About these answers. Most entries explain common industry practices, not Klistalabs-test controls. SIG entries marked “Company response” use approved Klistalabs-test wording supplied for this site.
35 results
01
How is the information security program organized?
General security / Security program · overview
An information security program defines documented policies, assigned responsibilities, and coordinated practices for managing risk. Leadership oversight and accountable operational teams guide control implementation and effectiveness review.
02
Who is responsible for information security governance?
General security / Security program · governance
Organizational leadership provides security governance oversight, while security and business owners carry operational responsibilities. Defined escalation paths and governance forums resolve risks and align security decisions with organizational priorities.
03
How are information security policies maintained?
General security / Security program · policy
A designated function owns information security policies, authorized leadership approves them, and the policies are communicated to the people they govern. Reviews and updates address significant changes to risks, laws, technology, or operations.
04
How are security risks identified and managed?
General security / Risk management · assessment
Security risk assessment considers threats, vulnerabilities, likelihood, and potential impact to information and services. Each risk is assessed, assigned an owner, and treated, accepted, or otherwise managed; decisions are revisited when circumstances change.
05
How are open security risks tracked to completion?
General security / Risk management · tracking
A risk register records each risk’s description, impact, likelihood, owner, treatment decision, and status. Target dates, progress updates, and escalation of overdue or accepted risks establish accountability and track follow-through.
06
How are legal, regulatory, and contractual security obligations tracked?
General security / Compliance · obligations
An inventory of applicable legal, regulatory, and contractual obligations identifies the requirements and accountable owners. Owners assess changes for impact and reflect them in relevant policies, processes, and compliance records.
07
What security assessments or audits are available for review?
General security / Assurance · independent review
Security assurance evidence includes assessments such as independent audits, certifications, penetration tests, and other reviews when performed for the relevant organization and scope. A report’s coverage period, included systems, exclusions, and distribution restrictions define the conclusions it supports.
08
How are information assets identified and managed?
General security / Asset management · inventory
An asset inventory identifies systems, services, data, and other resources, with assigned owners and appropriate classifications. The inventory is updated when assets are acquired, changed, or retired and aligned with the service boundary under assessment.
09
How is information classified and handled?
General security / Data protection · classification
Information classification reflects sensitivity, value, and potential impact from disclosure, alteration, or loss. Handling requirements for access, storage, sharing, and disposal are matched to each classification and applied to customer information within scope.
10
How is customer data handled through its lifecycle?
General security / Data protection · lifecycle
Customer data is collected for defined purposes, accessed only by authorized parties, and retained only as needed for those purposes or applicable obligations. Lifecycle practices address transfers, return or export when appropriate, and secure disposal when the data is no longer required.
11
Where is customer data processed and stored?
General security / Data protection · location
Customer data processing and storage locations are determined by the service architecture, selected regions, and third-party services involved. The relevant scope covers where data is stored, accessed, or otherwise processed, including applicable subprocessors.
12
How is data protected while in transit?
General security / Data protection · encryption
Encrypted communication protocols protect data in transit between systems and across networks. The applicable interfaces and service boundaries define the protection scope, which may differ for external connections, internal links, and data flows handled by third parties.
13
How is data protected while at rest?
General security / Data protection · encryption
Encryption and other storage safeguards protect data at rest according to the data, system, and threat model. The relevant scope includes persistent storage and copies such as backups; encryption complements rather than replaces access control and other protections.
14
How are cryptographic keys managed?
General security / Data protection · keys
Cryptographic key management protects keys throughout their lifecycle through secure generation and storage, access restriction, controlled use, rotation or replacement, and destruction. Recovery and separation of duties address key loss or compromise without granting unnecessary access.
15
How are retention periods determined?
General security / Data protection · retention
Retention periods reflect the data’s purpose, legal and contractual obligations, operational needs, and risk. A retention schedule defines when data is deleted or anonymized and how exceptions such as legal holds are handled.
16
How can customer data be deleted or returned?
General security / Data protection · deletion
A data return or deletion process identifies the data, authorized requester, applicable systems, dependencies, and retention obligations. Completion is subject to service terms and the handling of backups, logs, or legally retained records.
17
How is access to systems and data controlled?
General security / Access control · principles
Access is granted to authenticated identities according to authorization rules, business need, and least privilege. Approval, periodic review, logging, and prompt access removal keep permissions appropriate to the systems and data in scope.
18
How are privileged access rights reviewed?
General security / Access control · privilege
Privileged access is limited to authorized roles and granted only to perform defined responsibilities. Ownership, approval, monitoring, and periodic review identify excessive or unused privileges for adjustment or removal.
19
How are workforce identities managed?
General security / Access control · identity
Identity management covers account creation, authentication, role and employment changes, and deactivation when access is no longer needed. Access is tied to an accountable individual or approved service identity and adjusted promptly when responsibilities change.
20
What authentication factors are required for sensitive access?
General security / Access control · authentication
Multi-factor authentication combines two or more distinct factor types: something a person knows, possesses, or is. Requirements reflect access sensitivity, with stronger requirements for privileged, remote, and other sensitive access; exceptions are explicitly controlled.
21
What security events are logged?
General security / Monitoring · logging
Security logging captures authentication activity, access to sensitive resources, administrative actions, and significant system or security events. Effective logging preserves event context and integrity, restricts log access, and retains records to meet investigation and operational needs.
22
How are security events monitored and triaged?
General security / Monitoring · detection
Security monitoring analyzes relevant logs and signals to identify activity that indicates a threat or control failure. Alert triage assesses severity and context, then escalates alerts for investigation and response according to defined responsibilities.
23
How are vulnerabilities identified and prioritized?
General security / Vulnerability management · scanning
Vulnerability identification uses scanning, security testing, vendor advisories, and reports from internal or external sources. Prioritization considers severity, exploitability, exposure, and potential impact; findings are assigned, tracked, and managed through remediation or a documented exception.
24
How are security patches prioritized and applied?
General security / Vulnerability management · remediation
Patch priority reflects severity, exploitability, exposure, and the importance of the affected system. Testing and staged rollout reduce operational risk; exceptions and remediation progress are tracked to resolution.
25
What security testing is performed?
General security / Vulnerability management · testing
Security testing methods include vulnerability assessments, penetration tests, code analysis, and architecture reviews, selected according to system risk and scope. Results are interpreted in light of what was tested, when it was tested, the methods used, and how findings were addressed.
26
How are security practices incorporated into development?
General security / Secure development · lifecycle
Secure development integrates security requirements and risk review throughout design, implementation, testing, release, and maintenance. Code review, security testing, dependency management, and tracked remediation address defects before and after deployment.
27
How are production changes reviewed and approved?
General security / Change management · release
Production changes are assessed for risk, reviewed and authorized by appropriate parties, and tested before release. Change management includes deployment plans, rollback or recovery options, and an expedited but accountable path for emergencies.
28
How is service availability planned and reviewed?
General security / Resilience · availability
Availability planning identifies service objectives, critical dependencies, capacity needs, and risks that could interrupt operations. Performance and incidents are reviewed against applicable commitments, and resilience measures are adapted as the service and its dependencies change.
29
How are backups designed and protected?
General security / Resilience · backup
Backup design identifies the data and systems that require recovery, protects copies from loss or unauthorized access, and defines retention. Restoration testing establishes whether backups support recovery within defined organizational needs.
30
How is business continuity addressed?
General security / Resilience · continuity
Business continuity planning identifies the activities, people, facilities, technology, and external dependencies required to continue or restore operations during disruption. Plan maintenance and exercises identify gaps for remediation.
31
How is disaster recovery tested?
General security / Resilience · recovery
Disaster recovery testing evaluates whether prioritized systems and data can be restored under defined disruption scenarios. Exercises include plan walkthroughs or technical recovery tests, and results guide remediation of identified gaps.
32
What is the approach to security incident response?
General security / Incident management · response
Incident response comprises preparation, detection, triage, containment, investigation, recovery, and lessons learned. Defined roles and escalation paths support coordinated decisions, evidence preservation, and communication with affected stakeholders.
33
How are customers notified about a security incident?
General security / Incident management · notification
Customer notification is determined by the incident’s nature, affected data or services, applicable law, and contractual terms. The process assigns decision ownership and communication channels; applicable obligations govern required timing.
34
How are security responsibilities addressed for personnel?
General security / People · personnel security
Personnel security establishes role-appropriate responsibilities and communicates applicable security expectations during onboarding and throughout employment. Screening is applied where lawful and relevant to the role, and access is removed promptly during offboarding.
35
What security training and awareness activities are provided?
General security / People · awareness
Security awareness programs teach personnel to recognize threats and understand their responsibilities for protecting information. Training addresses topics such as phishing, data handling, access security, and incident reporting; completion tracking supports accountability.