any deviations to the customer defined management of technical vulnerability requirements should be recorded. Risks due to deviations shall be managed to acceptable levels through compensating controls.
Technical vulnerabilities shall be remediated or mitigated in timely manner following Change Management Processes: A phased rollout can be used to minimise impact. Establish expected remediation/mitigation timelines based on the criticality rating level. Any deviations to the customer defined management of technical vulnerability requirements should be recorded. Risks due to deviations shall be managed to acceptable levels through compensating controls.
Technical vulnerabilities shall be Monitored: As factors in the risk equation change, un-remediated technical vulnerabilities shall be reviewed at a defined interval to ensure that current controls are still effective at managing risk to an acceptable level.
Technical vulnerabilities shall be Monitored: As factors in the risk equation change, un-remediated technical vulnerabilities shall be reviewed at a defined interval to ensure that current controls are still effective at managing risk to an acceptable level.
All reports of potential technical security vulnerabilities on operational systems must be communicated promptly to all relevant internal stakeholders, in a timely manner, on a restricted basis, in order to effectively manage associated security risks.
All reports of potential technical security vulnerabilities on operational systems must be communicated promptly to all relevant internal stakeholders, in a timely manner, on a restricted basis, in order to effectively manage associated security risks.
the customer reserves the right to intercept and monitor information processed by the customer information resources and networks. This activity is solely used to identify threats to company information assets and enable early detection of potential malicious activities.
the customer reserves the right to intercept and monitor information processed by the customer information resources and networks. This activity is solely used to identify threats to company information assets and enable early detection of potential malicious activities.
The appropriate the customer stakeholders shall be informed of all potential vulnerabilities and non-compliance issues on a regular basis and be accountable for providing adequate resources to mitigate these issues.
The appropriate the customer stakeholders shall be informed of all potential vulnerabilities and non-compliance issues on a regular basis and be accountable for providing adequate resources to mitigate these issues.
Service Provider shall employ an independent security professional to perform penetration testing and other types of security testing on at least an annual basis or after major changes.
Service Provider shall employ an independent security professional to perform penetration testing and other types of security testing on at least an annual basis or after major changes.
Does the vendor use Third Party vulnerability testing of the infrastructure and the application?
Does the vendor use Third Party vulnerability testing of the infrastructure and the application?
Will any detected security violations and incidents be reported to the X Company Information Security Manager?
Will any detected security violations and incidents be reported to the X Company Information Security Manager?
What are the contract termination processes? How will we have access to our data on termination of the service? Would our data be completely deleted from the vendor's servers after termination?
What are the contract termination processes? How will we have access to our data on termination of the service? Would our data be completely deleted from the vendor's servers after termination?
How often do you perform periodic vulnerability scans on your information technology systems, networks and supporting security systems? i.e. Internal assessments, third party assessments, automated? What is the security patch management cadence to address vulnerabilities identified?
How often do you perform periodic vulnerability scans on your information technology systems, networks and supporting security systems? i.e. Internal assessments, third party assessments, automated? What is the security patch management cadence to address vulnerabilities identified?
Do you conduct vulnerability scanning or Penetration tests?
Do you conduct vulnerability scanning or Penetration tests?
A copy or summary of the most recent vulnerability assessments or penetration tests performed against the product or environment – this summary should include a statement on remediation of vulnerabilities from management.
A copy or summary of the most recent vulnerability assessments or penetration tests performed against the product or environment – this summary should include a statement on remediation of vulnerabilities from management.
Infrastructure security standard and hardening processes
Infrastructure security standard and hardening processes
Dynamic application security test report
Dynamic application security test report
Are all 3rd Party Libraries regularly reviewed and checked for potential vulnerabilities? (2)
Are all 3rd Party Libraries regularly reviewed and checked for potential vulnerabilities? (2)
Perform ongoing security assessments to identify and remediate high risk vulnerabilities on servers, data stores, web applications, and dependent systems and software.
Perform ongoing security assessments to identify and remediate high risk vulnerabilities on servers, data stores, web applications, and dependent systems and software.
3rd party components shall be evaluated for known vulnerabilities prior to and during use in production. Protect against supply chain threats to the information system, system component, or information system service by employing security safeguards as part of a comprehensive, defense-in-breadth information security strategy. EIS Architecture team shall be notified to conduct an assessment of the information system, system component, or information system service prior to selection, acceptance, or update. Review & replace information system components when support for the components is no longer available from the developer, vendor, or manufacturer; and Provides justification and documents approval for the continued use of unsupported system components required to satisfy mission/business needs.
3rd party components shall be evaluated for known vulnerabilities prior to and during use in production. Protect against supply chain threats to the information system, system component, or information system service by employing security safeguards as part of a comprehensive, defense-in-breadth information security strategy. EIS Architecture team shall be notified to conduct an assessment of the information system, system component, or information system service prior to selection, acceptance, or update. Review & replace information system components when support for the components is no longer available from the developer, vendor, or manufacturer; and Provides justification and documents approval for the continued use of unsupported system components required to satisfy mission/business needs.
Application must ensure that input validation or encoding routines must be performed and enforced on the server side. I.e. a centralized input validation strategy must be used where appropriate. Client-side validation can be implemented as an additional layer of security.
Application must ensure that input validation or encoding routines must be performed and enforced on the server side. I.e. a centralized input validation strategy must be used where appropriate. Client-side validation can be implemented as an additional layer of security.
Are there any open vulnerabilities which have not been patched?
Are there any open vulnerabilities which have not been patched?
Is security testing conducted wherever required before production release and vulnerabilities mitigated before release?
Is security testing conducted wherever required before production release and vulnerabilities mitigated before release?
Does the provider perform regular vulnerability assessments/penetration tests to determine security gaps? If so, state the date of the most recent vulnerability assessment/penetration test and provide a comprehensive list of all security risks/gaps identified
Does the provider perform regular vulnerability assessments/penetration tests to determine security gaps? If so, state the date of the most recent vulnerability assessment/penetration test and provide a comprehensive list of all security risks/gaps identified
