These Supplier Information and Physical Security Standards (the “Standards”) list the technical and organizational measures and security controls that Green Parrot Collective Pty Ltd, Vendors and Partners (for purposes of this document, collectively referred to as “Suppliers”) are required to adopt when (a) accessing Green Parrot customer facilities, networks and/or information systems, or (b) accessing, processing, or storing Green Parrot Confidential Information.

Supplier is responsible for compliance with these Standards by its Personnel, including ensuring that all Personnel are bound by contractual terms consistent with the requirements of these Standards. Additional security compliance requirements may be specified in Supplier’s Agreement or individual statement of work.

The Standards contain the following sections:
Section 1: Personnel/Human Resources Security
Section 2: Information Security Organization and Policy
Section 3: Compliance and Assessment
Section 4: Security Incident Management and Reporting
Section 5: IT Security Standards
Section 6: Backup, Business Continuity and Disaster Recovery
Section 7: Basic Physical and Environmental Security
Section 8: Definitions

1. Personnel/Human Resources (HR) Security

1.1. Supplier must perform Criminal and employment background checks, consistent with local laws and regulations, for all Personnel. The level of verification performed must be proportional to risk correlated to roles within the organization.

1.2. Supplier Personnel are required to agree, in writing, to abide by Supplier’s security requirements and organizational policies.

1.3. Supplier must have a comprehensive security awareness program for all Personnel that encompasses education, training and updates for security policies, procedures and requirements. Training must be provided at time of hiring and repeated at regular intervals thereafter (no less than every two years, and more frequently to the extent required by applicable law, regulation or standard (such as FedRAMP)).

1.4. Supplier must have formal disciplinary processes in place for Personnel and take appropriate action against Personnel who violate Supplier’s organizational policies, based upon the nature and gravity of the violation.

1.5. Upon termination of Personnel employment, Supplier must promptly remove access to Information Systems, Networks and Applications and confirm Personnel have not retained any Confidential Information.

1.6. Supplier is authorized to use subcontractors for the provision of the Services as long as Supplier is responsible for and contractually binds any subcontractor to comply with non-disclosure terms and security standards consistent with those set forth in the Agreement and this document.

1.7. Supplier must maintain and regularly update a list specifying its subcontractors, the country of destination of the data, and provide that list to Green Parrot entities upon reasonable notice. Green Parrot entities reserves the right to reject the use of any subcontractor or require reasonable steps to address objections to a subcontractor, for justified reasons.

2. Information Security Organization, Policies and Procedures

2.1. Supplier must have clearly defined organizational information security roles, responsibilities and accountability.

2.2. Supplier must publish, maintain and enforce formal written information security policies. Information security policies must be approved by management and communicated to Personnel. Personnel must be made aware of their obligations to protect Confidential Information, as well as the acceptable use of all Networks, Information Systems and Computers. The information security policies must be reviewed every year and updated as necessary.

2.3. Supplier must classify and label Information and enforce role-based access in accordance with their information classification scheme and in terms of its sensitivity.

2.4. Supplier must implement security processes for managing Suppliers throughout the business relationship lifecycle.

2.5. Supplier must maintain an inventory of assets that includes all business-critical information systems and information processing sites used in the delivery of Services to Green Parrot entities. The inventory must be accurate, remain current and include owners responsible for each asset.

2.6. Supplier must maintain an up-to-date record of Personnel who have access to Facilities, Information Systems, Networks and Applications, including their geographic location. Personnel access must be reviewed at least bi-annually and access promptly revoked when no longer deemed necessary for job function.

3. Compliance and Assessments

3.1. Regulatory Compliance
3.1.1. If Services involve Payment Card Information (PCI), Supplier will maintain compliance with the current version of the Data Security Standards (DSS) from the Payment Card Industry Security Standards Council (PCI SSC) for the duration of the Services provided to Green Parrot entities. On request, Supplier must provide Green Parrot entities the most recent PCI SSC “Attestation of Compliance” (AoC) reports prepared by a third-party PCI Qualified Security Assessor (QSA) for both Supplier’s systems and for any third-parties used by the Supplier for handling payment card data.

3.1.2. If Services involve Protected Health Information (PHI) subject to the U.S. Health Insurance Portability and Accountability Act of 1996 and the regulations promulgated under that Act (collectively, HIPAA), the Supplier will maintain compliance with HIPAA. On request, Supplier must provide Green Parrot entities reasonable assurance that Supplier (and any third parties used by the Supplier for handling PHI) maintains sufficient technical and organizational controls to comply with HIPAA requirements. This assurance may include audits and assessments from a qualified third-party and/or completion of a questionnaire with sufficient evidence to support Supplier’s compliance.

3.1.3. Supplier must inform Green Parrot entities if legislation applicable to the Supplier could prevent the Supplier from fulfilling the obligations relating to treatment of Green Parrot entities Personal Information.

3.1.4. In the event Supplier processes Confidential Information that is subject to additional regulatory requirements, or in a manner subject to additional regulatory requirements, Supplier agrees to cooperate with Green Parrot entities to comply with such requirements, including negotiating in good faith additional agreements as required for such compliance.

3.1.5. Supplier will comply with its obligations under applicable data protection laws. In the event Supplier processes Personal Information, Green Parrot entities and the Supplier must sign a data processing agreement.

3.2. Security Compliance
3.2.1.
Suppliers accessing Green Parrot entities’ Network may be required to execute a Green Parrot entities network access agreement.

3.2.2. Upon request, Supplier must confirm, in writing, the Supplier’s compliance with the requirements of these Standards and provide written responses to any questions that Green Parrot entities presents to Supplier regarding its security practices.

3.3. Security Assessments
3.3.1. Green Parrot entities reserves the right to perform security assessments to verify compliance with these Standards. Green Parrot entities will provide reasonable notification of a verification audit, ensure the audit is performed during normal business hours, and with minimal disruption to the Supplier’s business operations.

3.3.2. Supplier must promptly correct any material noncompliance issues identified during the security assessment.

3.3.3. Supplier cloud-based services provided to Green Parrot entities must undergo penetration testing by an independent third party, and summary findings made available to Green Parrot entities upon request. Any finding during the assessment must be remediated within a reasonable time period commensurate with this risk.

4. Security Incident Management and Reporting

5. IT Security Standards

5.1. IT Security Controls
5.1.1. Supplier’s Information Systems, Network Devices and Applications must be configured and deployed using a secure baseline (hardened) and unused ports/services must be disabled.

5.1.2. Supplier must implement controls to restrict connection times of idle/inactive sessions on Information Systems, Applications and Network Devices and terminate inactive sessions.

5.1.3. System clocks must be synchronized to a trusted time server source, maintaining accurate and synchronized time/time zone on all Information Systems and Network Devices and ensuring log files have consistent time stamp information recorded.

5.1.4. Supplier must have defined security review processes for the deployment of new services that store/process Green Parrot entities Confidential Information.

5.1.5. Supplier must perform security assessments, scans and testing of Information Systems, Networks and Applications at planned intervals, at least annually, to verify compliance with organizational security policies and standards.

5.1.6. Supplier must maintain documented change management procedures that provide a consistent approach for controlling and identifying configuration changes for Information Systems, Applications and Network Devices.

5.2. Network Security
5.2.1. Supplier must implement and maintain network security infrastructure components such as firewalls, intrusion detection/prevention systems (IDS/IPS) and other security controls, providing detection, continuous monitoring, and restrictive network traffic flow to assist in limiting the impact of attacks.

5.2.2. Network traffic must be appropriately segregated, with routing and access controls separating traffic on internal Networks from public or other untrusted networks.

5.2.3. Remote access into the Supplier’s Network must be approved and restricted to authorized Personnel only. Remote access must be controlled by secure access control protocols, encryption, authentication and logging.

5.2.4. If VPN access (either site-to-site or IPsec) is used to access Green Parrot entities Networks and Information Systems, Supplier must segregate Computers that remotely connect to Green Parrot entities (using either physical segregation or VLAN subnets) to prevent Green Parrot entities Confidential Information, Networks and Information Systems from potentially being accessible or visible to unauthorized personnel.

5.2.5. To the extent permitted by law, Green Parrot entities reserves the right to monitor Supplier access to and use of Green Parrot entities Information Systems, Networks and Applications (“Systems”) for compliance with these Standards, and violations are subject to immediate removal of access.

5.3. Logging
5.3.1. Supplier must maintain logs from Information Systems, Network Devices and Applications for a minimum period of 90 days, unless otherwise stated in an Order. Logs must provide sufficient details to assist in the identification of the source of an issue and enable a sequence of events to be recreated.

5.3.2. Logs must record date, time and source location (IP address/hostname) for all access attempts and successful unauthorized access. Logs must capture system and network security event information, alerts, failures, events and errors. Integrity of log files must be maintained and protected from tampering by restricting access to systems that store log information. Log files must be stored on a centralized log server.

5.4. Technical Vulnerability and Patch Management
5.4.1. Supplier must track information from vendors and other sources relating to technical vulnerabilities of Operating Systems, Applications, and Network Devices; and must promptly evaluate exposure to reported vulnerabilities to ensure that appropriate measures are taken to address potential risks.

5.4.2. Supplier must promptly apply patches for all Operating Systems, Applications and Network Devices according to a documented vulnerability & patch management process and policy that requires patches be applied in a consistent, standardized manner and prioritized based on criticality and risk. If a security patch cannot be promptly applied due to requirements for testing, then effective risk mitigation controls must be implemented until such time that patches can be applied.

5.4.3. Where feasible, Computers must be configured to automatically receive operating system patches and updates from a centralized service that manages and distributes updates.

5.4.4. Supplier must use anti-virus/malware detection software to prevent, detect and remove malicious code. The software must provide automated signature updates. The software must detect if anti-virus/malware software on Computers has been disabled or not receiving regular updates.

5.4.5. Automatic virus and malware scanning checks must be carried out on all email attachments sent to or received from external sources. Attachments identified as containing malicious code must be removed and deleted.

5.5. Account Management
5.5.1. Supplier must have user account management procedures to support the secure creation, amendment and deletion of accounts on Information Systems, Network Devices and Applications.

5.5.2. Supplier must ensure Information Systems, Network Device and Application owners authorize all new user account requests and identify redundant accounts.

5.5.3. User accounts must have a unique login identifier and password. Supplier Personnel must not share account credentials.

5.6. Access Controls
5.6.1. Access controls must be implemented for Information Systems, Networks and Applications that verify the identity of all users and restrict access to authorized users. Access controls must use a role-based access model based on the “least privilege” security principle and differentiate access levels for end users and privileged access (e.g., systems administrators).

5.6.2. Access controls must be implemented for Information Systems, Networks and Applications that provide appropriate separation of duties, e.g., different Personnel must perform the access authorization and access administration roles.

5.6.3. Access lists for Information Systems, Network Devices and Applications must be reviewed at least annually and access removed promptly when no longer required. Access to Green Parrot entities Information Systems, Networks and Applications by Supplier Personnel is limited to the purposes of performing Services as specified in the Agreement with Green Parrot entities.

5.7. Password Management
5.7.1. Strong password practices must be implemented, including minimum password length and complexity requirements (e.g., no dictionary words, use a mix of alpha, numeric characters, require special characters, etc.).

5.7.2. Passwords may not be reused.

5.7.3. Passwords must have a defined expiration period not to exceed 90 days; alternatively, password practices may follow all requirements for memorized secrets found in National Institute of Standards and Technology (NIST) Special Publication 800-53B.

5.7.4. Passwords must be distributed separately from account information, in a manner that ensures confidentiality of information.

5.7.5. Passwords must be encrypted when transmitted between Information Systems, Network Devices and Applications and when stored.

5.8. Protection of Green Parrot entities Confidential Information
5.8.1. Supplier may access, use and process Green Parrot entities Confidential Information only on behalf of Green Parrot entities and only for the purposes specified in the Agreement with Green Parrot entities and in compliance with these Standards.

5.8.2. Green Parrot entities Confidential Information stored on Supplier’s Computers (excluding servers) and external Electronic Media (e.g., USB memory storage, tape) must be fully encrypted using AES 256-bit or higher encryption.

5.8.3. Green Parrot entities Confidential Information must be physically or logically separated (as applicable) from the confidential information of Supplier and its customers.

5.8.4. Green Parrot entities Confidential Information may not be stored on mobile devices or device media cards unless encrypted using 256-bit or higher encryption and devices are managed through centralized device management software, with the capability to remotely lock and wipe lost/stolen devices.

5.8.5. Supplier must delete or securely destroy Green Parrot entities Confidential Information upon Green Parrot entities’ request, upon completion of Services or upon the termination of Services. Supplier may retain one copy of the foregoing materials, as required for regulatory retention purposes or by law, provided that any such copy is kept in encrypted format, is not used or accessed for any other purpose, and remains protected in accordance with the requirements of these Standards and is deleted promptly when no longer needed for such purpose.

5.8.6. Electronic Media containing Green Parrot entities Confidential Information must be sanitized before disposal using a process that assures complete data deletion and prevents data from being reconstructed or read, as prescribed in industry standards such as NIST SP 800-88 Revision 1 and DoD 5220.22-M. Defective Electronic Media containing Green Parrot entities Confidential Information must be physically destroyed.

5.8.7. Green Parrot entities Confidential Information must not be transmitted using unencrypted (plain text) channels or Services over public networks. Encrypted protocols protecting the transfer of information such as SFTP or TLS (TLS version 1.2 or higher).

5.8.8. Secure e-mail transport using Transport Layer Security (TLS version 1.2 or higher) between Green Parrot entities mail gateways and Supplier mail gateways must be used to protect Green Parrot entities Confidential Information sent using email.

5.9. Computing Environments
5.9.1. Supplier will not permit the use of personal email accounts for exchanging, processing or storing Green Parrot entities Confidential Information.

5.9.2. Supplier will not use production systems that store or process Green Parrot entities Confidential Information for development, testing or staging purposes.

5.9.3. The use of public cloud storage Services for the storage/exchange of Green Parrot entities Confidential Information must be agreed and approved in writing by Green Parrot entities.

6. Back-up, Business Continuity and Disaster Recovery

6.1. Information Backup

6.1.1. Supplier must ensure Information Systems, Computers and software involved in the performance of the Services provided to Green Parrot entities are backed up to online and/or offline storage. Backups must be tested in accordance with operational backup standards.

6.1.2. Backup media leaving Supplier’s facility must be protected against unauthorized access, misuse or corruption during transportation. Green Parrot entities Confidential Information stored on backup media must be encrypted using AES 256-bit or higher encryption.

6.1.3. If Supplier is storing Green Parrot entities Confidential Information on Green Parrot entities’ behalf, Supplier must ensure daily backups, at a minimum.

6.2. Business Continuity and Disaster Recovery
6.2.1. Suppliers must have a Disaster Recovery (DR) program and maintain a documented organizational Business Continuity Plan (BCP). The DR program and BCP must be designed to prevent the loss of data and to ensure the Supplier can continue to function through operational interruption and continue to provide Services as specified in its Agreement with Green Parrot entities. Supplier will provide Green Parrot entities written summaries of its DR program and BCP upon request.

6.2.2. Supplier must ensure the scope of the BCP encompasses all locations, Personnel and Information Systems used to perform or provide Services for Green Parrot entities.

6.2.3. The BCP must be tested at least annually with documented results. The Supplier will provide confirmation of tests performed, including identified gaps and remediation actions or plans.

6.2.4. Supplier must promptly notify and report the potential impact to Green Parrot entities when the DR plan is executed.

7. Basic Physical and Environmental Security

7.1. Supplier Facilities
7.1.1. Supplier must maintain a physical security plan to protect offices and information processing Facilities that address internal and external threats to sites. Plans must be reviewed and updated on at least an annual basis.

7.1.2. Sites must have secure entry points that restrict access and protect against unauthorized access. Access to all locations must be limited to authorized Personnel and approved visitors. All visitors must be logged and be escorted by Supplier Personnel at all times. Security guards, intrusion detection, and/or CCTV cameras must be used to monitor building entry points, loading and shipping docks, and public access areas. All visitors must be required to sign a visitor register.

7.1.3. Reception areas for offices and information processing Facilities must be manned by a receptionist or security guard. Off hours access must be monitored, recorded and controlled. Logs detailing access must be stored for a period of at least 90 days.

7.1.4. Supplier Personnel and authorized visitors must be issued identification cards. Visitor identification cards must be distinguishable from Supplier Personnel identification.

7.1.5. Access cards and keys that provide access to secure areas and information processing Facilities such as data centres must be monitored and limited to authorized Personnel. Regular reviews of access rights to Facilities must be performed.

7.1.6. Off-site removal of Information Systems, servers and Network Devices must be restricted, approved and authorized by appropriate security departments.

7.1.7. A clear desk policy must be enforced in areas where Green Parrot entities Confidential Information is stored. Documents that contain Green Parrot entities Confidential Information must be secured when not in use.

7.2. Green Parrot entities Facilities
7.2.1. Supplier Personnel are required to abide by Green Parrot entities’ security requirements and direction when working at Green Parrot entities Facilities. The security measures employed at Green Parrot entities Facilities (e.g., use and placement of security cameras, use and placement of other physical and logical security controls) are Green Parrot entities Confidential Information. Personnel may not photograph or otherwise record Green Parrot entities Facilities or infrastructure, unless required for the performance of Services and Green Parrot entities approves in advance.

7.2.2. Supplier Personnel may not access Green Parrot entities Computers or Networks unless expressly authorized by Green Parrot entities Personnel.

8. Definitions

Login / Sign UpGPC Platform