Security related questionnaire

VidyaSagarA1989
Giga Contributor

For the questions below, I was requested to provide comments which will help explaining the policy or details about question. Kindly help. 

 

Asset Management

 

[D.14] In the event of a subpoena or forensics incident, is specific data able to be put on Litigation Hold without impacting other clients' data? 
Yes
Comments: (Required)

 

 

Access Control:
[H.1.6] Are requests for granting access documented, retained and retrievable for audit purposes for a minimum of one year?

Yes

Comments: (Required)

 

 

[H.1.14] Is a standards-based federated ID capability available to clients e.g., SAML, OpenID, Single Sign On?

Yes

Comments: (Required)

 

 

Operational Resilience:
[K.1.1] Do the products and/or services specified in the scope of this assessment fall within the scope of the business resilience program?

Yes

Comments: (Required)

 

 

End Point Security:
[M.1.2] Are constituents allowed to utilize mobile devices within the organization's environment?

[Answer]: Yes

Comments: (Required)

 

 

Privacy Management:
[P.1.1] Is client scoped data collected, accessed, transmitted, processed, disclosed, or retained that can be classified as client-scoped employee data in accordance with state privacy laws (e.g., CPRA)?

Yes

Comments: (Required)

2 REPLIES 2

kaushal_snow
Mega Sage

Hi @VidyaSagarA1989 ,

 

1. Yes. ServiceNow provides the Legal Hold Notification application, enabling organizations to preserve relevant information during legal proceedings. This application allows for the placement of legal holds on specific data without affecting other clients' data....

 

2. Yes. ServiceNow Identity and Access Audit functionality allows for the configuration of retention periods for access requests. Administrators can set the retention period to a minimum of one year to ensure compliance with audit requirements.....

 

3. Yes. ServiceNow supports federated identity capabilities through standards like SAML and OpenID Connect. These protocols enable clients to implement Single Sign-On (SSO) for seamless and secure user authentication across platforms.....

 

4. Yes. ServiceNow Business Continuity Management application helps organizations improve operational resilience through risk mitigation, crisis management, and plan testing. It ensures that products and services are included in the business resilience program to maintain service delivery during disruptions....

 

5. Yes. ServiceNow mobile applications support secure access through AppAuth, utilizing the default OS browser (Safari for iOS and Chrome for Android). This approach ensures secure communication and data protection for mobile device users.....

 

6.  Yes. ServiceNow's Data Privacy Framework helps organizations classify sensitive data and remove personally identifiable information (PII) from user data in production instances. This ensures compliance with state privacy laws such as the California Privacy Rights Act (CPRA).

 

 

If you found my response helpful, please mark it as ‘Accept as Solution’ and ‘Helpful’. This helps other community members find the right answer more easily and supports the community.

 

 

Thanks and Regards,
Kaushal Kumar Jha - ServiceNow Consultant - Lets connect on Linkedin: https://www.linkedin.com/in/kaushalkrjha/

@kaushal_snow : Thanks a lot for your quick response and help. 

 

By any chance, will you be able to help on below questions? 

Your help is much appreciated. 

 

1. Will you, as our vendor, allow or provide for Flagstar Bank to participate as a client in your Disaster Recovery test for the services that you provide Flagstar Bank?


[K.5.4] Are offline data backups protected from destructive malware or other threats that may corrupt production and online backup versions of data?

[Answer]: Yes

 

[K.3.7] Are test results and remediation action plans provided by critical service providers after each test?

Yes

Comments: (Required)