Solution Development
Do you have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data?
Do you logically and/or physically separate tenant systems from corporate systems?
Are information system documents (e.g., administrator and User guides, architecture diagrams, etc.) made available to authorized personnel to ensure configuration, installation, and operation of the information system?
Can you a provide dedicated computing environment for the tenant?
Do you provide the logical segregation of tenant data and the application?
Do you logically and physically segregate production and non-production environments?
Are there any coding standards in place?
Are there any teams that can deploy code into production environments without it passing through the QA process?
How regularly are backups tested - has the recovery process ever been tested?
Describe your incident escalation process?
Describe your key management processes.
How is product security considered during the development process?
Last updated
Was this helpful?