/ Docs

Security Measures

Last updated August 22, 2024 · View as Markdown

Overview

Commonly found in DPAs, Security Addenda/Exhibits, and MSAs, security measures are a data processorʼs contractual commitment outlining how a data controllerʼs personal data is protected against unwanted physical or electronic intrusion.

Relyance shows our customers what security measures their vendors have in place within the Vendor Lifecycle & ROPAs module on both the Universal ROPA and Contract Analysis tabs.

SecurityMeasures-1.png

Security Measures

Relyance AI has studied the landscape of available security measures frameworks, including the NIST Cybersecurity Framework, and has synthesized these into a common taxonomy.

The Relyance AI platform includes the following Security Measures:

Security Measure Description
Acceptable Use Policy A policy that governs how a company's personnel access, use, and disclose customer data
Access & Disclosure Controls Access and disclosure controls are those which limit what information a company or individual can access and define how that information can be disclosed.

Access controls generally prevent unauthorized individuals from accessing or manipulating data. Role-based access controls limit access to information based on the individual’s role, and least-privileged access is that which limits access only to information necessary for the individual to do their job.

Disclosure controls require security measures for all aspects of personal data transmission, including monitoring and logging related to: electronic transmission data transport transmission control storage (manual or electronic) subsequent inspection User access policies and procedures

Credential lifecycle and provision management, where user access policies and procedures are designed to provide the most flexibility while maintaining a high level of security at the same time.

Segregation of duties, which further restricts users and roles from accessing the system as a whole. Users can only access data and resources that are assigned to them based on their roles and responsibilities | | Additional Measures | Additional security measures to appropriate technical and organizational measures. This label will be avoided if a more specific label applies. | | Anonymization | Anonymization is a data processing technique that removes all personal identifiers such as names or addresses from data so that the data subject is no longer identifiable.

There are two types of identifiers – direct and indirect. Direct identifiers refer to your name, your address or a copy of your photo. Indirect identifiers include information such as your place of work (from your LinkedIn profile), location, or a behavioral trait.

For anonymization to be complete, direct and indirect identifiers must be removed. Anonymized data does not fall under the scope and scrutiny of GDPR. | | Application & System Security Controls | General security of the application.

Application & Interface Security is the design, development, and deployment of a software application and APIs in alignment with industry standards. | | Appropriate Technical & Organizational Measures | Technical and organizational measures are the functions, processes, controls, systems, procedures and measures taken to protect and secure the personal information that an organization processes.

Because this is a commonly used phrase, this label should be avoided if a more specific label applies. | | Article 32 GDPR Controls | Security addendums will often reference GDPR Article 32 or include its text in their contract provisions:

Security of processing

  1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

(a) the pseudonymisation and encryption of personal data;

(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;

(d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

  1. In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored or otherwise processed.

  2. Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.

  3. The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.

Select this label over "Appropriate Technical and Organizational Security Measures" when GDPR Article 32 is specifically referenced, or the text above (which comes directly from the statute) appears in the materially the same form in the contract. | | Audit Controls | Clause that governs terms around audit permissions and logistics. | | Business Continuity Controls | Business continuity planning (BCP) is the process a company undergoes to create a prevention and recovery system from potential threats such as natural disasters or cyber attacks. BCP is designed to protect personnel and assets and make sure they can function quickly when disaster strikes. | | Change Control Procedure | Change control is a process—either formal or informal—used to ensure that changes to a product or system are introduced in a controlled and coordinated manner.

Covers production/system changes, acquisition of new data or applications, addition of new data centers and infrastructure, outsourced product development, quality testing, and unauthorized software installs. | | Data Integrity Assurance | Data integrity is the maintenance and assurance of the overall accuracy, completeness, and consistency of data.

Data integrity also refers to the safety of data in regards to regulatory compliance — such as GDPR compliance — and security.

It is maintained by a collection of processes, rules, and standards implemented during the design phase; and needs to be maintained through reconciliation and multiple checks to avoid errors, corruption, and other security risks. | | Data Security by Design | Implementing privacy and security as new features and products are designed, at the design/inception stage, to think about privacy from the beginning instead of an afterthought. | | De-identification/Pseudonymization | De-identification is a process involving the removal of personal direct identifiers (such as names and addresses) which reduces the risk of re-identification and the use of security measures to prevent anyone from re-identifying the individual or data subject.

Pseudonymisation, under GDPR and as stated in Article 4(3b), refers to ‘the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.’

Common example of pseudonymisation: 16-digit card number masking to XXXX XXXX XXXX 1015 with only the last four digits visible. Other methods of pseudonymisation include encryption, tokenization and scrambling. | | Developer Controls | Developer - focused controls, including security protection into how the developer is selected, designs, implements, tests, and evaluates the system, component, or service under development. | | Encryption | Encryption without specification as to whether the data is at rest or in transit (see below). Will not be used if a more specific encryption label applies. | | Encryption at Rest | Data at rest in information technology means data that is housed physically on computer data storage in any digital form (e.g. cloud storage, file hosting services, databases, data warehouses, spreadsheets, archives, tapes, off-site or cloud backups, mobile devices etc.). Data at rest includes both structured and unstructured data. This type of data is subject to threats from hackers and other malicious threats to gain access to the data digitally or physical theft of the data storage media. To prevent this data from being accessed, modified or stolen, organizations will often employ security protection measures such as password protection, data encryption, or a combination of both. The security options used for this type of data are broadly referred to as data at rest protection (DARP). | | Encryption in Transit | Data in transit, also referred to as data in motion, and data in flight, is defined into two categories, information that flows over the public or untrusted network such as the Internet and data that flows in the confines of a private network such as a corporate or enterprise Local Area Network (LAN). The security options used for this type of data are broadly referred to as data in transit protection. | | Identification & Authentication Controls | Verification of the identity of an individual, device, or service in order to allow access to certain information. | | Incident Response Procedure | Outlines the process to follow when a security incident (a.k.a. data breach) happens or is suspected of happening. | | Information Management Controls | Relates to how data inventory and data flow is handled and includes: classification, handling/labeling/security policy, non production data (used for development, test and stage environments), ownership/stewardship, and secure data disposal. Ensuring the accuracy, availability, integrity, etc. of the information throughout the lifecycle.

Covers: how transactional data, such as e -commerce transactions, need to be classified and processed to prevent contract dispute process for defining responsibility and documenting how data is handled across the system | | Input Control | Input control requires that every piece of information is traceable back to input data.

Includes: Traceability, documentation of data transmission and maintenance Measures in place for subsequent inspection Measures to detect whether data been entered, amended or removed (deleted) | | Key Management | Key Management sets up a secure environment via key generation and key management policies that cover storage and access, and encryption for sensitive data, including: Entitlement - forces each key to have a clear owner and obliges processor to have clear key management policies in place Key generation - includes policies and procedures related to how encryption keys (and the identities behind them) are created Storage and access - security requirements for storing keys and identities are defined and implemented as policies | | Media Protection | Controls regarding how digital and non-digital media is handled, used, transported, stored, and disposed. | | Mobile Security Practices | Ensuring the security of portable devices such as mobile phones or laptops. | | Network Security Controls | The process of protecting the underlying networking infrastructure by installing preventative measures to deny unauthorized access, modification, deletion, and theft of resources and data. These security measures can include network access control, network security, firewalls, virtual private networks (VPN), behavioral analytics, and wireless security. | | Penetration Testing | An evaluation methodology whereby assessors search for vulnerabilities and attempt to circumvent the security features of a network and/or information system. | | Personnel Security Controls | Security measures in place with personnel which may be administrative, technical or organizational (e.g., cybersecurity training, contract, technical control) that limits access to data, including offboarding processes. Personnel controls require that unauthorized persons must not access data processing systems. Personnel measures cover: Asset returns Background screening Employment agreements Employment termination NDAs Personnel roles/responsibilities Acceptable use Training/awareness User responsibility Workspace | | Physical Security Controls | Control of physical access to data processor's premises to prevent internal and external threats; identification of authorized persons.

Covers asset management and controlling physical access, including: equipment identification off-site equipment authorization and logging of physical access to data center, servers and supporting equipment | | Return and Deletion of Customer Data | Requirements around the return and deletion of customer data, usually following the termination of the agreement. | | Security Certifications | Clause that governs terms around security certifications. | | Security Policy & Assessments | An administrative assessment & evaluation, which covers: regular review of security policies data focused risk assessments - processes where data governance requirements and risks are identified and mitigated, all while remaining in compliance with other requirements management oversight - may include development of an Information Security Management Program policy enforcement, disciplinary action and sanctions against employees who violate the security procedures policy impact on risk assessment A technical process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing | | Separation & Segregation Controls | Technical separation of data. Data collected for different purposes shall be processed separately. Measures in place for separate data processing (storing, alteration, deletion, transmission) of data with different contract purposes. | | Subprocessor Security Controls | Governs the requirements and obligations around the use of subprocessors. | | System Reliability Controls | Data availability means that information is accessible to authorized users. It provides an assurance that your system and data can be accessed by authenticated users whenever they're needed.

Data reliability governs data loss and uptime/downtime.

Resilience is the ability to prepare for and adapt to changing conditions and withstand and recover rapidly from disruptions. Resilience includes the ability to withstand and recover from deliberate attacks, accidents, or naturally occurring threats or incidents. | | Threat & Vulnerability Controls | Threat and Vulnerability Management covers: Antivirus / Malicious Software - policies and procedures that prevent the execution of malware and similar security threats Vulnerability / Patch Management - risk-based model for identifying security risks and prioritizing the development of patches and solutions Mobile Code - designed to address end-to-end security measures and communication between connected devices | | Transmission & Transfer Control | Measures to ensure data is protected during transit or transfer.

The Transmission Control Protocol (TCP) is an Internet protocol that connects a server and a client. Together, TCP and Internet Protocol (IP) are the set of networking protocols that enable computers to connect over the Internet.

TCP manages the reliability of the rails on which data packets travel to ensure that no packets are lost, they are properly ordered, and that there are no delays in the journey that would affect data reassembly or quality. IP manages the addressing and forwarding of the data to and from its proper destinations. TCP/IP work together in a protocol stack, with one protocol working on top of the other. | | Updates/Amendments to Security Measures | Clause that governs updates or amendments required in order to implement security measures between the parties. |