Version: 1.2
Date adopted: August 09, 2022
Table of Contents:
Each party recognises the importance of maintaining the highest levels of Information Security Management. Confidential Information can exist in many physical and electronic forms, and is subject to many types of human, physical and/or electronic threats when being transmitted, processed and stored.
By each party providing the other party with Confidential Information, it is necessary to define a set of minimum security standard requirements which ensure the continued safe-custodianship of those assets.
This document summarises the minimum technical and organisational controls each party should implement to maintain the security and integrity of Confidential Information in accordance with Security Industry best practices.
Each party shall employ operational and technological processes and procedures in line with good industry practices to protect against unauthorised use, access, loss, destruction, theft or disclosure of any information provided under the Agreement.
Each party shall be either registered to ISO27001, or have suitable controls in place which are aligned to the standard and demonstratable. If the Client is in the process of working towards the certification and is able to demonstrate progression, timescale of completion must be agreed with Transunion.
If a party is provided with access to Primary Account Numbers or is a Service Provider (in each case as defined by the Payment Card Industry Security Standards Council), it shall ensure that its environment and any subsequent services are provided in a manner which is compliant with the latest version of the Payment Card Industry Data Security Standard (“PCI DSS”). In addition, where applicable, each party must provide the other party with evidence of PCI DSS compliance certification. This must be an Attestation of Compliance (AoC) by an Payment Card Industry Qualified Security Assessor (PCI QSA) or appropriate Self-Assessment documentation that attests to the results of a PCI compliance audit or assessment.
Where applicable, SOC 2 compliance reports must be provided to each party as and when requested. This standard is a minimal requirement for those providing or considering a SaaS provider.
Information security management defines and manages controls that an organisation needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities.
Each party shall ensure that the following requirements are met:
Each party will ensure that the following requirements are met:
Each party shall ensure that appropriate secure measures will be implemented, at all premises, including remote working locations, at which that party (or its staff), access, store or otherwise process Confidential Information. Such appropriate measures shall include (to the extent possible and/or practical, depending on the applicable location), the following:
Each party will encrypt all personal data contained in Mobile Media. “Mobile Media” means portable and mobile devices used to store and transport information (including, but not limited to, paper records and magnetic and other electronic media, laptops, computers, mobile phones, memory sticks, PDAs, discs, external hard drives, and magnetic tapes)
Each party shall implement the following access control measures in respect of its technical environment:
Each party shall ensure that the following requirements are met:
Each party shall ensure that the following requirements are met:
Each party shall have an appropriate Business Continuity Management System (including Disaster Recovery) in place that will include a documented Business Continuity Plan and Policy. A Business Continuity Plan (BCP) must be tested and updated on a regular basis to ensure its effectiveness in the event of a disaster and its continuing relevance to the Business. There must also be a named individual in place who is responsible for the day to day management of Business Continuity.
If the Client is provided with access to a TransUnion API service, each party shall ensure that its communication with the API is encrypted to a suitable standard in line with industry best practice.