The file's text, extracted by GovTribe without its formatting.
Data Security Questionnaire 26-081P Cyber Security Managed Detection And Response Service: Vendor Security Questionnaire
| Vendor: | | |
| Please answer each question thoroughly and provide supporting documentation where requested. If a question does not apply, explain why. Where possible, provide examples, recent reports, or evidence to support your responses. | | |
| # | Topic/Question | Response |
| 1 | Authentication & Access Control | |
| 1.1 | Do you have Azure/AD Integration? | |
| 1.2 | Do you support Multi-Factor Authentication (MFA) or SSO for accounts and access? Which accounts are covered (e.g., all users, privileged accounts)? | |
| 1.3 | Describe your access control procedures (Identity and Access Management) and provide supporting documentation. | |
| 1.4 | Can logs integrate with SIEM tools? | |
| 2 | Patch Management |
| 2.1 | What is your policy and process for patching the operating system (OS) and/or application(s)? |
| 2.2 | Please provide recent examples or reports of patch management activities. |
| 2.3 | If applicable, does your product allow for mass distribution through tools like SCCM or Intune? |
| 3 | Security Testing & Compliance |
| 3.1 | What are your practices regarding penetration testing and vulnerability assessments? |
| 3.2 | Do you meet any security compliance standards (e.g., NIST, ISO 27001, SOC 2/3)? |
| 3.3 | Have you received any formal certifications related to your environment? Please specify and attach documentation. |
| 4 | Incident Response & Data Protection |
| 4.1 | Do you have a formal incident response plan? Please attach or summarize the plan. |
| 4.2 | What is your process for Disaster Recovery (DR)? |
| 4.3 | Has your application or data center ever been compromised? If yes, describe the incident and remediation steps taken. |
| 4.4 | Do you have an average Mean Time To Recovery (MTTR) or an SLA for MTTR, and what are they? |
| 5 | Data Protection |
| 5.1 | Is customer data protected at rest, and what encryption method is used, e.g., AES-256? Where is our data stored (geographic location, data center details)? |
| 5.2 | How do you manage data backups? Describe your backup policy and frequency. |
| 5.3 | Who owns the data, and do we have data export capabilities to non-proprietary formats? |
| 5.4 | Who has access to our data? |
| 5.5 | What are you insured for if our data (including Personally Identifiable Information - PII) is compromised and revealed? Please provide details of your insurance coverage. |
| 6 | Physical & Network Security |
| 6.1 | What is the physical security for your data centers? Describe controls and provide documentation if available. Is Data encrypted during transit, e.g., Transport Layer Security (TLS), and what version? |
| 6.2 | Provide details for Operations to assess the feasibility of the VPN tunnel if used. |
| 7 | Additional Controls & Services |
| 7.1 | What other applications do you incorporate into your services? |
| 7.2 | Do you have email authentication protocols in place (DKIM, DMARC, and SPF)? Is your platform set up for high availability? Please describe your approach. |
| 7.3 | Do you employ multi-tenant architecture? If so, how is tenant isolation achieved? |
| 7.4 | What controls do you have in place for supply chain compromise? Please provide details and examples. |
Please ensure that all responses are accurate and provide supporting evidence where applicable. Additional information may be requested based on your responses.
Sheet2