Question group
Data protection and encryption
How the customer's data is protected at rest and in transit, where it sits, how long it is kept and how it is destroyed. Card data questions sit here too, and reach past an ISO 27001 certificate.
The families
5 families| Family and a typical question | ISO 27001 | Evidence expected |
|---|---|---|
| Encryption at restDo you encrypt customer data at rest? Specify the algorithm. | 8.24 | The cryptography standard naming the algorithms and key lengths, where stored data is encrypted, and who holds and rotates the keys. |
| Encryption in transitIs all data encrypted in transit using TLS 1.2 or higher? | 8.24 | The protocol versions and cipher settings in use on every external and internal path that carries the customer's data, and the certificate management record. |
| Data retention and secure deletionHow is customer data deleted or returned at the end of the contract? | 8.10 | The retention schedule for the customer's data, the deletion method on each store including backups, and the deletion certificate template used at exit. |
| Data location and transfersIn which countries will our data be stored and processed? | 5.31 | A list of the countries and facilities where the customer's data is stored, processed and backed up, and the transfer mechanism for each country outside the customer's own region. |
| Cardholder data and PCI DSSDo you store, process or transmit cardholder data? | none | The PCI DSS attestation of compliance or self-assessment for the service, with its scope, and the data flow showing where account data goes. |