Vendor Assessment
Type: Vendor Assessment
Project Information
| Field | Description | Value |
|---|---|---|
| Name | Enter the name | |
| TPA: Project Name | Whirlpool project name requesting third party or service provider connection | |
| TPA: Project Owner | Whirlpool project owner requesting third party or service provider connection | |
| TPA: Business Area | Whirlpool business area or process supported by the third party or service provider | |
| TPA: Service Provider Name | Service provider company name | |
| TPA: Service Provider Contact | Service provider or third party contact | |
| TPA: Target Implementation Date | Target implementation date | |
| TPA: CISO | Vendor Chief Information Security Officer (CISO) or equivalent | |
| TPA: User Directory | Choose the user directory used to manage security and provisioning of access on your internal network | |
| TPA: OS and database | List the operating system and database used to manage Whirlpool data | |
| TPA: Datacenter location | List the location of the datacenter that hosts Whirlpool data |
OS/Database options: Mainframe, Unix, AS400, Windows, Oracle, DB2/UDB, MS SQL, Other
Organizational Security and Privacy
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Has a complete and current Information Security policy been established? | Yes | |
| 2 | Are retention and destruction requirements documented and followed for different classifications of data? | Yes | |
| 3 | Are documented guidelines followed to review relevant laws and regulations; including but not limited to, privacy protection, international privacy law, or data security and their impact to the organizations IS controls? | Yes | |
| 4 | Have documented incident management procedures been established to ensure a timely, effective and orderly response to security incidents including coordination with key partners and customers? | Yes | |
| 5 | Are documented policies followed for enforcing segregation of duties? | Yes | |
| 6 | Are audits performed to ensure compliance of systems with organizational security policies and standards? | Yes, external audits are performed on a periodic basis. | SAS-70, SOX Audit |
| 7 | How often are documented audits/reviews performed of Third Party’s security controls for compliance with service and delivery levels in the agreement? | Semi-annually |
What types of audits are performed? 2
Employment Security
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Do employees sign a confidentiality (non-disclosure) agreement as part of the initial terms and conditions of employment? | Yes | |
| 2 | Are verification (background) investigations conducted on applicants for permanent employment, including third party contractors, vendors, and consultants? | Yes for all applicants and is required by contract by any third party vendors | |
| 3 | Are documented guidelines followed for providing security awareness training (SAT) to all personnel? | Yes, training is required at least annually |
Business Continuity
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Are controls in place to ensure that back-ups of business information are completed on a regular basis? | Yes, full back-ups are performed weekly | |
| 2 | Are controls in place to ensure that backed-up information, records of the back-up copies, and documented restore procedures be stored in a remote location? | Yes, back-up are retained off-site at a distance greater than 15 miles | |
| 3 | Do policies and procedures exists in to ensure that controls applied to media at the main site are extended to the back-up site? | Yes, controls are in place are greater than the main site |
Physical Security
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Have controls been established to ensure that physical access to areas with confidential information, and information systems be controlled and restricted to authorised persons only? | Yes, documented approval required with physical access controlled by an electronic card key | |
| 2 | Are documented guidelines followed for granting access to visitors? | Yes, sign in and data centre manager approval required | |
| 3 | How often are reviews of access rights to secure areas conducted? | Access rights are reviewed semi-annually | After Every 6 month (Dec and July) |
| 4 | Are controls in place to address the possibility of damage from fire in secure areas? | Yes, fire detection in place with automated fire suppression system in place | |
| 5 | Have controls been established to ensure uninterruptible power supplies (UPS) are put in place to protect critical equipment from power failures? | Yes, equipment protected by UPS and generator back-up |
When are the audits performed? 2
Software Development
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Are documented guidelines followed to separate development, test and production (operational) environments? | Yes | |
| 2 | Are all security requirements identified and justified during the requirements phase of projects? | Yes | |
| 3 | Are formal procedures and management responsibilities defined and documented to require satisfactory control of all changes to equipment, software or procedures including formal approval, recording, and communication of changes? | Yes | |
| 4 | Do documented guidelines require static code testing, vulnerability scanning, and web application scanning of applications before migration to production? | N/A | |
| 5 | Do technical compliance checks include static code tests, vulnerability scans, and web application scans for existing systems and applications? | Yes, all three types of testing are deployed at every release | |
| 6 | Have controls been established to protect the storing of confidential data on local devices? | Yes, local encryption required |
Security Operations
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | How often are security logs reviewed? | Security logs contain user ID, failed log-ins, and other security events and are reviewed weekly | |
| 2 | Are documented guidelines followed to ensure access controls of mobile devices (Laptops, PDA’s etc.)? | Yes, encryption required | |
| 3 | Have all critical systems with real-time clocks had their time set and synchronized with a common Network Time Protocol (NTP) service? | Yes | |
| 4 | Are cryptographic systems and techniques used for storage of information that is considered confidential? | Yes, for all confidential data | |
| 5 | Have controls been established to ensure the handling of compromised keys? | Yes, compromised key is revoked | |
| 6 | How often are security or vulnerability patches applied? | Patches are applied more frequently than monthly | |
| 7 | Have controls been established to ensure installation and regular update of anti-virus software to protect computers on a precautionary or routine basis? | Yes, virus definitions are updated daily | |
| 8 | Do the media handling procedures ensure the safe and secure storage of media containing confidential information? | Yes | |
| 9 | Do the media handling procedures ensure the safe and secure disposal of electronic media containing confidential information? | Yes, media is disposed in a way that renders the data irretrievable | |
| 10 | Do the media handling procedures ensure the safe and secure disposal of paper documents containing confidential information? | Yes, media is disposed in a way that renders the document irretrievable | |
| 11 | Is access to the modify job schedules limited to authorised personnel? | Yes | |
| 12 | Have mechanisms been implemented to protect electronically published information (web sites, ftp, etc)? | Yes, PGP or other enhanced encryption | |
| 13 | Have mechanisms been implemented to protect information on media in transit between organizations (i.e. backup tapes)? | Yes, secure package handling controls | |
| 14 | Are the domains with different security needs separated by secure gateways? | Yes, DMZ’s exist for internal and external network | |
| 15 | Are documented guidelines followed for the secure exchange of confidential information to prevent the unauthorized disclosure and misuse? | Yes, documented and encryption is always required | |
| 16 | Are documented guidelines followed to safeguard the confidentiality and integrity of data passing over wireless networks? | Yes, WEP encryption | |
| 17 | Have mechanisms been implemented to protect confidential information contained in electronic mail (Email) between organizations? | Yes, SSL/TLS is required |
Password Controls
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Does the authentication method to gain access to the network utilise passwords? | Passwords are used | |
| 2 | What is the minimum password length available to end-users? | Requires at least 6 characters | |
| 3 | How often are end-users forced to change their passwords? | Quarterly | |
| 4 | What are the minimum password complexity requirements being enforced for end-users? | Mixed case alphabetic, numeric, and plus special characters | |
| 5 | Are end-users restricted from using previous passwords (password history)? | No password re-use restrictions | |
| 6 | Are users forced to change their password during first login? | Users are forced to change passwords on first login | |
| 7 | Are passwords hidden during authentication? | Passwords characters are masked | |
| 8 | Is a complete & current mechanism in place to report & reset lost or compromised passwords? | Secure self service password reset mechanism |
Infrastructure Access
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | When authentication fails, is the user informed of which portion of the authentication process failed? | Message indicates which portion of the authentication process failed | |
| 2 | Are authentication credentials securely communicated across the network? | Authentication credentials are securely encrypted using industry standards | |
| 3 | Are accounts locked after several failed login attempts? | Locked after 3 or more failed attempts | |
| 4 | How long before the system automatically re-enables the account after an account lock out? | Auto unlock after 30 minutes or more | |
| 5 | How often are accounts reviewed for deactivation (due to inactivity, termination, etc)? | Recurring ≤ 6 months | |
| 6 | Have control requirements been established for requesting, establishing, and issuing user accounts? | Yes | |
| 7 | How often is a review of accounts and related privileges conducted? | Accounts with access to confidential data are reviewed ≤ 6 months | |
| 8 | Are controls in place to ensure all user activities on IT systems are uniquely identifiable? | Yes, all user accounts have unique IDs and are not shared | |
| 9 | Are access rights immediately adjusted for users who have changed jobs? | Yes, as requested by management | |
| 10 | Is a documented termination procedure followed which includes the removal of access rights? | Yes, process is documented and access is removed within one business day of termination and immediately for emergency termination. |
Application Password Controls
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Does the application that houses Whirlpool information conform to the exact access and password controls for your infrastructure? | Yes | |
| 2 | Does the authentication method to gain access to the application utilise passwords? | Passwords are used | |
| 3 | What is the minimum password length available to end-users? | Requires at least 6 characters | |
| 4 | How often are end-users forced to change their passwords for the application? | Quarterly | |
| 5 | What are the minimum application password complexity requirements being enforced for end-users? | Mixed case alphabetic, numeric, and plus special characters | |
| 6 | Are end-users restricted from using previous application passwords (password history)? | No password re-use restrictions | |
| 7 | Are users forced to change their application password during first login? | Users are forced to change passwords on first login | |
| 8 | Are passwords hidden during authentication? | Passwords characters are masked | |
| 9 | Is a complete & current mechanism in place to report & reset lost or compromised application passwords? | Secure self service password reset mechanism |
Application Access Controls
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | When the application authentication fails, is the user informed of which portion of the authentication process failed? | Message indicates which portion of the authentication process failed | |
| 2 | Are application authentication credentials securely communicated across the network? | Authentication credentials are securely encrypted using industry standards | |
| 3 | Are application accounts locked after several failed login attempts? | Locked after 3 or more failed attempts | |
| 4 | How long before the system automatically re-enables the application account after an account lock out? | No auto unlock, manual administrator unlock only | |
| 5 | How often are application accounts reviewed for deactivation (due to inactivity, termination, etc)? | Recurring ≤ 6 months | |
| 6 | Have application control requirements been established for requesting, establishing, and issuing user accounts? | Yes | |
| 7 | How often is a review of application accounts and related privileges conducted? | Accounts with access to confidential data are reviewed ≤ 6 months | |
| 8 | Are controls in place to ensure all user activities in the application are uniquely identifiable? | Yes, all user accounts have unique IDs and are not shared | |
| 9 | Are application access rights immediately adjusted for users who have changed jobs? | Yes, as requested by management | |
| 10 | Is a documented termination procedure followed which includes the removal of application access rights? | Yes, process is documented and access is removed within one business day of termination and immediately for emergency termination. |
Vendor Portal Access and Password Controls
| # | Question | Answer | Comments |
|---|---|---|---|
| 1 | Do you provide access to a web based portal? | Yes | |
| 2 | Does the web portal access and password controls conform to either the infrastructure or application password and access controls? | Yes | Yes |
| 3 | Does the authentication method to gain access to the portal utilise passwords? | Passwords are used | |
| 4 | What is the minimum password length available to end-users? | Requires at least 6 characters | |
| 5 | How often are end-users forced to change their passwords for the portal? | Quarterly | |
| 6 | What are the minimum portal password complexity requirements being enforced for end-users? | Mixed case alphabetic, numeric, and plus special characters | |
| 7 | Are end-users restricted from using previous portal passwords (password history)? | No password re-use restrictions | |
| 8 | Are users forced to change their portal password during first login? | Users are forced to change passwords on first login | |
| 9 | Are passwords hidden during authentication? | Passwords characters are masked | |
| 10 | Is a complete & current mechanism in place to report & reset lost or compromised portal passwords? | Secure self service password reset mechanism | |
| 11 | When the portal authentication fails, is the user informed of which portion of the authentication process failed? | Message indicates which portion of the authentication process failed | |
| 12 | Are portal authentication credentials securely communicated across the network? | Authentication credentials are securely encrypted using industry standards | |
| 13 | Are portal accounts locked after several failed login attempts? | Locked after 3 or more failed attempts | |
| 14 | How long before the system automatically re-enables the portal account after an account lock out? | Auto unlock after 30 minutes or more | |
| 15 | How often are portal accounts reviewed for deactivation (due to inactivity, termination, etc)? | Recurring ≤ 6 months | |
| 16 | Have portal control requirements been established for requesting, establishing, and issuing user accounts? | Yes | |
| 17 | How often is a review of portal accounts and related privileges conducted? | Accounts with access to confidential data are reviewed ≤ 6 months | |
| 18 | Are controls in place to ensure all user activities in the portal are uniquely identifiable? | Yes, all user accounts have unique IDs and are not shared | |
| 19 | Are portal access rights immediately adjusted for users who have changed jobs? | Yes, as requested by management | |
| 20 | Is a documented termination procedure followed which includes the removal of portal access rights? | Yes, process is documented and access is removed within one business day of termination and immediately for emergency termination. |
Vendor Access to Whirlpool Data Types
What type of Whirlpool data does the vendor have access to?
- Employee Compensation
- Country Specific Personal ID (e.g. social security number [US], social insurance number [Canada])
- Employee Health Information
- Employee Criminal Information
- Employee Contact Information
- Employee Benefits Information
- Employee Performance/Talent Ratings
- Employee Emergency Contact Information
- Employee Demographic Information
- Credit Card Information
- Consumer Contact Information (X)
- Customer Service Centre Call History
- Prospective Customer Information
- Consumer Demographic Information
- Pre-release Financial Information
- Business Development Information
- Board and Executive Committee Materials
- Restructuring Information
- Corporate Strategy
- Regional Trade Sensitive Information
- Aggregate Corporate Forecast and Planning Information
- Historical Earnings Information
- Capital Plan and Spend Information
- Treasury Information
- Tax Information
- Internal Audit Information
- Supply Chain Cost Information
- IS Security Incident Information
- IS Vulnerability Information
- Application Code and Documentation
- System Performance Information
- Detailed System Information