Annex II to the SCCs - Technical and Organizational Measures
For the purposes of Annex II to the SCCs, Company in its capacity as data importer, shall implement and maintain the technical and organisational security measures set out hereunder.
The data importer must maintain appropriate technical and organisational security measures to protect Meta Platforms Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. Such measures must take into account the nature, scope, context, and purposes of the processing as well as the risks.
Further to this, the security objectives described below are to be implemented by the data importer to protect its systems, including the physical, technical, and administrative controls that govern access to and use of the data importer's systems. Properly implemented, the measures below represent a description of the technical and organisational security measures that the data exporter would consider appropriate to protect the security of the data, taking into account the nature, scope, context and purposes of the processing activity as well as the potential risk to rights and freedoms of natural persons.
The data importer must, at the request of the data exporter, be able to describe the means by which they are achieving these security requirements and maintain appropriate records and other evidence to enable the data exporter to perform an assessment of the implemented security measures.
The data importer shall be responsible for its own compliance with its obligations under the SCCs and this Annex II to the SCCs, and shall be able to demonstrate such compliance upon request of the data exporter.
- Application Security
The data importer shall implement appropriate security measures to prevent, detect and mitigate threats or flaws in its products and services throughout the development lifecycle.
Where appropriate, these measures may include:
A. Secure coding practices which are communicated to all developers.
B. Periodic training for developers on secure coding methodologies.
C. For all in-house developed software, controls to identify, triage, monitor, and mitigate vulnerabilities or bugs in code through the use of static and dynamic tools and manual code reviews.
D. Separate production and development environments.
- a. Production data is anonymised if being used in development or testing environments or testing and development have controls implemented that are equivalent to production.
E. For applications that rely on a database, use of standard hardening configuration templates.
- Asset Management
The data importer shall actively manage (inventory, track, and correct) devices on its network, so that only authorised devices are given access, and unauthorised devices are found and prevented from gaining access to protected systems, applications and data.
Where appropriate, these measures may include:
A. Defined processes and approved channels for asset acquisition, including intake request and purchase approval.
B. Maintenance of an asset inventory, tracking all assets throughout their lifecycle.
C. End of life asset management procedures for the sanitization and destruction of all decommissioned production and non-volatile memory media including certification of sanitisation/destruction where appropriate.
D. Implementation of a mobile device management solution that allows controlled access to networks and has the ability to remotely wipe lost or stolen mobile devices.
E. Implementation of a system development life cycle to manage systems.
F. Periodically assess for unauthorized, unlicensed and unsupported hardware/software.
- Business Continuity and Disaster Recovery
The data importer shall protect critical business processes from the effects of major failures of information systems or disasters and ensure their timely resumption in the event of an incident. These measures must include requirements for ensuring ongoing availability and resilience of processing systems and services and for the ability to restore availability and access to data in a timely manner in the event of an incident.
Where appropriate, these measures may include:
A. Implementation of a disaster recovery program that focuses on making information systems resilient against failures and disasters.
- a. Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed.
- b. Designated personnel with responsibility for developing and improving disaster recovery capabilities.
- c. Adequate capacity planning to maintain availability.
B. Performance of data backups to enable resumption of system operations in an event of failure.
C. Replication of data across multiple data center regions across the globe/region and automatically route and load-balance network traffic based on latency and network health checks.
D. Regular disaster recovery tests and, based on the learning from these tests, works to update and improve disaster recovery processes.
- Security Compliance, Policy and Risk
The data importer shall align security objectives with business goals and applicable laws and regulations through the creation and maintenance of appropriate documentation, while effectively managing risk and meeting compliance requirements.
Where appropriate, these measures may include:
A. An established security leadership team including key stakeholders to operate, maintain and continually develop an information security program through an integrated system of policies, standards, guidelines and controls.
B. Maintenance of a suite of information security policies based on a standard policy framework.
- a. Provide risk-based security requirements and measurable security recommendations in policy form .
- b. Provide guidance on the adoption of requirements and recommendations.
- c. Procedures regarding the policy development lifecycle (development, implementation, maintenance, and exception management).
C. Regular assessments of compliance with security policies, frameworks, and regulatory requirements.
D. Maintenance of a risk program which includes risk assessment and risk management procedures.
- a. Inputs from activities such as vulnerability scanning, penetration testing, and product security reviews are used to determine risks.
- Configuration Management
The data importer shall have in place measures to configure systems and applications in a consistent and secure manner.
Where appropriate, these measures may include:
A. Configuration settings, including secure baselines are maintained for servers, mobile devices and network devices.
- a. Baseline configurations are stored in a central repository and define the services available on each system and how those services should be configured.
- b. Standard configurations are established for network devices.
- c. Systems are regularly checked for compliance with secure configuration baseline.
B. Security configurations are managed through configuration management and change control processes.
- Change Management
The data importer shall have in place measures to ensure changes to critical systems follow approved procedures and are tracked through version control tools.
Where appropriate, these measures may include:
A. A formal change management process and internal tracking system to initiate, log, review, approve and test system and configuration changes.
B. The monitoring changes for a period of time before full deployment to all production systems
- Data Security
The data importer shall have in place security measures to protect data confidentiality, integrity, and availability throughout the data lifecycle, from creation until deletion.
Such measures must be designed to implement confidentiality and integrity of processing systems and services and include requirements for the protection of data during transmission and storage such as encryption of data in transit and at rest.
Where appropriate, these measures may include:
A. Implementation of policies and standards such as data classification standards that require that appropriate security and access controls be implemented, taking into account data type, business need, the nature and purpose of processing, legal requirements, and roles and responsibilities of accessing parties.
- a. Noncompliance with such policies may result in a formal disciplinary process.
B. Policies define permitted and prohibited data sharing, based on data classification.
C. Documented encryption policy and/or procedure.
D. Data at rest is protected through encryption where appropriate.
E. Passwords are encrypted at rest and in transit.
F. Full disc or file based encryption is implemented on all managed laptops and mobile devices.
G. Encryption of data in transit across public networks using strong industry protocols.
H. Removable media is protected and its use restricted according to policy.
- Identity and Access Management
The data importer shall implement technical and organisational measures to provide security throughout the identity and access management lifecycle by ensuring access to data and systems are provisioned to the authorised people through correct channels.
Where appropriate, these measures may include:
A. User identity is tied to a unique account and access is limited based on role, elevated access such as administrative or super-user access that allows for the full control of critical identity and access management systems is restricted to authorized personnel.
B. Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.
- a. Procedures are in place to perform regular access reviews.
C. Identity management systems (or directory services) are used for managing account access credentials including accounts with elevated privileges.
D. Access credentials may not be shared with unauthorized individuals, stored on unauthorized devices, or retained in an insecure manner.
E. Changes to access levels are logged for analysis and investigative purposes.
F. Automatically disable account access credentials assigned to employees including contractors and contingent workers on their termination date.
G. Passwords meet password complexity requirements as defined in a password management standard or policy.
H. Multi-factor authentication is enabled.
I. Cryptographically protect or otherwise secure user passwords when stored and when in transit .
J. Change all default passwords prior to deploying any new asset.
- Logging and Monitoring
The data importer shall ensure that security logs are effectively generated, protected and reviewed to support the detection and investigation of suspicious events in production and corporate systems.
Where appropriate, these measures may include:
A. Logging and monitoring systems are designed to generate logs of event types that enable security related activities be detected.
B. Event data are collected and correlated from multiple sources and sensors.
C. Logs are sent to remote log aggregator systems.
D. Clocks are synchronised to a single referenced time source
E. Logs are protected in transit where appropriate.
F. Logs are protected against unauthorized changes or access.
G. Logs are backed up according to defined schedules and retention policies.
H. Procedures are in place to ensure that notifications from detection systems are routed to dedicated security personnel for investigation and escalated where appropriate.
I. Endpoint-monitoring software is in place to log and monitor activity on managed IT assets.
J. Implementation of cloud monitoring services .
- Network Security
The data importer shall have in place measures to securely design, protect and manage the supporting network infrastructure (including firewalls, routers, switches, and related infrastructure) and to protect information flowing in its networks from unauthorised access.
Where appropriate, these measures may include:
A. The use of secure protocols for remote access to critical systems such as an approved VPN client and multi-factor authentication.
B. The use of firewalls, host-based filtering, DDoS detection/mitigation technologies, anti-spoofing technologies on perimeter and edge information systems.
C. Deploy Network-Based IDS Sensors and Network-Based Intrusion Prevention Systems which are kept current with updated signature files of known vulnerabilities and attack patterns.
- a. Monitoring for unauthorized personnel, connections, devices, and software is performed.
D. Regular review of firewall and router configurations including automated port scans for service discovery to ensure that the configuration rules comply with applicable security requirements.
- a. Access to network device configurations are restricted to authorised personnel.
E. Segment the network based on sensitivity or where appropriate such as a separate wireless network for personal and untrusted devices.
- People Security
The data importer shall have in place processes which establish security expectations and responsibilities for its personnel before, during and after termination of employment.
Where appropriate, these measures may include:
A. Background checks are completed on employees and contractors prior to commencing employment.
B. Employees and contract workers sign confidentiality agreements prior to commencing employment.
C. Providing training to new hires on information security policies and procedures with further training related to job roles as appropriate.
D. Continuing security awareness training is provided to personnel throughout their employment.
E. Assets are returned upon termination of employment or contract.
- Physical Security
The data importer shall have in place measures to prevent unauthorised physical access to organisational assets and systems, to protect them from damage, misuse, destruction of theft. These measures include requirements for physical security of locations at which data are processed.
Where appropriate, these measures may include:
A. Visitor management processes to ensure visitors register at reception, present a valid ID, and sign a non-disclosure agreement, or otherwise obtain an approved exception
- a. Visitors are escorted by employees while on premises at all times.
B. Ability to monitor facilities and respond to physical security alerts 24x7 through use of CCTV, alarms and on premise security.
C. Access is controlled through access badges issued to personnel (including employees, visitors, interns, contract workers, and vendors).
D. Access to higher risk areas is monitored through enhanced physical and electronic means with badge access privileges limited to personnel on a need to access basis.
E. Where applicable data centres may use additional security measures including biometric devices.
F. Pre-approval is required to access higher risk areas such as data centres, server rooms or payment processing facilities.
- a. Access is reviewed regularly.
G. Protect data centre equipment from damage, destruction and/or interruption due to environmental factors, these measures include.
- a. Temperature and humidity level controls to monitor and maintain appropriate environmental conditions.
- b. Fire detection and suppression equipment is in place at all data centres.
- c. Redundant secondary power (UPS/CPS), backup generator units, and backup telecommunications to support critical systems in the event of a utility outage.
- Security Incident Response
The data importer shall have in place measures to prepare for, respond to and learn from security incidents in an effective manner.
Where appropriate, these measures may include:
A. A formally defined security incident response plan in place to detect, record, prioritise and respond to security incidents, including defined roles and responsibilities.
- a. Response plans should include escalation and isolation / containment procedures.
B. Recovery planning and processes are improved by incorporating lessons learned into future activities.
C. Incident Response plans are regularly tested, reviewed and updated.
D. Training is provided to enable employees and contractors to identify and report security incidents.
- Third Party Security
The data importer shall have in place measures to protect the security of data that is accessed, processed, transferred to, shared with, or managed by external parties and vendors.
Where appropriate these measures may include:
A. Processes in place for conducting due diligence on service providers who may receive or be granted access to data in order to evaluate whether their data security standards are appropriate in order to protect data.
B. Third party security assessments and audits are conducted by security personnel and are based on a range of factors
C. A level of assessment conducted for each third party determined according to the type of data the vendor may process and the nature of anticipated connectivity:
- a. Critical issues identified during the assessment process be remediated before a vendor is onboarded.
- b. Depending on the sensitivity of data shared with the service provider and other factors, the service provider may be required to undergo a periodic or random security assessmen.
- Vulnerability Management
The data importer shall have in place measures to prevent, detect, and remediate software vulnerabilities in its corporate and production infrastructure, including processes for regularly testing, assessing and evaluating vulnerabilities to ensure security of processing.
Where appropriate, these measures may include:
A. Development and implementation of a vulnerability management and patching program.
B. Performing regular vulnerability scans/detection on both internal and external systems to identify vulnerabilities and evaluate the risks.
C. Coordinate with owners of affected products or systems to resolve the vulnerabilities according to severity level and defined service levels.
D. A mechanism for third parties to report vulnerabilities in your software, application, or hardware.
E. The conduct of regular penetration tests to evaluate critical systems and processes for vulnerabilities.
F. The use of centrally managed anti-malware software which is updated regularly.
- Data Protection Principles and Data Subject Rights
The data importer shall have in place measures to ensure that personal data is:
A. adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed
B. accurate and, where necessary, kept up to date (with every reasonable step taken to ensure that personal data which is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay)
The data importer shall have appropriate measures in place to retain and delete personal data in accordance with relevant retention policies (as updated from time to time), and subject to requirements under applicable law.
The data importer shall have appropriate measures in place to assist the data exporter in complying with its obligations in respect of erasure requests and data portability, including by utilising commonly-used file formats and using tools to enable users to exercise their rights of access and portability.