diff --git a/_pages/security/caiq.md b/_pages/security/caiq.md new file mode 100644 index 00000000..cf4ab761 --- /dev/null +++ b/_pages/security/caiq.md @@ -0,0 +1,410 @@ +--- +layout: page +title: CAIQ +subtitle: "TBA" +permalink: /security/caiq/ +published: true +--- + + +We use the Consensus Assessments Initiative Questionnaire Lite (CAIQ-Lite) from the Cloud Security Alliance as a baseline mechanism to express our security posture in real terms and to provide security control transparency. + +We’ve made this publicly available to help customers assess our security posture for their own vendor management initiatives. Please reach out to our security people over at security@glitchsecure.com if you have any queries. + +# Audit and Assurance + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| A&A-02.1 | Are independent audit and assurance assessments conducted according to relevant standards at least annually? | NO | +| A&A-03.1 | Are independent audit and assurance assessments performed according to risk-based plans and policies? | NO | +| A&A-04.1 | Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit? | YES | +| A&A-06.1 | Is a risk-based corrective action plan to remediate audit findings established, documented, approved, communicated, applied, evaluated, and maintained? | YES | +| A&A-06.2 | Is the remediation status of audit findings reviewed and reported to relevant stakeholders? | YES | + +#### CSP Implementation Descriptions + +- **A&A-02.1**: Currently we are in the process of documenting our existing practices and procedures to fully prepare for an independent audit. +- **A&A-03.1**: See above. +- **A&A-04.1**: Yes. We provide full details of this via our customer agreements, terms of service, and privacy policy on our website. +- **A&A-06.1**: Yes. We provide a full vulnerability disclosure policy on our security page. +- **A&A-06.2**: + + + +# Application & Interface Security + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| AIS-02.1 | Are baseline requirements to secure different applications established, documented, and maintained? | YES | +| AIS-04.1 | Is an SDLC process defined and implemented for application design, development, deployment, and operation per organizationally designed security requirements? | YES | +| AIS-06.1 | Are strategies and capabilities established and implemented to deploy application code in a secure, standardized, and compliant manner? | YES | +| AIS-06.2 | Is the deployment and integration of application code automated where possible? | YES | +| AIS-07.1 | Are application security vulnerabilities remediated following defined processes? | YES | +| AIS-07.2 | Is the remediation of application security vulnerabilities automated when possible? | YES | + +#### CSP Implementation Descriptions + +- **AIS-02.1**: +- **AIS-04.1**: +- **AIS-06.1**: +- **AIS-06.2**: +- **AIS-07.1**: +- **AIS-07.2**: + + + +# Business Continuity Mgmt & Op Resilience + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| BCR-01.1 | Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | NO | +| BCR-01.2 | Are the policies and procedures reviewed and updated at least annually? | NO | +| BCR-02.1 | Are criteria for developing business continuity and operational resiliency strategies and capabilities established based on business disruption and risk impacts? | N/A | +| BCR-03.1 | Are strategies developed to reduce the impact of, withstand, and recover from business disruptions in accordance with risk appetite? | YES | +| BCR-08.1 | Is cloud data periodically backed up? | YES | +| BCR-08.2 | Is the confidentiality, integrity, and availability of backup data ensured? | YES | +| BCR-08.3 | Can backups be restored appropriately for resiliency? | YES | +| BCR-09.1 | Is a disaster response plan established, documented, approved, applied, evaluated, and maintained to ensure recovery from natural and man-made disasters? | NO | +| BCR-09.2 | Is the disaster response plan updated at least annually, and when significant changes occur? | NO | + +#### CSP Implementation Descriptions + +- **BCR-01.1**: +- **BCR-01.2**: +- **BCR-02.1**: +- **BCR-03.1**: +- **BCR-08.1**: +- **BCR-08.2**: +- **BCR-08.3**: +- **BCR-09.1**: +- **BCR-09.2**: + +# Change Control & Configuration Management + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| CCC-01.1 | Are risk management policies and procedures associated with changing organizational assets including applications, systems, infrastructure, configuration, etc., established, documented, approved, communicated, applied, evaluated and maintained (regardless of whether asset management is internal or external)? | NO | +| CCC-01.2 | Are the policies and procedures reviewed and updated at least annually? | NO | +| CCC-02.1 | Is a defined quality change control, approval and testing process (with established baselines, testing, and release standards) followed? | YES | +| CCC-04.1 | Is the unauthorized addition, removal, update, and management of organization assets restricted? | YES | +| CCC-05.1 | Are provisions to limit changes that directly impact CSC-owned environment and require tenants to authorize requests explicitly included within the service level agreements (SLAs) between CSPs and CSCs? | YES | +| CCC-06.1 | Are change management baselines established for all relevant authorized changes on organizational assets? | YES | +| CCC-07.1 | Are detection measures implemented with proactive notification if changes deviate from established baselines? | YES | +| CCC-09.1 | Is a process to proactively roll back changes to a previously known "good state" defined and implemented in case of errors or security concerns? | YES | + +#### CSP Implementation Descriptions + +- **CCC-01.1**: +- **CCC-01.2**: +- **CCC-02.1**: +- **CCC-04.1**: +- **CCC-05.1**: +- **CCC-06.1**: +- **CCC-07.1**: +- **CCC-09.1**: + + +# Cryptography, Encryption & Key Management + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| CEK-01.1 | Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | YES | +| CEK-01.2 | Are cryptography, encryption, and key management policies and procedures reviewed and updated at least annually? | YES | +| CEK-02.1 | Are cryptography, encryption, and key management roles and responsibilities defined and implemented? | YES | +| CEK-03.1 | Are data at-rest and in-transit cryptographically protected using cryptographic libraries certified to approved standards? | YES | +| CEK-04.1 | Are appropriate data protection encryption algorithms used that consider data classification, associated risks, and encryption technology usability? | YES | +| CEK-05.1 | Are standard change management procedures established to review, approve, implement and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources? | YES | +| CEK-10.1 | Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications? | YES | +| CEK-12.1 | Are cryptographic keys rotated based on a cryptoperiod calculated while considering information disclosure risks and legal and regulatory requirements? | NO | +| CEK-13.1 | Are cryptographic keys revoked and removed before the end of the established cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures to include legal and regulatory requirement provisions? | YES | +| CEK-14.1 | Are processes, procedures and technical measures to destroy unneeded keys defined, implemented and evaluated to address key destruction outside secure environments, revocation of keys stored in hardware security modules (HSMs), and include applicable legal and regulatory requirement provisions? | YES | + +#### CSP Implementation Descriptions + +- **CEK-01.1**: +- **CEK-01.2**: +- **CEK-02.1**: +- **CEK-03.1**: +- **CEK-04.1**: +- **CEK-05.1**: +- **CEK-10.1**: +- **CEK-12.1**: +- **CEK-13.1**: +- **CEK-14.1**: + +# Datacenter Security + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| DCS-03.1 | Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained? | NO | +| DCS-03.2 | Are policies and procedures for maintaining safe, secure working environments (e.g., offices, rooms) reviewed and updated at least annually? | NO | +| DCS-05.1 | Is the classification and documentation of physical and logical assets based on the organizational business risk? | YES | +| DCS-06.1 | Are all relevant physical and logical assets at all CSP sites cataloged and tracked within a secured system? | YES | + +#### CSP Implementation Descriptions + +- **DCS-03.1**: +- **DCS-03.2**: +- **DCS-05.1**: +- **DCS-06.1**: + +# Data Security & Privacy + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| DSP-01.1 | Are policies and procedures established, documented, approved, communicated, enforced, evaluated, and maintained for the classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level? | YES | +| DSP-01.2 | Are data security and privacy policies and procedures reviewed and updated at least annually? | YES | +| DSP-03.1 | Is a data inventory created and maintained for sensitive and personal information (at a minimum)? | YES | +| DSP-04.1 | Is data classified according to type and sensitivity levels? | YES | +| DSP-05.1 | Is data flow documentation created to identify what data is processed and where it is stored and transmitted? | NO | +| DSP-05.2 | Is data flow documentation reviewed at defined intervals, at least annually, and after any change? | NO | +| DSP-06.1 | Is the ownership and stewardship of all relevant personal and sensitive data documented? | YES | +| DSP-06.2 | Is data ownership and stewardship documentation reviewed at least annually? | YES | +| DSP-07.1 | Are systems, products, and business practices based on security principles by design and per industry best practices? | YES | +| DSP-08.1 | Are systems, products, and business practices based on privacy principles by design and according to industry best practices? | YES | +| DSP-08.2 | Are systems' privacy settings configured by default and according to all applicable laws and regulations? | YES | +| DSP-10.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope (as permitted by respective laws and regulations)? | YES | +| DSP-11.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable data subjects to request access to, modify, or delete personal data (per applicable laws and regulations)? | YES | +| DSP-12.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure personal data is processed (per applicable laws and regulations and for the purposes declared to the data subject)? | YES | +| DSP-13.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated for the transfer and sub-processing of personal data within the service supply chain (according to any applicable laws and regulations)? | YES | +| DSP-14.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to disclose details to the data owner of any personal or sensitive data access by sub-processors before processing initiation? | YES | +| DSP-16.1 | Do data retention, archiving, and deletion practices follow business requirements, applicable laws, and regulations? | YES | +| DSP-17.1 | Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle? | YES | +| DSP-19.1 | Are processes, procedures, and technical measures defined and implemented to specify and document physical data locations, including locales where data is processed or backed up? | YES | + +#### CSP Implementation Descriptions + +- **DSP-01.1**: +- **DSP-01.2**: +- **DSP-03.1**: +- **DSP-04.1**: +- **DSP-05.1**: +- **DSP-05.2**: +- **DSP-06.1**: +- **DSP-06.2**: +- **DSP-07.1**: +- **DSP-08.1**: +- **DSP-08.2**: +- **DSP-10.1**: +- **DSP-11.1**: +- **DSP-12.1**: +- **DSP-13.1**: +- **DSP-14.1**: +- **DSP-16.1**: +- **DSP-17.1**: +- **DSP-19.1**: + +# Governance, Risk Management & Compliance + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| GRC-01.1 | Are information governance program policies and procedures sponsored by organizational leadership established, documented, approved, communicated, applied, evaluated, and maintained? | NO | +| GRC-01.2 | Are the policies and procedures reviewed and updated at least annually? | NO | +| GRC-02.1 | Is there an established formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks? | NO | +| GRC-06.1 | Are roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs defined and documented? | NO | +| GRC-07.1 | Are all relevant standards, regulations, legal/contractual, and statutory requirements applicable to your organization identified and documented? | YES | + +#### CSP Implementation Descriptions + +- **GRC-01.1**: +- **GRC-01.2**: +- **GRC-02.1**: +- **GRC-06.1**: +- **GRC-07.1**: + +# Human Resources Security + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| HRS-03.1 | Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained? | NO | +| HRS-03.2 | Are policies and procedures requiring unattended workspaces to conceal confidential data reviewed and updated at least annually? | NO | +| HRS-04.1 | Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained? | NO | +| HRS-04.2 | Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations reviewed and updated at least annually? | NO | +| HRS-11.1 | Is a security awareness training program for all employees of the organization established, documented, approved, communicated, applied, evaluated and maintained? | NO | +| HRS-11.2 | Are regular security awareness training updates provided? | NO | + + +#### CSP Implementation Descriptions + +- **HRS-03.1**: +- **HRS-03.2**: +- **HRS-04.1**: +- **HRS-04.2**: +- **HRS-11.1**: +- **HRS-11.2**: + +# Identity & Access Management + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| IAM-01.1 | Are identity and access management policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained? | YES | +| IAM-01.2 | Are identity and access management policies and procedures reviewed and updated at least annually? | YES | +| IAM-03.1 | Is system identity information and levels of access managed, stored, and reviewed? | | +| IAM-04.1 | Is the separation of duties principle employed when implementing information system access? | | +| IAM-05.1 | Is the least privilege principle employed when implementing information system access? | | +| IAM-06.1 | Is a user access provisioning process defined and implemented which authorizes, records, and communicates data and assets access changes? | | +| IAM-07.1 | Is a process in place to de-provision or modify the access, in a timely manner, of movers / leavers or system identity changes, to effectively adopt and communicate identity and access management policies? | | +| IAM-08.1 | Are reviews and revalidation of user access for least privilege and separation of duties completed with a frequency commensurate with organizational risk tolerance? | | +| IAM-09.1 | Are processes, procedures, and technical measures for the segregation of privileged access roles defined, implemented, and evaluated such that administrative dataaccess, encryption, key management capabilities, and logging capabilities are distinct and separate? | | +| IAM-10.1 | Is an access process defined and implemented to ensure privileged access roles and rights are granted for a limited period? | | +| IAM-10.2 | Are procedures implemented to prevent the culmination of segregated privileged access? | | +| IAM-14.1 | Are processes, procedures, and technical measures for authenticating access to systems, application, and data assets including multifactor authentication for a least-privileged user and sensitive data access defined, implemented, and evaluated? | | +| IAM-14.2 | Are digital certificates or alternatives that achieve an equivalent securitylevel for system identities adopted? | | + +#### CSP Implementation Descriptions + +- **IAM-01.1**: +- **IAM-01.2**: +- **IAM-03.1**: +- **IAM-04.1**: +- **IAM-05.1**: +- **IAM-06.1**: +- **IAM-07.1**: +- **IAM-08.1**: +- **IAM-09.1**: +- **IAM-10.1**: +- **IAM-10.2**: +- **IAM-14.1**: +- **IAM-14.2**: + +# Interoperability & Portability + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| IPY-01.1 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for communications between application services(e.g., APIs)? | | +| IPY-01.2 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information processing interoperability? | | +| IPY-01.3 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for application development portability? | | +| IPY-01.4 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information/data exchange, usage, portability, integrity, and persistence? | | +| IPY-01.5 | Are interoperability and portability policies and procedures reviewed and updated at least annually? | | + +#### CSP Implementation Descriptions + +- **IPY-01.1**: +- **IPY-01.2**: +- **IPY-01.3**: +- **IPY-01.4**: +- **IPY-01.5**: + +# Infrastructure & Virtualization Security + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| IVS-03.1 | Are communications between environments monitored? | | +| IVS-03.2 | Are communications between environments encrypted? | | +| IVS-03.3 | Are communications between environments restricted to only authenticated and authorized connections, as justified by the business? | | +| IVS-03.4 | Are network configurations reviewed at least annually? | | +| IVS-03.5 | Are network configurations supported by the documented justification of all allowed services, protocols, ports, and compensating controls? | | +| IVS-04.1 | Is every host and guest OS, hypervisor, or infrastructure control plane hardened(according to their respective best practices) and supported by technical controls as part of a security baseline? | | +| IVS-06.1 | Are applications and infrastructures designed, developed, deployed, and configured such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented, segregated, monitored, and restricted from other tenants? | | +| IVS-07.1 | Are secure and encrypted communication channels including only up-to-date and approved protocols used when migrating servers, services, applications, or data to cloud environments? | | +| IVS-09.1 | Are processes, procedures, and defense-in-depth techniques defined, implemented, and evaluated for protection, detection, and timely response to network-based attacks? | | + +#### CSP Implementation Descriptions + +- **IVS-03.1**: +- **IVS-03.2**: +- **IVS-03.3**: +- **IVS-03.4**: +- **IVS-03.5**: +- **IVS-04.1**: +- **IVS-06.1**: +- **IVS-07.1**: +- **IVS-09.1**: + +# Logging & Monitoring + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| LOG-01.1 | Are logging and monitoring policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | | +| LOG-01.2 | Are policies and procedures reviewed and updated at least annually? | | +| LOG-04.1 | Is access to audit logs restricted to authorized personnel, and are records maintained to provide unique access accountability? | | +| LOG-05.1 | Are security audit logs monitored to detect activity outside of typical or expected patterns? | | +| LOG-05.2 | Is a process established and followed to review and take appropriate and timely actions on detected anomalies? | | + +#### CSP Implementation Descriptions + +- **LOG-01.1**: +- **LOG-01.2**: +- **LOG-04.1**: +- **LOG-05.1**: +- **LOG-05.2**: + +# Sec. Incident Mgmt, E-Disc & Cloud Forensics + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| SEF-03.1 | Is a security incident response plan that includes relevant internal departments, impacted CSCs, and other business-critical relationships (such as supply-chain)established, documented, approved, communicated, applied, evaluated, and maintained? | | +| SEF-04.1 | Is the security incident response plan tested and updated for effectiveness, as necessary, at planned intervals or upon significant organizational or environmental changes? | | +| SEF-07.1 | Are processes, procedures, and technical measures for security breach notification defined and implemented? | | +| SEF-07.2 | Are security breaches and assumed security breaches reported (including any relevant supply chain breaches) as per applicable SLAs, laws, and regulations? | | + +#### CSP Implementation Descriptions + +- **SEF-03.1**: +- **SEF-04.1**: +- **SEF-07.1**: +- **SEF-07.2**: + +# Supply Chain Mgmt, Transparency & Accountability + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| STA-02.1 | Is the SSRM applied, documented, implemented, and managed throughout the supply chain for the cloud service offering? | | +| STA-04.1 | Is the shared ownership and applicability of all CSA CCM controls delineated according to the SSRM for the cloud service offering? | | +| STA-07.1 | Is an inventory of all supply chain relationships developed and maintained? | | + +#### CSP Implementation Descriptions + +- **STA-02.1**: +- **STA-04.1**: +- **STA-07.1**: + +# Threat & Vulnerability Management + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| TVM-02.1 | Are policies and procedures to protect against malware on managed assets established, documented, approved, communicated, applied, evaluated, and maintained? | | +| TVM-02.2 | Are asset management and malware protection policies and procedures reviewed and updated at least annually? | | +| TVM-03.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable scheduled and emergency responses to vulnerability identifications(based on the identified risk)? | | +| TVM-04.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to update detection tools, threat signatures, and compromise indicators weekly (or more frequent) basis? | | +| TVM-07.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated for vulnerability detection on organizationally managed assets at least monthly? | | +| TVM-09.1 | Is a process defined and implemented to track and report vulnerability identification and remediation activities that include stakeholder notification? | | + +#### CSP Implementation Descriptions + +- **TVM-02.1**: +- **TVM-02.2**: +- **TVM-03.1**: +- **TVM-04.1**: +- **TVM-07.1**: +- **TVM-09.1**: + +# Universal EndPoint Management + +| ID | Question | CSP CAIQ Answer | +| :--- | --- | ---: | +| UEM-02.1 | Is there a defined, documented, applicable and evaluated list containing approved services, applications, and the sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data? | | +| UEM-04.1 | Is an inventory of all endpoints used and maintained to store and access company data? | | +| UEM-05.1 | Are processes, procedures, and technical measures defined, implemented and evaluated, to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data? | | +| UEM-06.1 | Are all relevant interactive-use endpoints configured to require an automatic lock screen? | | +| UEM-09.1 | Are anti-malware detection and prevention technology services configured unmanaged endpoints? | | +| UEM-10.1 | Are software firewalls configured on managed endpoints? | | +| UEM-13.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable remote company data deletion on managed endpoint devices? | | + +#### CSP Implementation Descriptions + +- **UEM-02.1**: +- **UEM-04.1**: +- **UEM-05.1**: +- **UEM-06.1**: +- **UEM-09.1**: +- **UEM-10.1**: +- **UEM-13.1**: + + +# Document Changelog +- diff --git a/assets/attachments/security/caiq/CAIQLitev4.0.3_STAR-Security-Questionnaire_Generated-at_2023-08-14.xlsx b/assets/attachments/security/caiq/CAIQLitev4.0.3_STAR-Security-Questionnaire_Generated-at_2023-08-14.xlsx new file mode 100644 index 00000000..4c573150 Binary files /dev/null and b/assets/attachments/security/caiq/CAIQLitev4.0.3_STAR-Security-Questionnaire_Generated-at_2023-08-14.xlsx differ diff --git a/assets/attachments/security/caiq/CCM v4.0 Implementation Guidelines 090921.pdf b/assets/attachments/security/caiq/CCM v4.0 Implementation Guidelines 090921.pdf new file mode 100644 index 00000000..5ecbe06c Binary files /dev/null and b/assets/attachments/security/caiq/CCM v4.0 Implementation Guidelines 090921.pdf differ diff --git a/assets/attachments/security/caiq/CCMLitev4.0.9_Generated-at_2023-08-14.xlsx b/assets/attachments/security/caiq/CCMLitev4.0.9_Generated-at_2023-08-14.xlsx new file mode 100644 index 00000000..0c0c6772 Binary files /dev/null and b/assets/attachments/security/caiq/CCMLitev4.0.9_Generated-at_2023-08-14.xlsx differ