Vendor Assessment

Type: Vendor Assessment


Project Information

FieldDescriptionValue
NameEnter the name
TPA: Project NameWhirlpool project name requesting third party or service provider connection
TPA: Project OwnerWhirlpool project owner requesting third party or service provider connection
TPA: Business AreaWhirlpool business area or process supported by the third party or service provider
TPA: Service Provider NameService provider company name
TPA: Service Provider ContactService provider or third party contact
TPA: Target Implementation DateTarget implementation date
TPA: CISOVendor Chief Information Security Officer (CISO) or equivalent
TPA: User DirectoryChoose the user directory used to manage security and provisioning of access on your internal network
TPA: OS and databaseList the operating system and database used to manage Whirlpool data
TPA: Datacenter locationList the location of the datacenter that hosts Whirlpool data

OS/Database options: Mainframe, Unix, AS400, Windows, Oracle, DB2/UDB, MS SQL, Other


Organizational Security and Privacy

#QuestionAnswerComments
1Has a complete and current Information Security policy been established?Yes
2Are retention and destruction requirements documented and followed for different classifications of data?Yes
3Are documented guidelines followed to review relevant laws and regulations; including but not limited to, privacy protection, international privacy law, or data security and their impact to the organizations IS controls?Yes
4Have documented incident management procedures been established to ensure a timely, effective and orderly response to security incidents including coordination with key partners and customers?Yes
5Are documented policies followed for enforcing segregation of duties?Yes
6Are audits performed to ensure compliance of systems with organizational security policies and standards?Yes, external audits are performed on a periodic basis.SAS-70, SOX Audit
7How often are documented audits/reviews performed of Third Party’s security controls for compliance with service and delivery levels in the agreement?Semi-annually

What types of audits are performed? 2


Employment Security

#QuestionAnswerComments
1Do employees sign a confidentiality (non-disclosure) agreement as part of the initial terms and conditions of employment?Yes
2Are verification (background) investigations conducted on applicants for permanent employment, including third party contractors, vendors, and consultants?Yes for all applicants and is required by contract by any third party vendors
3Are documented guidelines followed for providing security awareness training (SAT) to all personnel?Yes, training is required at least annually

Business Continuity

#QuestionAnswerComments
1Are controls in place to ensure that back-ups of business information are completed on a regular basis?Yes, full back-ups are performed weekly
2Are controls in place to ensure that backed-up information, records of the back-up copies, and documented restore procedures be stored in a remote location?Yes, back-up are retained off-site at a distance greater than 15 miles
3Do policies and procedures exists in to ensure that controls applied to media at the main site are extended to the back-up site?Yes, controls are in place are greater than the main site

Physical Security

#QuestionAnswerComments
1Have controls been established to ensure that physical access to areas with confidential information, and information systems be controlled and restricted to authorised persons only?Yes, documented approval required with physical access controlled by an electronic card key
2Are documented guidelines followed for granting access to visitors?Yes, sign in and data centre manager approval required
3How often are reviews of access rights to secure areas conducted?Access rights are reviewed semi-annuallyAfter Every 6 month (Dec and July)
4Are controls in place to address the possibility of damage from fire in secure areas?Yes, fire detection in place with automated fire suppression system in place
5Have controls been established to ensure uninterruptible power supplies (UPS) are put in place to protect critical equipment from power failures?Yes, equipment protected by UPS and generator back-up

When are the audits performed? 2


Software Development

#QuestionAnswerComments
1Are documented guidelines followed to separate development, test and production (operational) environments?Yes
2Are all security requirements identified and justified during the requirements phase of projects?Yes
3Are formal procedures and management responsibilities defined and documented to require satisfactory control of all changes to equipment, software or procedures including formal approval, recording, and communication of changes?Yes
4Do documented guidelines require static code testing, vulnerability scanning, and web application scanning of applications before migration to production?N/A
5Do technical compliance checks include static code tests, vulnerability scans, and web application scans for existing systems and applications?Yes, all three types of testing are deployed at every release
6Have controls been established to protect the storing of confidential data on local devices?Yes, local encryption required

Security Operations

#QuestionAnswerComments
1How often are security logs reviewed?Security logs contain user ID, failed log-ins, and other security events and are reviewed weekly
2Are documented guidelines followed to ensure access controls of mobile devices (Laptops, PDA’s etc.)?Yes, encryption required
3Have all critical systems with real-time clocks had their time set and synchronized with a common Network Time Protocol (NTP) service?Yes
4Are cryptographic systems and techniques used for storage of information that is considered confidential?Yes, for all confidential data
5Have controls been established to ensure the handling of compromised keys?Yes, compromised key is revoked
6How often are security or vulnerability patches applied?Patches are applied more frequently than monthly
7Have controls been established to ensure installation and regular update of anti-virus software to protect computers on a precautionary or routine basis?Yes, virus definitions are updated daily
8Do the media handling procedures ensure the safe and secure storage of media containing confidential information?Yes
9Do the media handling procedures ensure the safe and secure disposal of electronic media containing confidential information?Yes, media is disposed in a way that renders the data irretrievable
10Do the media handling procedures ensure the safe and secure disposal of paper documents containing confidential information?Yes, media is disposed in a way that renders the document irretrievable
11Is access to the modify job schedules limited to authorised personnel?Yes
12Have mechanisms been implemented to protect electronically published information (web sites, ftp, etc)?Yes, PGP or other enhanced encryption
13Have mechanisms been implemented to protect information on media in transit between organizations (i.e. backup tapes)?Yes, secure package handling controls
14Are the domains with different security needs separated by secure gateways?Yes, DMZ’s exist for internal and external network
15Are documented guidelines followed for the secure exchange of confidential information to prevent the unauthorized disclosure and misuse?Yes, documented and encryption is always required
16Are documented guidelines followed to safeguard the confidentiality and integrity of data passing over wireless networks?Yes, WEP encryption
17Have mechanisms been implemented to protect confidential information contained in electronic mail (Email) between organizations?Yes, SSL/TLS is required

Password Controls

#QuestionAnswerComments
1Does the authentication method to gain access to the network utilise passwords?Passwords are used
2What is the minimum password length available to end-users?Requires at least 6 characters
3How often are end-users forced to change their passwords?Quarterly
4What are the minimum password complexity requirements being enforced for end-users?Mixed case alphabetic, numeric, and plus special characters
5Are end-users restricted from using previous passwords (password history)?No password re-use restrictions
6Are users forced to change their password during first login?Users are forced to change passwords on first login
7Are passwords hidden during authentication?Passwords characters are masked
8Is a complete & current mechanism in place to report & reset lost or compromised passwords?Secure self service password reset mechanism

Infrastructure Access

#QuestionAnswerComments
1When authentication fails, is the user informed of which portion of the authentication process failed?Message indicates which portion of the authentication process failed
2Are authentication credentials securely communicated across the network?Authentication credentials are securely encrypted using industry standards
3Are accounts locked after several failed login attempts?Locked after 3 or more failed attempts
4How long before the system automatically re-enables the account after an account lock out?Auto unlock after 30 minutes or more
5How often are accounts reviewed for deactivation (due to inactivity, termination, etc)?Recurring ≤ 6 months
6Have control requirements been established for requesting, establishing, and issuing user accounts?Yes
7How often is a review of accounts and related privileges conducted?Accounts with access to confidential data are reviewed ≤ 6 months
8Are controls in place to ensure all user activities on IT systems are uniquely identifiable?Yes, all user accounts have unique IDs and are not shared
9Are access rights immediately adjusted for users who have changed jobs?Yes, as requested by management
10Is a documented termination procedure followed which includes the removal of access rights?Yes, process is documented and access is removed within one business day of termination and immediately for emergency termination.

Application Password Controls

#QuestionAnswerComments
1Does the application that houses Whirlpool information conform to the exact access and password controls for your infrastructure?Yes
2Does the authentication method to gain access to the application utilise passwords?Passwords are used
3What is the minimum password length available to end-users?Requires at least 6 characters
4How often are end-users forced to change their passwords for the application?Quarterly
5What are the minimum application password complexity requirements being enforced for end-users?Mixed case alphabetic, numeric, and plus special characters
6Are end-users restricted from using previous application passwords (password history)?No password re-use restrictions
7Are users forced to change their application password during first login?Users are forced to change passwords on first login
8Are passwords hidden during authentication?Passwords characters are masked
9Is a complete & current mechanism in place to report & reset lost or compromised application passwords?Secure self service password reset mechanism

Application Access Controls

#QuestionAnswerComments
1When the application authentication fails, is the user informed of which portion of the authentication process failed?Message indicates which portion of the authentication process failed
2Are application authentication credentials securely communicated across the network?Authentication credentials are securely encrypted using industry standards
3Are application accounts locked after several failed login attempts?Locked after 3 or more failed attempts
4How long before the system automatically re-enables the application account after an account lock out?No auto unlock, manual administrator unlock only
5How often are application accounts reviewed for deactivation (due to inactivity, termination, etc)?Recurring ≤ 6 months
6Have application control requirements been established for requesting, establishing, and issuing user accounts?Yes
7How often is a review of application accounts and related privileges conducted?Accounts with access to confidential data are reviewed ≤ 6 months
8Are controls in place to ensure all user activities in the application are uniquely identifiable?Yes, all user accounts have unique IDs and are not shared
9Are application access rights immediately adjusted for users who have changed jobs?Yes, as requested by management
10Is a documented termination procedure followed which includes the removal of application access rights?Yes, process is documented and access is removed within one business day of termination and immediately for emergency termination.

Vendor Portal Access and Password Controls

#QuestionAnswerComments
1Do you provide access to a web based portal?Yes
2Does the web portal access and password controls conform to either the infrastructure or application password and access controls?YesYes
3Does the authentication method to gain access to the portal utilise passwords?Passwords are used
4What is the minimum password length available to end-users?Requires at least 6 characters
5How often are end-users forced to change their passwords for the portal?Quarterly
6What are the minimum portal password complexity requirements being enforced for end-users?Mixed case alphabetic, numeric, and plus special characters
7Are end-users restricted from using previous portal passwords (password history)?No password re-use restrictions
8Are users forced to change their portal password during first login?Users are forced to change passwords on first login
9Are passwords hidden during authentication?Passwords characters are masked
10Is a complete & current mechanism in place to report & reset lost or compromised portal passwords?Secure self service password reset mechanism
11When the portal authentication fails, is the user informed of which portion of the authentication process failed?Message indicates which portion of the authentication process failed
12Are portal authentication credentials securely communicated across the network?Authentication credentials are securely encrypted using industry standards
13Are portal accounts locked after several failed login attempts?Locked after 3 or more failed attempts
14How long before the system automatically re-enables the portal account after an account lock out?Auto unlock after 30 minutes or more
15How often are portal accounts reviewed for deactivation (due to inactivity, termination, etc)?Recurring ≤ 6 months
16Have portal control requirements been established for requesting, establishing, and issuing user accounts?Yes
17How often is a review of portal accounts and related privileges conducted?Accounts with access to confidential data are reviewed ≤ 6 months
18Are controls in place to ensure all user activities in the portal are uniquely identifiable?Yes, all user accounts have unique IDs and are not shared
19Are portal access rights immediately adjusted for users who have changed jobs?Yes, as requested by management
20Is a documented termination procedure followed which includes the removal of portal access rights?Yes, process is documented and access is removed within one business day of termination and immediately for emergency termination.

Vendor Access to Whirlpool Data Types

What type of Whirlpool data does the vendor have access to?

  • Employee Compensation
  • Country Specific Personal ID (e.g. social security number [US], social insurance number [Canada])
  • Employee Health Information
  • Employee Criminal Information
  • Employee Contact Information
  • Employee Benefits Information
  • Employee Performance/Talent Ratings
  • Employee Emergency Contact Information
  • Employee Demographic Information
  • Credit Card Information
  • Consumer Contact Information (X)
  • Customer Service Centre Call History
  • Prospective Customer Information
  • Consumer Demographic Information
  • Pre-release Financial Information
  • Business Development Information
  • Board and Executive Committee Materials
  • Restructuring Information
  • Corporate Strategy
  • Regional Trade Sensitive Information
  • Aggregate Corporate Forecast and Planning Information
  • Historical Earnings Information
  • Capital Plan and Spend Information
  • Treasury Information
  • Tax Information
  • Internal Audit Information
  • Supply Chain Cost Information
  • IS Security Incident Information
  • IS Vulnerability Information
  • Application Code and Documentation
  • System Performance Information
  • Detailed System Information