Security Operations & Technical Capabilities and Support
Does your incident response plan comply with industry standards for legally admissible chain-of-custody management processes and controls?
What controls are used to mitigate DDoS (distributed denialβof-service) attacks?
Is there a cloud audit program to address the client's audit and assessment requirements?
Does your incident response capability include the use of legally admissible forensic data collection and analysis techniques?
Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific tenant without freezing other tenant data?
Do you enforce and attest to tenant data separation when producing data in response to legal subpoenas?
Give details of platform on which the application is developed.
Does your product provide/support mobility through native mobile apps etc.?
Do you offer configurability in your SaaS solution? Give the options if available
What customization options are available to cater to tenant's requirements? E.g. Customized reports etc.
If customization is possible, what are the development tools and APIs available?
Do you support out-of-the-box integration with on premise applications such as SAP, Active Directory etc.?
Do you support movement of applications and data from one cloud service provider to another cloud service provider or back to in-house data center whenever required?
What are the available management reporting capabilities?
Can the reports be customizable based on the tenant's needs?
What types of Advisory and technical support are provided?
How does the Cloud Service Provider protect keys, and what security controls are in place to effect that?
Are hardware security modules used to protect such keys? Who has access to such keys?
What procedures are in place to manage and recover from the compromise of keys?
If an advanced warning is given for service interruption will it count as downtime?
What is the SLA (Time) for different levels of support different incidents and change requests? Standard example: Critical - 2 hrs. or less, Moderate - 4 hrs. or less, Minimum - 8 hrs. or less
Do you have penalty clauses in the event of performance failure ?
What are the inbuilt APIs for third party tools available? Can you integrate with SailPoint, ForgeRock, Splunk, OneCert, EDM?
How is the overall Application logging operation managed? - Does the solution support monitoring for security events and can event notifications/incident response be integrated with bank system?
Does the application have robust authentication methods (e.g. SSO, multi-factor authentication, One-time password, secure token, etc.) for administrative access to this service?
Do you report PEN test, SOC findings?
How is the compatibility of the application with Desktop(Mac/OS); Tablet; Mobile (Android/iPhone)?'- Any additional components required to download in user's computer in order to access the application?
Does the application have a robust Backup and Restore procedures? Is the duration configurable? Can you share your DR strategy and tests results? Is it Active-active?
How is data isolated between customers? Is the data in non-prod instance refreshed with Prod data and masked? If data masking is performed, then how configurable are the masking scripts? What protection is used for Prod data at rest and at transit?
How many instances to be provided and supported? How seamless is the Product upgrade release? What is the hosting model - public, private, hybrid, etc.
What is the RTO and RPO? Can you share the latest DR strategy test results?
Are there any FLASH component installed in your web app. If yes, can it be disabled without any detrimental impact to the application itself?
How mature is the technical capabilities of the product to be able to integrate seamlessly and securely with the Bank's tools and applications?
Does the Vendor and/or Business User have controls on elevated/privileged or operational access? Does this mean SCB admin staff will have the control and will be able to perform any administrative or operational activities? How are the roles ""Admin"" and ""Super Admin"" defined?"
How is the overall Application logging operation managed? - Does the solution support monitoring for security events and can event notifications/incident response be integrated with bank system?
What are WCAG Guidelines?
Do you comply with WCAG Guidelines?
Can people with disabilities use your website and application without barriers?
Do you consider WCAG guidelines during product development?
Do you conduct any periodical review and improve the website or applications?
Last updated
Was this helpful?