Your legal name ( cover will apply to all your subsidiaries unless you tell us otherwise))For how many years have you carried on business ?StreetAddressStatePostcodeCountryAfghanistanAfrique du SudAlbanieAlgérieAllemagneAndorreAngolaAnguillaAntarctiqueAntigua-et-BarbudaAntilles NéerlandaisesApatridesArabie SaouditeArgentineArménieArubaAustralieAutricheAzerbaïdjanBahamasBahreïnBangladeshBelgiqueBermudesBhoutanBiélorussieBolivieBosnie-HerzégovineBotswanaBruneiBrésilBulgarieBurkina FasoBurundiBélizeBéninCambodgeCamerounCanadaCap VertChiliChine, République populaire deChypreCité du VaticanColombieComoresCongo, République duCongo, République démocratique duCorée, République deCorée, République démocratique populaire deCosta RicaCroatieCubaCuraçaoCôte d’IvoireDanemarkDjiboutiDominiqueEspagneEstonieFidjiFinlandeFranceFrance, MétropolitaineGabonGambieGhanaGibraltarGrenadeGroenlandGrèceGuadeloupeGuamGuatémalaGuerneseyGuinéeGuinée ÉquatorialeGuinée-BissauGuyaneGuyane françaiseGéorgieGéorgie du Sud et Sandwich du SudHaïtiHondurasHong KongHongrieIndeIndonésieIranIraqIrelandIslandeIsraelItalieJamaïqueJaponJerseyJordanieKazakhstanKenyaKirghizistanKiribatiKosovoKoweïtLa BarbadeLesothoLettonieLibanLibyeLibériaLiechtensteinLithuanieLuxembourgMacaoMacédoine du NordMadagascarMalaisieMalawiMaldivesMaliMalteMarocMartiniqueMauritanieMayotteMexiqueMicronésieMoldavieMonacoMongolieMontserratMonténégroMozambiqueMyanmarNamibieNauruNicaraguaNigerNigeriaNiuéNorvègeNouvelle ZelandeNouvelle-CalédonieNépalOmanOugandaOuzbékistanPakistanPalauPalestine, État dePanamaPapouasie-Nouvelle-GuinéeParaguayPays-BasPhilippinesPolognePolynésie FrançaisePorto RicoPortugalPérouQatarRoumanieRoyaume-UniRussieRwandaRépublique CentrafricaineRépublique DominicaineRépublique TchèqueRépublique du SalvadorRépublique démocratique populaire du LaosSahara occidentalSaint Pierre et MiquelonSaint-Kitts-et-NevisSaint-MarinSaint-Martin (Royaume des Pays-Bas)Saint-Vincent-et-les-GrenadinesSainte LucieSainte-HélèneSamoaSamoa américainesSao Tomé-et-PrincipeSerbieSeychellesSierra LeoneSingapourSlovaquieSlovénieSomalieSoudanSoudan, SudSri LankaSuisseSurinameSuèdeSvalbard et Jan MayenSwazilandSyrieSénégalTadjikistanTaiwan, République de ChineTanzanieTchadTerres australes et antarctiques françaisesTerritoire britannique de l’océan IndienThaïlandeTimor-OrientalTogoTokelauTongaTrinité et TobagoTunisieTurkménistanTurquieTuvaluUkraineUruguayVanuatuVietnamVénézuélaYemenZambieZimbabweÉgypteÉmirats Arabes UnisÉquateurÉrythréeÉtats-Unis d’Amérique (USA)ÉthiopieÎle BouvetÎle ChristmasÎle Heard et île McdonaldÎle JohnstonÎle MauriceÎle NorfolkÎle de la RéunionÎles CaïmansÎles CocosÎles CookÎles FalklandÎles FéroéÎles Mariannes du NordÎles MarshallÎles PitcairnÎles SalomonÎles Turques-et-CaïquesÎles Vierges américainesÎles Vierges britanniquesÎles Wallis et FutunaÎles mineures éloignées des États-UnisWebsiteEmail AddressPlease provide your revenueWhat % of your revenue is from ecommerce ?How many staff do you have ?Please describe the nature of your business :Have there been any mergers or acquisitions in the last 3 years or are there any planned in the next 12 monthsHave there been any mergers or acquisitions in the last 3 years or are there any planned in the next 12 monthsWhat % of your revenue is to the following market sectors:GovernmentManufacturing/IndustrialConstruction/EngineeringRetailHealthcare/MedicalFinanceOtherIf the above business activity and sector split has been substantially different in the past 12 months, please explain:If any substantial changes are expected in the next 12 months, please explain:Please provide details of personal information (in both electronic and non-electronic form) you process or store using the following table. This should include information relating to employees and third-parties:Please provide further details below if necessary:Please indicate your level of compliance with the latest Payment Card Industry (PCI) data security standards:If you have answered less than 100% compliance for the level of transactions you process, please advise what steps you are taking to ensure future compliance and the expected timeline for major milestones to achieve this:Do you operate any POS systems?YesNoplease explain how you prevent intrusions and protect card data, including wehther you emply full end to end encryption, tokenisation and white labelling etc. If you do not use these measures, how do you ensure the security fo the card data?Do you obtain permission before collecting sensitive personal information?YesNoDo you have a material or critical reliance on any computer system or platform (including any industrial control system) for any aspect of your continuing business operations?YesNoplease state in what way you are reliant and what steps you take to mitigate that risk includingreduntant servers,hot and warm start backups, co-location, mirror sites etc.how frequently you back up,how often you test your BCP and DRP and backup processe to ensure they remain effectives,any steps you have taken to quantify the likely loss of net profit from the failure of a critical system (for example carrying out a business impact assessment),how interdependent different systems are (ie could a failure of one critical system bring down many systems or are they sufficiently segregated to minimise that risk?),have you calculated any RTO or do you have plans to do so?Do you have a designated Chief Privacy Officer?YesNoDo you have a designated Chief Information Security Officer?YesNoDo you have a formal risk assessment process that identifies critical assets, threats and vulnerabilities?YesNoDo you have a formal documented policy with respect to:Data classificationYesNoInformation SecurityYesNoPrivacyYesNoAcceptable UseYesNoAccess ManagementYesNoDisaster recovery and business continuity with defined RTO?YesNoDo you perform annual disaster recovery tests of critical systems?YesNoDo you have a formal security due diligence and sign-off process prior to appointing system vendors and third party service providers?YesNoDo your contracts with such vendors include rights of audit, minimum network security standards and rights of audit?YesNoDo you perform formal reviews of third party service providers to ensure that they adhere to your data security requirements?YesNoDo you have installed and configured:firewalls to prevent unauthorised access and antivirus software on all end-points, mission critical servers, portable media and connection points etc ?YesNoan intrusion detection and prevention system?YesNoWhitelistingYesNoa solution to protect the security of mobile devices that store Company data?YesNoSecurity Event Management Software?YesNoData leak prevention softwareYesNoComment:Have vulnerability audits and/or has third party penetration testing been carried out in the last 12 months?Vulnerability auditsYesNoPenetration testingYesNoPlease provide brief details including whether any ‘red-flag’ or critical issues or vulnerabilities were identified:Is sensitive data ever stored on internet facing servers?YesNoDo you automatically update or patch commercial desktop software and open source software for known vulnerabilities?YesNoDo you use any software that is considered retired or “end-of-life” by the manufacturer and is no longer supported (for example Windows XP)?YesNoDo you have a formal procedure to add, delete or modify user access to your computer system?YesNoDo you enforce complex passwords (at least 8 characters and that must contain both alphabetic and numeric characters), which must be regularly changed?YesNoDo you use a multi-factor authentication system for remote access to its computer system?YesNoDo you perform a criminal history check and obtain references for all new recruits and (if relevant) contractors?YesNoDo you regularly conduct information security awareness training for employees including Phising?YesNo) Do you have entry controls that limit and monitor physical access to premises where your systems or data are held?YesNoDo you maintain daily off-site back-ups of critical system data?YesNoDo you regularly test your ability to recover back-up data?YesNoEnvoyer le message