Open poliarush opened 1 year ago
What technical measures protect the data in relation to this asset? Please choose from the following, and/or add your own.
Select all that apply:
What organisational measures protect the data in relation to the product/service provided by this vendor? Please choose from the following, and/or add your own.
I'm undertaking an analysis of Test Management tools and have the following questions on Testomat: a) Does it provide 2FA or something similar in terms of access/logon? b) Where is the data hosted? Is it possible to choose the location? c) Does the Product have ISO27001 Accreditation or similar? If similar what accreditation.
I just need some additional security documentation for my review. Typically, we look for our vendors to have security documentation to the level of a current SOC2 report, ISO27001 certification, or at least a Security Whitepaper covering industry standards for critical security controls.
Additionally, I can see that you have attached external penetration reports to the vendor form. Are you able to also provide a high level overview confirming actions taken to mitigate the findings within these reports?
- Considering Data (either in transit, at rest, or at endpoints), and
- Confidentiality, Integrity and Availability of services provided
The Answer needs to be provided with either of the 3 options; Yes, No, or Not Applicable, followed by the responses in detail for all the questions.
Meanwhile, if you can share the SOC 2 report, ISO 27001:2013 certificate, and Information Security Policies, to enable us to begin the Vendor Security review process?
Introduction
Servers Security
Data Security
Access Control
Network Security
Application Security
Incident Response
Third-party Integrations
Compliance and Certifications
Employee Training and Awareness
Security Audits
User Best Practices
Resources and Tools
Feedback and Reporting
Updates and Changelog
Conclusion and Assurance
Also, users requests following questions, we should have answers for such questions on the page: