<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Application for approval of a new IT service on Virtosoftware Guides &amp; Docs</title><link>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/</link><description>Recent content in Application for approval of a new IT service on Virtosoftware Guides &amp; Docs</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 08 Nov 2024 18:43:03 +0000</lastBuildDate><atom:link href="https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/index.xml" rel="self" type="application/rss+xml"/><item><title>Maintenance</title><link>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/maintenance/</link><pubDate>Fri, 08 Nov 2024 18:43:03 +0000</pubDate><guid>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/maintenance/</guid><description>&lt;figure class="wp-block-table"&gt;&lt;table class="has-fixed-layout"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Maintenance&lt;/th&gt;&lt;th&gt;Supplier's response&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Are there logging functions for security-related events, and if so, which events do you log?&lt;/td&gt;&lt;td&gt;Nothing&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;How do you protect logging features and logging tools against tampering and unauthorized access, including from your own staff?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Describe how you inform customers about technical vulnerabilities. How and when do you report that you have discovered a vulnerability or leak?&lt;/td&gt;&lt;td&gt;Via email immediately&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Describe what you use for principles and methods for developing secure systems.&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have guidelines for information security in your development processes? How are these applied to major changes?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;The supplier must have routines for reviewing and testing the availability and security of changes to business-critical operating platforms. Describe your routines for reviewing and testing the availability and security of changes to business-critical operating platforms.&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have documented routines for monitoring, detecting, analyzing, reporting, escalating, and handling security events and security incidents?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you follow the routines for handling safety incidents from current laws and regulations?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Briefly describe your routines to ensure the availability of the system/application.&lt;/td&gt;&lt;td&gt;Internal information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Describe your routines for continuity and disaster management. How is our data protected from a reliability and accessibility perspective?&lt;/td&gt;&lt;td&gt;Data is always stored on your side. We don’t have access to it.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What are your SLA levels? (What do you guarantee for availability/uptime?)&lt;/td&gt;&lt;td&gt;Same as Azure&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;How often is data backed up?&lt;/td&gt;&lt;td&gt;We don’t store data&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;</description></item><item><title>Data Security</title><link>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/data-security/</link><pubDate>Fri, 08 Nov 2024 18:42:28 +0000</pubDate><guid>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/data-security/</guid><description>&lt;figure class="wp-block-table"&gt;&lt;table class="has-fixed-layout"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Data security&lt;/th&gt;&lt;th&gt;Supplier's response&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;How do you store credentials, such as passwords? (It also applies to system accounts in source code).&lt;/td&gt;&lt;td&gt;n/a, you install an app in your SharePoint and use your Office 365 credentials&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have rules that staff follow regarding how authentication information is handled?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Briefly describe how you allocate and update permissions for users and system components.&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;The supplier must protect and ensure that there is traceability in the tools intended for system maintenance, their security configuration, and their information. How do you protect these tools?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you own and operate your own data center, or is it outsourced to a third-party or cloud-based solution such as AWS/Azure? To whom is it outsourced?&lt;/td&gt;&lt;td&gt;We store it in Azure.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;If you have your data center, what level of protection does it have?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have routines that ensure that only authorized personnel have physical access to any potential data centers?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;The supplier must have routines regarding change management for the parts that may affect the delivery’s security and availability. Do you have routines regarding change management for components, systems, and other factors that may affect the security and availability of the delivery?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What malware protection do you use, and how often is it updated?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What security measures have you implemented against unauthorized access and unauthorized information modifications?&lt;/td&gt;&lt;td&gt;Internal information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Which authentication solution have you opted for?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have routines for conducting security tests, such as penetration testing?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;How do you mitigate any security incidents?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;</description></item><item><title>Information Security</title><link>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/information-security/</link><pubDate>Fri, 08 Nov 2024 18:40:11 +0000</pubDate><guid>https://docs-hugo-4dl.pages.dev/docs/virto-security-frequently-asked-questions-faq/application-for-approval-of-a-new-it-service/information-security/</guid><description>&lt;figure class="wp-block-table"&gt;&lt;table class="has-fixed-layout"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Information security&lt;/th&gt;&lt;th&gt;Supplier's response&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Do you have a policy that describes how employees may work remotely regarding the operation, management, and support of the services delivered?&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have processes and routines in place for background checks on staff?&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Have you signed a confidentiality agreement (NDA) with your employees? The confidentiality agreement must include information about your customers.&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have agreements that ensure confidentiality for subcontractors (NDA)?&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you regularly conduct staff training to increase information security awareness?&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Describe what measures you have in place for violating information security rules.&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have documented rules, routines, and roles that describe the permitted use of the resources included in the delivery?&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you have routines and features for permanently deleting information related to the delivery? (The supplier must, on request, be able to present evidence that this has happened.)&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you conduct regular risk assessments for the system/service/application?&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What routines do you have for information management?&lt;/td&gt;&lt;td&gt;Documents and procedures&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What are your guidelines for system administration accounts?&lt;/td&gt;&lt;td&gt;Internal information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Briefly describe what encryption routines you have in place.&lt;/td&gt;&lt;td&gt;Internal information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Do you encrypt all communications, and which encryption technologies are used?&lt;/td&gt;&lt;td&gt;n/a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Describe your data destruction procedures. What happens to customer data if a customer leaves you? How do you handle the decommissioning or temporarily managing databases and storage media holding customer-related information? Within what time period is it managed?&lt;/td&gt;&lt;td&gt;We don’t store customer data. All data is stored in your SharePoint tenant&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;</description></item></channel></rss>