Vendors must integrate security practices into their service management approach, aligning with Uhubs's security requirements (e.g. ISO / SOC, Industry Leader, GDPR Compliant).
Establish SLAs with vendors, emphasizing incident response commitments, transparency, and collaboration during security incidents.
Follow the Incident Response plan outlined in the Governance, Risk and Compliance Policy.
Simulate a cloud service disruption to evaluate the effectiveness of incident response procedures specific to cloud environments.
Test the response to a simulated data exfiltration incident, focusing on detection, containment, and communication in cloud-based scenarios.
Simulate a security incident involving a vendor, assessing coordination, communication, and resolution processes.
Measure the average time taken to resolve security incidents within cloud environments.
Track the efficiency of Uhubs's response to e-discovery requests, ensuring timely and accurate information retrieval.
Evaluate the effectiveness of incident response efforts when collaborating with vendors.
Triage events based on their impact on cloud services, prioritizing incidents affecting critical infrastructure.
Prioritize e-discovery requests based on legal requirements, ensuring compliance with timelines and accuracy.
Establish criteria for identifying incidents requiring vendor collaboration, streamlining coordination efforts.
Establish protocols for notifying vendors in the event of a security breach, emphasizing timely and transparent communication.
This vendor timeframe is separate from, and does not limit, the customer notification commitment in section 6.2.
Define procedures for reporting e-discovery findings, adhering to legal requirements and maintaining transparency.
Uhubs notifies affected customers in writing without undue delay after becoming aware of any actual or suspected security breach, unauthorised access, or loss of data affecting the Platform or customer data held within it, and in any event within the timeframe agreed in the applicable data processing agreement or contract.
The first notice covers what is known at the time. Uhubs does not wait for a complete picture before notifying.
Conduct regular reviews of vendor points of contact, ensuring accurate information for incident reporting and coordination.
Maintain up-to-date information for legal contacts and e-discovery points of contact to facilitate efficient communication and compliance.
Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.