Introduction #
1.1. The Information Security provisions which Tax Systems shall adhere to are as set out below.
Compliance & Governance #
2.1. Tax Systems shall maintain ISO 27001 certification for the duration of this Agreement.
2.2. In the event that Tax Systems is unable to maintain certification, Tax Systems shall:.
a) Inform the Customer in writing of its intention not to remain ISO 27001 certified together with details of how Tax Systems shall maintain the Information Security requirements of this Agreement.
2.3. Should Tax Systems ISO 27001 certification lapse and Tax Systems intend to re-apply for ISO 27001 certification, Tax Systems shall provide the Customer with a detailed action plan on how it intends to recertify, together with timescales for such actions.
Security awareness and education #
3.1. Tax Systems shall promote and maintain a security-aware culture where positive security behaviour is embedded. Tax Systems shall ensure that its staff and third party staff have the skills, knowledge and expertise to carry out their roles and responsibilities securely.
3.2. Tax Systems shall implement a security awareness and education programme which is:
(a) supported by a documented set of measurable objectives;
(b) recorded and tested so that they can evidence that their staff understand their security responsibilities; and
(c) delivered at regular intervals including when staff join the supply chain or move role.
3.3. Third party Tax Systems staff who interact directly with the Customer as part of the service, shall have appropriate security awareness training.
3.4. Tax Systems shall conduct regular, at least annually, ethical phishing tests on its staff.
Disaster Recovery #
4.1. Tax Systems will ensure that at all times it has in place and is able to implement a Disaster Recovery plan in accordance with its terms. Tax Systems.
4.2. Tax Systems will advise the Customer as soon as reasonably practicable of any event that causes or threatens to cause, disruption to the performance and operation resilience of any of the Services.
4.3. Tax Systems shall review the disaster recovery plan on a regular basis and, in any event, not less than once in every twelve-month period, in accordance with Good Industry Practice test the effectiveness of the disaster recovery plan
Physical Security #
5.1. The Customer acknowledges that Tax Systems only uses Microsoft UK Azure Cloud facilities for processing and storing Customer Data and that physical access to servers or infrastructure used in the processing of Customer Data is managed and controlled my Microsoft in accordance with their policies and procedures and that Tax Systems has no physical access to the servers or infrastructure.
5.2. Tax Systems will use physical security controls to protect its premises and assets from unauthorised access, damage, and threats.
5.3. Tax Systems shall ensure any Confidential documentation is physically protected from unauthorised access, damage, or loss.
Asset Inventory #
6.1. Tax Systems shall ensure any Confidential documentation is physically protected from unauthorised access, damage, or loss.
6.2. Tax Systems shall define and operate a process for managing asset inventories which includes:
(a) how they will be kept up-to-date (for example, new owners, change of use, disposal);
(b) when the process will be reviewed and approved; and
(c) when and how discrepancies will be identified and resolved.
Internal Acceptable Use #
7.1. To protect the Customer’s information against corruption, loss and unauthorised exposure, Tax Systems shall ensure its staff understand their security responsibilities and behave appropriately when working with Customer Data. This includes but is not limited to:
(a) Appropriate use of Tax Systems Assets and Systems;
(b) creating hard-to-guess passwords and keeping them secret;
(c) what to do when working away from the office;
(d) locking their screens when unattended;
(e) use of email system and treatment of unexpected or suspicious emails;
(f) anti-virus software dos and don’ts;
(g) use of resources;
(h) personal usage;
(i) legal responsibilities;
(j) Clear desk policy; and
(k) monitoring and enforcement.
Mobile Devices AUP #
8.1. The Customer acknowledges that Tax Systems operates a Mobile Acceptable Use Policy (MAUP) for company mobile devices.
8.2. Tax Systems shall maintain an MAUP which is available to all staff and contractors, which prohibits the download or storage of Customer Data on such devices.
8.3. Tax Systems shall include the use of Mobile Devices in its MAUP, making clear the consequences of breaching the terms of the MAUP.
8.4. Tax Systems shall deploy processes to ensure all Mobile Devices are appropriately protected, including but not limited to:
(a) device encryption;
(b) forced passcode or biometric entry;
(c) prevent the use of jail broken devices; and
(d) forced Operating Systems updates within 14 days of release.
8.5. Mobile Devices that do not conform to the above requirements shall not be granted access to Tax Systems’s infrastructure and systems.
8.6. Mobile Devices that fail to maintain the above (section 8.4) shall have access to Tax Systems’s infrastructure and systems withdrawn until such times as the Mobile Device meets the requirements.
8.7. Tax Systems shall ensure Multi-Factor Authentication (MFA) is required for access to Tax Systems’s systems from Mobile Devices.
8.8. Tax Systems shall block access to Tax Systems infrastructure or systems from the following countries and/or regions:
(a) Russia;
(b) China;
(c) North Korea; and
(d) Iran.
Audits and Compliance #
9.1. Upon reasonable written notice (no less than 30 days) and no more than once in any 12-month period, the Client may conduct audits (or use a mutually agreed third-party auditor) limited to verifying compliance with this DPA without disrupting Tax Systems’ normal operations. Such audits shall be conducted at the Client’s expense.
Vulnerability Management #
Penetration testing
10.1. Tax Systems shall perform annual independent Penetration Testing of its environment using CREST approved personnel. The results of such tests shall be managed by Tax Systems Information Security Management System (ISMS).
10.2. The Customer does not have the right to perform security tests, such as penetration testing, against Tax Systems’s solutions without written permission. The Customer may request the outcome of Tax Systems’s own annual independent penetration testing.
10.3. Tax Systems shall run regular, at least daily, attack surface vulnerability scans, the results of such scans shall be managed by Tax Systems Information Security Management System (ISMS).
10.4. The severity of identified vulnerabilities shall be measures and priorities using the Common Vulnerability Scoring System (CVSS) score (https://nvd.nist.gov/vuln-metrics/cvss).
10.5. Tax Systems shall use all reasonable commercial efforts to mitigate those vulnerabilities with a High or Critical severity rating (CVSS base score equal to or greater than 7.0). Medium severity rating vulnerabilities will be reviewed.
10.6. All other mitigation activities will be included into Tax Systems’s product development lifecycle for scheduled release.
Vulnerability Monitoring and Mitigation
10.7. Tax Systems shall:
(a) define and operate response processes to ensure timely response to detected events and incidents including phishing emails;
(b) establish a process for dealing with security events that require forensic investigation, to identify perpetrators of malicious acts and to preserve sufficient evidence to prosecute them if required;
(c) analyse security events to identify root cause, patterns, trends, and lessons to be learned, to reduce the risk of similar events occurring; and
(d) respond to security events by mitigating them or managing them as risks.
10.8. Tax Systems shall inform the Customer in writing no later than 72 hours after Tax Systems becomes aware of any vulnerabilities that may have a materially adverse impact on Tax Systems’s ability to meet its obligations under this Agreement.
Breach Management
10.9. Tax Systems shall ensure that it has appropriate Information Security Incident management mechanisms in place to ensure an effective response to Information Security Incidents, included within Tax Systems Information Security Management Systems.
10.10. In the event of an Information Security Breach Tax Systems shall notify the Customer at its first opportunity of any Information Security Incident but no later than 72 hours after the Breach has been identified. Tax Systems shall disclose to the Customer as much detail concerning its extent, effects, and mitigations as is possible. Tax Systems shall support the Customer and/or regulator in any post-incident investigation, remediation, and communications efforts.
10.11. Tax Systems and the Customer shall work together to formulate necessary remedial actions and measures such that are reasonably necessary to prevent reoccurrence of the breach.
10.12. Tax Systems will not issue any filings, communications, notices, press releases, or reports related to any Information Security Breach which would lead to the identification of the Customer without prior written approval from Tax Systems.
Security Incident and Event Monitoring
10.13. Tax Systems shall utilise Security Incident and Event Monitoring (SIEM) technology to alert information security threats to a 24x7x365 Security Operations Centre (SOC) for mitigation. Such monitoring shall include Tax Systems Azure environment as well as the wider organisational landscape.
10.14. Logs ingested into the SIEM shall be protected from deletion or alteration, and retained for a period of 12 months.
Endpoint management
10.15. Tax Systems shall maintain a register of Tax Systems Assets, together with owners and a unique asset identifier.
10.16. Tax Systems shall deploy perimeter protection solutions (such as Firewalls), such protection shall:
(a) be reviewed every 6 months for effectiveness of configuration;
(b) be maintained in respect of updated operating system or firmware within 30 days of such becoming available;
(c) be subject to Tax Systems’s Change Control policies and processes; and
(d) be protected from alteration or disabled by unauthorised persons.
10.17. Tax Systems shall encrypt, where possible or practical, all endpoints and maintain such encryption keys utilising an industry standard Key Management solution.
10.18. Tax Systems shall maintain the Operating System and/or BIOS of all endpoints within 30 days of release, with the exception of Critical security patches which shall be deployed within 14 days of release.
10.19. Tax Systems shall prevent the use of USB storage devices. Where a business need exists to use such USB devices, Tax Systems shall:
(a) ensure use complies with Tax Systems Policies and Processes;
(b) ensure all devices are encrypted and, where possible, password protected; and
(c) that such USB devices are not used to store or transport Customer Data.
10.20. Virus and Malware protection
(a) Tax Systems shall define and operate processes for malware protection on IT systems exposed to malware. These processes will:
(i) include a documented process for the distribution of malware protection;
(ii) include methods for installing and configuring the software;
(iii) mandate using the latest tested version of software and signatures; and
(iv) define what is to be scanned and when.
10.21. Tax Systems shall implement malware protection on IT systems exposed to malware. This malware protection will:
(a) use threat signatures which are distributed and updated automatically within 24 hours of release;
(b) use anomaly detection which includes behavioural analysis;
(c) provide an alert to Tax Systems when suspected malware is detected;
(d) prevent the spread of malware on IT systems;
(e) scan files as they are accessed;
(f) scan electronic messages and their attachments;
(g) carry out full scans periodically; and
(h) prevent the unauthorised modification or disabling of malware protection by unauthorised users.
Secure disposal
10.22. Tax Systems shall securely dispose of Customer information in paper form that’s no longer needed, so it can’t be recovered or read in line with BS EN 15713:2023 or equivalent.
10.23. Tax Systems shall securely dispose of Tax Systems owned electronic devices and digital removable media shall such that information can’t be recovered or read, in line with NIST SP 800-88 Revision 2.
10.24. Storage devices within Tax Systems Microsoft Azure Cloud environment that are used to store Customer information shall be disposed of in line with Microsoft’s secure disposal policies (https://learn.microsoft.com/en-us/azure/security/fundamentals/physical-security).
Access management and secure access
10.25. Tax Systems shall implement and maintain an Access Management Policy, including (but not limited to):
(a) conditions for 3rd party access and authorisations necessary;
(b) passwords requirements, including:
(i) complexity and strength;
(ii) change frequency;
(iii) history/recycling requirements;
(iv) change on first use (where appropriate);
(v) any uplifted requirements for high privilege account access;
(vi) User Accounts;
(vii) Ability to identify individuals; and
(viii) Where and under what conditions, generic user accounts are permitted.
(c) segregation of duties and the principle of least privilege;
(d) Necessary for an auditable trail which can be used for forensic analysis and must be ingested into the SIEM;
(e) Use of Virtual Private Network (VPN) for access to sensitive systems or information;
(f) The use of MFA where possible;
(g) The use of SSO for access to third party/supply chain systems where possible; and
(h) Annual review of all granted active access.
Supply Chain
10.26. The Supplier shall develop and maintain a Supplier Policy, including (but not limited to): information Security requirements and alignment with Tax Systems Information Security commitments;
(a) use of Single Sign On (from Tax Systems Active Directory) where available;
(b) annual review of Supply chain organisations to ensure compliance with Tax Systems and Supply Chain organisations requirements including licensing;
Security in Change Management
10.27. Tax Systems shall define and operate a change management process that applies to the following change types:
(a) upgrades and modifications to third party Tax Systems IT systems and applications;
(b) emergency fixes;
(c) changes to supporting IT systems and networks; and
(d) change of use (for example for buildings used as part of the service).
Tax Systems shall implement and maintain an Access Management Policy, including (but not limited to):
10.28. Before changes are applied, the change management process must ensure that:
(a) change requests are documented and approved by authorised individuals;
(b) changes are planned, taking into account other planned changes to IT systems;
(c) any IT system interdependencies are understood and acted upon,
(d) change assessment is performed;
(e) material changes are tested to determine the expected results is achieved;
(f) back-out positions are established so that the services can recover from failed changes or unexpected results;
(g) changes are performed by approved people with the required technical skills; and
(h) segregation of duties is maintained between the requesting, authorising, and implementing roles.
10.29. After changes are applied, the change management process must ensure that:
(a) checks are performed to confirm that only the intended changes have been made;
(b) supporting documentation including inventories and version control documents are updated; and
(c) details of changes are communicated to relevant people.
Information Security within Employees
10.30. Tax Systems shall develop and maintain a Policy to manage Information Security during employment.
The Policy shall include (but not limited to):
(a) Onboarding
(i) Information Security within Job Descriptions;
(ii) Information Security within employment contract;
(iii) System and privilege access requirements; and
(iv) Required Assets.
(b) Change of Role
(i) Review of system and privilege access requirements; and
(ii) Review of employment contract Information Security.
(c) Leavers
(i) Time and date of access with draw;
(ii) Return of Tax Systems Assets;
(iii) Protection of any information held within Employees email or OneDrive; and
(iv) Reinforcement of post-employment Information Security obligations.
(d) Information Security Education
(i) Information Security Induction training;
(ii) Annual training; and
(iii) Training in the event of a security incident or a change in legal or regulatory requirement.
Further Information #
For details on how Tax Systems protects its and customer information, please see: https://www.alphatax.com/security/
Tax Systems Service Level Agreements are detailed here: https://www.alphatax.com/legal-policies/service-levels/
Information Security Contact #
Customers may contact information.security@taxsystems.com with Information Security questions.