4. Information Security Requirements
4.1General security requirement
Vendor will maintain Physical, Administrative, and Technical safeguards consistent with industry-accepted best practices (including the International Organization for Standardization’s standards ISO 27001 and 27002, the National Institute of Standards and Technology (NIST) Cybersecurity Framework, or other similar industry standards for information security) to protect the Confidentiality, Integrity, and Availability of Socure Information.
4.2Specific safeguard requirements
In addition to following the above standards, Vendor’s information security program will include, at a minimum, the following safeguards and controls:
4.2.1Written information security program
Vendor shall maintain and implement a written information security program, including appropriate policies, procedures, and risk assessments that are reviewed at least annually. The program will apply to Vendor’s employees, agents, subcontractors, and Vendors. Vendor will maintain a process to monitor and enforce program compliance and log program violations.
4.2.2Security awareness training
Vendor will provide periodic and no less than annually, security training to its Personnel on relevant threats and business requirements [such as social-engineering attacks, sensitive data handling, causes of unintentional data exposure, and security incident identification and reporting].
4.2.3Data inventory
Vendor will document and maintain information regarding how and where Socure Information is Processed while in Vendor’s possession or control.
4.2.4Secure configurations
Vendor shall manage security configurations of its systems using industry best practices to protect Socure Information from exploitation through vulnerable services and settings.
4.2.5Controlled use of administrative privileges
Vendor shall limit and control the use of administrative privileges on computers, networks, and applications consistent with industry best practices.
4.2.6Vulnerability and patch management
Vendor will maintain a process to timely identify and remediate system, device, and application vulnerabilities through patches, updates, bug fixes, or other modifications to maintain the security of Socure Information. Vendor must mitigate all discovered actively exploited and public facing Critical vulnerabilities within 48 hours, Critical (CVSS 9.0 – 10.0) vulnerabilities with immediate urgency and no later than 7 days, mitigate High (CVSS 7.0 – 8.9) risk vulnerabilities within 14 days, mitigate Moderate (CVSS 4.0 – 6.9) vulnerability risks in 90 days, and mitigate Low (CVSS 0.1 – 3.9) vulnerability risks in 180 days. CVSS ratings are defined here https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
4.2.7Maintenance, monitoring, and analysis of audit logs
Vendor will collect, manage, retain, and analyze audit logs of events to help detect, investigate, and recover from unauthorized activity that may affect Socure Information. Logs will be kept and maintained for at least 18 months. If Vendor is providing Infrastructure as a Service (IaaS), Platform as a Service (Paas), or Software as a Service (SaaS), Vendor must audit all user management activities in section and provide a tamper-protected audit trail of such activities as an encrypted continuous export stream or file that will be available to Socure information security in a SIEM-compatible format, and can clearly demonstrate the user performing the action, the action taken, success or failure, date and time. Further, in a multi-tenant environment with a shared responsibility model (e.g. a SaaS), Vendor shall associate all logs with a unique Socure implementation id, and provide this information to Socure upon request. Vendor will implement reasonable controls to control access to and prevent modification of security audit logs.
4.2.8Availability Monitoring
If Vendor is providing Infrastructure as a Service (IaaS), Platform as a Service (Paas), or Software as a Service (SaaS), Vendor will implement the following availability monitoring Only applicable to IaaS, PaaS, SaaS vendors:
(a) Service Level Agreements. Vendor must have documented service level agreements and their definitions for all services and APIs consumed by Socure, and should make such definition either publicly available or share such definition with Socure upon request. When Vendor makes changes to service level agreements, such changes must be notified to Socure at least 30 days before the change is made, and changes cannot degrade existing committed service level agreements.
(b) Status Page. Vendor must maintain a status page that indicates whether services are functioning as expected and continuously updates status page in a timely fashion when a service disruption occurs with current status and action taken to remediate. Vendor must provide a way to register for status page updates either through RSS or email notifications.
(c) Documented API. Vendor must expose availability metrics for their services through a documented API. These metrics should include uptime, downtime, Latency or response times, and error rates.
4.2.9Malware defenses
Vendor will deploy endpoint detection and response and anti-malware software to control, detect and remediate the installation, spread, and execution of malicious code on all assets.
4.2.10Firewalls
Vendor will maintain and configure firewalls to protect systems containing Socure Information from unauthorized access. Vendor will review firewall rule sets at least annually to ensure valid, documented business cases exist for all rules.
4.2.11Dedicated IP Addresses
Vendor will provide and document dedicated IP addresses for services that interact with Socure Information or Socure’s network. These dedicated IP addresses will be used exclusively for Socure’s traffic and will be documented and shared with Socure. This documentation must include the purpose of each IP address, the services associated with it, and any relevant network configuration details.
4.2.12Suitable Environment
Data will be used in an environment suitable to its purpose. Production data will not be used on test equipment and test data will not be used on production equipment.
4.2.13Change Management
Changes to production systems are tracked, recorded, appropriately authorised and reviewed per vendor’s change management policy.
4.2.14Authorised Services
Authorized services must be documented with a business justification and be appropriately approved. All unnecessary services, protocols, and ports are disabled or deleted.
4.2.15Encryption
Vendor will encrypt all Socure Information at rest and when in transit in accordance with industry best practices. Vendor will prohibit the use of known weak ciphers (reference https://www.cisa.gov/news-events/alerts/2021/01/05/nsa-releases-guidance-eliminating-obsolete-tls-protocol). For encryption at rest, AES128, or greater, shall be used. For encryption at transit, TLS 1.2 or higher shall be used. Vendor must transition to TLS 1.3 or its successor, as soon as possible and no later than December 2, 2029 to support the shift to Post-Quantum Cryptography (PQC). By December 2, 2034, all systems must transition to PQC as legacy algorithms will be disallowed. Upon Socure’s written request, the Vendor will confirm that all copies of encryption keys have been securely deleted.
4.2.16Access controls
Vendor will implement the following access controls with respect to Socure Information:
(a) Unique IDs. Vendor will assign individual, unique IDs to all Personnel with access to Socure Information, including accounts with administrative access. Accounts with access to Socure Information must not be shared.
(b) Need-to-know. Vendor will restrict access to Socure Information to only those Personnel with a “need-to-know” for a Permitted Purpose.
(c) Access termination. Vendor will terminate accounts within 24 hours of personnel separation from the Vendor.
(d) User access review. Vendor will periodically review Personnel and services with access to Socure Information and remove accounts that no longer require access. [This review must be performed at least once every 90 days.]
4.2.17“In bulk” access
Except where expressly authorized by Socure in writing, Vendor will not access, and will not permit access to, Socure Information “in bulk” whether the Socure Information is in a Socure or Vendor-controlled database or stored in any other method, including storage in file-based archives (e.g., flat files).
(a) Definition of “in bulk” access. For purposes of this section, “in bulk” access means accessing data by means of database query, report generation, or any other mass transfer of data.
(b) “In bulk” safeguards. Vendor will implement appropriate Physical, Organisational, Personnel, and TechnologicalSafeguards—including access controls, logging of all “in bulk” access, and monitoring to prevent and detect “in bulk” access to Socure Information or, where authorized by Socure, to (1) limit such access only to specified employees with a “need-to-know”, and (2) require explicit authorization and logging of all “in bulk” access.
(c) “In bulk” log access. Upon Socure’s request, Vendor will provide to Socure all logs on “in bulk” access referenced in this section.
4.2.18Account and password management
Vendor will implement account and password management policies to protect Socure Information, including, but not limited to:
(a) No default passwords. Before deploying any new hardware, software, or other asset, Vendor will change all default and manufacturer-supplied passwords to a password consistent with the password strength requirements in subsection (c).
(b) Inventory of administrative accounts. Vendor will maintain an inventory of all administrator accounts with access to Socure Information and will provide a list of these accounts to Socure at Socure’s request.
(c) Password strength. Vendor will ensure that all Personnel use strong passwords by enforcing the following minimum requirements. Socure encourages vendor to deploy FIDO2 security mechanisms for authentication and move to passwordless. If FIDO2 is deployed, the following password requirements do not apply.
- passwords must be a minimum length of 8 characters
- passwords must be unique and not be reused on any other system
- passwords may not match commonly used, expected, or compromised passwords; and
- Vendor must force a password change if there is evidence the password may have been compromised.
(d) Credential encryption. Encrypted passwords and other secrets shall be stored in an industry-accepted form that is resistant to offline attacks.
(e) Rate limiting. Vendor shall implement an industry-accepted rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on a user’s account.
4.2.18.1Single sign-on (SSO) and user management
If Vendor provides software for Socure’s use, either as a service or as a packaged software, the software must at a minimum provide the following controls:
(a) Single sign-on – The software must support integration with a SAML and / or OAUTH Single sign-on identity provider such as OKTA, Azure active directory.
(b) The software must support enforcement of Socure selected single sign-on identity provider as the only possible authentication mechanism.
(c) The software must support either SCIM for automated user lifecycle management or an API to manage user, entitlement and role management within the software, including provisioning, deprovisioning, role and entitlement query, assignment and removal. Vendor shall implement SCIM or APIs that integrate with a centralized Identity Governance (IG) solution (e.g. Okta) to automate the assignment of users and groups to roles within the application.
(d) If Vendor requires a service account to integrate, the Vendor needs to provide the functionality to rotate credentials via automated means.
4.2.19Multi-factor authentication (MFA)
Vendor will implement phishing-resistant multi-factor authentication (i.e., requiring at least two factors to authenticate a user and ideally use FIDO2.X as one of the factors) for access to (i) any network, system, application, or other asset containing Socure Information; or (ii) Vendor’s corporate or development networks.
4.2.20Data segregation
Except where expressly authorized by Socure in writing, Vendor will logically or physically isolate Socure Information at all times from Vendor’s and any third-party information.
4.2.21Security testing
Vendor will conduct internal and external penetration testing of systems that process Socure Information at least annually to identify vulnerabilities and attack vectors that can be used to exploit those systems. Identified vulnerabilities shall be addressed as part of Vendor’s vulnerability management program. Vendor will make available to Socure, upon request the results of such penetration tests and vulnerability remediation actions. Upon Socure request, Vendor will make available any internet-facing systems that store or process Socure information to a penetration test by Socure or its representative.
4.2.22Personnel security and nondisclosure
All Vendor Personnel with access to Socure information must sign an individual NDA with Vendor and successfully complete a background check by Vendor. In addition, Socure may require its own Non-Disclosure Agreement (NDA) to be signed by Vendor and/or individual Vendor Personnel. At a minimum:
4.2.23Restricted Individuals and Entities (“Covered Persons”)
Vendor will prohibit access to Socure information and systems by Vendor Personnel, Subcontractors, or any other third party that are: (I) listed on the Specially Designated Nationals and Blocked Persons List of the U.S. Department of Treasury (SDN List) or any other U.S. government restricted party list; (II) currently residing in a country subject to sanctions by the Office of Foreign Assets Control (OFAC); or (III) an entity 50% or more owned, directly or indirectly, by a person, entity, or government from a “Country of Concern” as defined in Section 4.2.24; or (IV) an employee or contractor of an entity or government of a “Country of Concern as defined in Section 4.2.24, regardless of where the individual resides, without Socure’s explicit prior written consent.
4.2.24Section 889 Compliance (“Covered Telecommunications Equipment or Services”)
Vendor will not provide to Socure, and will ensure no Subcontractor provides, any equipment, system, or service that constitutes or uses “covered telecommunications equipment or services” as defined under Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) and its implementing regulations (FAR 52.204-25), whether as a substantial/essential component or as critical technology of any system. Vendor represents that neither it nor any Subcontractor uses such prohibited equipment or services in connection with this Agreement, and will notify Socure promptly in writing if it discovers otherwise.
4.2.25Restricted Countries of Concern
Vendor will prohibit access to Socure information and systems by Vendor Personnel that currently resides in or accesses such information or systems from: (a) the People’s Republic of China (including provinces of Hong Kong and the special administrative region of Macau), (b) Russia, (c) Ukraine, (d) North Korea, (e) Iran, (f) Cuba, and (g) Venezuela unless otherwise specifically approved in writing by Socure. This restriction applies regardless of the Personnel’s nationality. Vendor must ensure that no vendor, subcontractor, or investor involved in performing services under the Agreement is located in, or majority-owned by an entity from, these locations without Socure’s explicit prior written consent.
4.3PCI DSS requirements
If, in the course of its engagement by Socure, Vendor has access to or will Process credit, debit, or other payment cardholder information, Vendor shall at all times remain in compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements (in addition to the minimum requirements in Section 4.2), and shall remain aware at all times of changes to the PCI DSS and promptly implement all procedures and practices necessary to remain in compliance with the PCI DSS.
4.4Subcontracts
Except as expressly set forth in the Agreement, Vendor will not subcontract or delegate any of its obligations under this Security Policy to any subcontractors, affiliates, or delegates (“Subcontractors”) without Socure’s prior written consent. Vendor will ensure that all requirements in this agreement are followed by any subcontractor, subprocessor or affiliate.
4.5Access to Socure Extranet and Vendor portals
Socure may grant Vendor Personnel access to Socure Information via web portals or other non-public websites or extranet services on Socure’s or a third party’s website or system (each, an “Extranet”) for the Permitted Purposes. If Socure permits Vendor to access any Socure Information using an Extranet, Vendor must comply with the following requirements:
4.5.1Permitted Purpose
Vendor and its Personnel will access Socure information or systems and access, collect, use, view, retrieve, download or store Socure Information solely for the Permitted Purpose.
4.5.2Accounts
Vendor will ensure that Vendor Personnel use only the Extranet account(s) designated for each individual by Socure and will require Vendor Personnel to keep their access credentials confidential. Accounts are not to be shared and must use secure multi-factor authentication (MFA).
4.5.3Systems
Vendor will access Socure information or systems only through either systems provided by Socure or in cases explicitly approved by Socure, computing or processing systems or applications running operating systems managed by Vendor and that include: (i) system network firewalls in accordance with Section 4.10.9 (firewalls); (ii) centralized patch management in compliance with Section 4.2.6 (vulnerability and patch management); (iii) operating system appropriate endpoint detection and response and anti-malware software in accordance with Section 4.2.9 (malware defenses); and (iv) for mobile and portable devices, full disk encryption and mobile device management (MDM) that ensures the device is running a version of the mobile operating system with no known vulnerabilities.
4.5.4Restrictions
Except if approved in advance in writing by Socure, Vendor will not download, mirror or permanently store any Socure Information from any Extranet on any medium, including any machines, devices or servers.
4.5.5Account Termination
Vendor will terminate the account of each Vendor Personnel and notify Socure no later than 24 hours after any specific Vendor Personnel who has been authorized to access any Extranet (a) no longer needs access to Socure Information or (b) no longer qualifies as Vendor Personnel (e.g., the personnel leaves Vendor’s employment).
4.6Socure Sub-Domains or URL’s
Any sub-domain or URL that the Vendor provisions for Socure’s sole use during the contracted period must not be issued or re-used by a non-Socure customer for 5 years after Socure terminates use of the service.