Skip to content

RINP // CYBERSECURITY SERVICES

Resource Center
Customer Review FAQ

The canonical answer framework for the questions raisedin a vendor security review is available on this page.

We gather the questions frequently raised in vendor cybersecurity reviews under eight headings aligned with the SIG, CAIQ, and VSAQ patterns. The standard and verifiable record underpinning each answer help assessment teams conduct the review process consistently.

The answer framework describes the information security, data protection, access control, and controlled testing processes we apply in service delivery. Organization-specific fields are completed according to the customer’s request; the legal scope is supported by the relevant legislation and contractual records.

NavigateOn-page navigation: eight categories

// 8 CATEGORIES · 22 QUESTIONS01

The answer framework, category by category

K1

Company and Corporate Framework

Legal entity identity, certification track, and insurance coverage

The full trade name, MERSIS number, tax office, trade registry number, and registered head office address are set out in the official corporate identity document. This information is conveyed by formal letter to the customer’s legal or procurement unit before the vendor contract is signed. The corporate identity document is provided as a separate KYC package upon request.

Basis: Turkish Commercial Code Art. 39 (trade name), Tax Procedure Law Art. 5 (tax registration)

Corporate certifications, team competency certifications, and in-progress certification processes are maintained in separate lists. Tracking of corporate certifications follows the annual audit calendar; team certifications for offensive security competencies are managed in an individual competency map. We share the current certification status based on the official record as of the date of the request.

Basis: ISO/IEC 27001:2022 Annex A.5.31 (compliance review); Shared Assessments SIG Core category A

Professional liability (errors and omissions) and cyber liability policies for offensive security services are renewed annually. The coverage amounts, insurer information, and policy certificate are conveyed to the customer during the vendor approval process. The scope of any consequential damage that may arise during testing is defined in a separate clause within the policy.

Basis: SIG Core E (Risk Management): insurance requirement; Shared Assessments

K2

Personnel and Access Security

Background verification, training, least privilege, and confidentiality discipline

All team members undergo identity, education, reference, and criminal record verification during the hiring process. Verification is carried out through an accredited HR service, and the resulting file is retained in the relevant personnel record. When critical customer projects require additional verification, we extend this process according to the customer’s request.

Basis: ISO/IEC 27001:2022 A.6.1 (pre-employment screening); SIG Core G (Human Resources)

Alongside annual security awareness training, the team maintains an individual training plan for the upkeep of offensive competencies. Each team member’s minimum annual hands-on lab hours, industry conference attendance, and certification renewal schedule are tracked in the competency map. The plan is reviewed at the annual performance discussion.

Basis: ISO/IEC 27001:2022 A.6.3 (awareness and training); NIST SP 800-181 NICE framework

For each engagement, access accounts valid only for the duration of that engagement are provisioned, and access to out-of-scope systems is restricted in writing. All team members sign a customer NDA in addition to the corporate NDA; when the engagement ends, the access accounts are closed and evidence of closure is recorded. This discipline is applied together with the controlled Rules of Engagement (RoE).

Basis: ISO/IEC 27001:2022 A.5.15 (access control); CIS Controls v8 IG2 #6

K3

Data Security and KVKK

Customer data lifecycle, encryption, and the KVKK 6698 accountability chain

Customer data is protected with industry-standard transport layer encryption in transit and with a symmetric block cipher algorithm at rest. Encryption keys are rotated through a dedicated key management service; access to production keys is kept under dual-approval controls. Key destruction is completed at the end of the retention period.

Basis: ISO/IEC 27001:2022 A.8.24 (use of cryptography); NIST SP 800-57 key management

Raw evidence data is retained for a limited period after the engagement ends, while report and summary documents are kept within a longer audit window. At the end of the retention period, all customer data is deleted through an approved destruction procedure and a destruction record is generated. Retention periods can be shortened by contract according to the customer’s preference.

Basis: KVKK 6698 Art. 7 (erasure/destruction/anonymization); ISO/IEC 27001:2022 A.8.10

In a typical vendor engagement, the customer acts as the data controller and Red in Pulse as the data processor. The data processing agreement signed between the two parties defines the KVKK Art. 12 obligations, the limits of instructions, and the terms for use of subprocessors. In special projects that require a change of roles, the definition is redone through a contract addendum.

Basis: KVKK 6698 Art. 3 (definitions), Art. 12 (data security); KVKK Data Processors Guide

By default, customer data is processed on systems under Turkish jurisdiction. A cross-border transfer is possible only with the customer’s written consent, the satisfaction of the KVKK Art. 9 conditions, and additional measures appropriate to the purpose of the transfer. If a cross-border data flow exists in third-party tools, this is disclosed to the customer at the start of the engagement.

Basis: KVKK 6698 Art. 9 (cross-border transfer); KVKK 2024 cross-border transfer regulation

When a security incident affecting customer data is detected, the customer point of contact is informed as soon as possible after the initial assessment and within the 72-hour notification threshold defined in the KVKK guidance. The notification includes the scope of the incident, the affected data categories, the initial measures taken, and the next steps. The KVKK notification is made according to the allocation of roles in the contract.

Basis: KVKK 6698 Art. 12/5 (breach notification); KVKK Data Breach Notification Guide

K4

Technical Infrastructure

Test lab isolation, authentication, and endpoint security

The offensive test lab is logically separated from the corporate office network; engagement-specific project areas operate in isolation from one another. Customer evidence is processed only within the isolated area of that engagement; when the engagement ends, the area is put through a sanitization procedure. This isolation prevents both side-effect risk and cross-customer leakage.

Basis: ISO/IEC 27001:2022 A.8.22 (segregation of networks); CIS Controls v8 IG2 #12

Multi-factor authentication is mandatory on all team accounts; hardware keys are preferred for privileged accounts. Corporate passwords are stored in a centralized password management tool, and the use of shared accounts is not permitted. Privileged access is authorized on a per-session basis, and session logs are retained for audit purposes.

Basis: ISO/IEC 27001:2022 A.5.17 (authentication information); NIST SP 800-63B

All team endpoints operate under central device management; full disk encryption is mandatory and an endpoint detection and response solution provides continuous monitoring. Critical security patches are applied within a strict SLA; a non-compliant device is quarantined before it is granted access. The endpoint inventory and compliance status are monitored by administrators.

Basis: ISO/IEC 27001:2022 A.8.1 (endpoint devices); CIS Controls v8 IG1 #4-#10

K5

Test Execution Discipline

Written authorization, scope, prohibition of destructive testing, and incident response

No test begins without an authorization document and scope statement signed by the customer. In-scope assets, test windows, the escalation communication line, and approval gates are fixed as separate clauses in the controlled engagement file. When a scope change is requested, written additional approval is obtained with the same discipline.

Basis: PTES Pre-engagement Interactions; NIST SP 800-115 §3

Destructive test actions are prohibited by default; steps carrying potential impact are carried out only with written approval and within a controlled window. If an incident affecting a production system emerges during testing, the team halts the action, alerts the customer escalation line, and shares the observation records. Response responsibility operates according to the allocation of roles in the contract.

Basis: NIST SP 800-115 §6 (test execution); OSSTMM 3.0 RoE

The finding report is delivered over an encrypted channel only to the authorized recipient list previously provided by the customer. The executive summary and the technical report are prepared as separate files; the distribution permission for each file is handled separately. The report is shared with third parties only with the customer’s written consent.

Basis: ISO/IEC 27001:2022 A.5.13 (labeling); SIG Core L (Data Management)

K6

Certification and Standard Alignment

ISO 27001, SOC 2, NIST CSF, OWASP, BRSA, and KVKK mapping

The verification scope of each service is mapped to recognized control frameworks, and this mapping is published in a separate reference table. In the mapping matrix, ISO 27001:2022 Annex A, NIST CSF 2.0 functions, SOC 2 trust criteria, OWASP ASVS, KVKK Art. 12, and sector frameworks are visible against the nine services. Upon customer request, additional framework mappings can be added to the contract.

Basis: Compliance Mapping Matrix; ISO/IEC 27001:2022 Annex A; NIST CSF 2.0

For financial sector customers, the BRSA Information Systems and Electronic Banking Services regulations, together with the relevant penetration testing guidance, are taken as a reference in the engagement scope document. For the KVKK Art. 12 data security obligation, verification results are shown in the control mapping. When regulatory expectations change, the service scope is calibrated accordingly.

Basis: BRSA IS and Electronic Banking Services Regulation; KVKK 6698 Art. 12; Compliance Mapping Matrix

K7

Business Continuity and Emergency Response

Backup, customer data loss scenario, and loss of key personnel

Evidence stores are backed up periodically and backup integrity is verified on a regular basis. In a data loss scenario, the recovery time objective (RTO) and recovery point objective (RPO) are defined in the business continuity plan. The scenario is exercised through an annual tabletop drill, and the results enter management review.

Basis: ISO/IEC 27001:2022 A.5.29-A.5.30 (business continuity); ISO 22301

Every engagement is conducted with a two-person discipline; alongside the primary operator, a backup team member can access the engagement records. When the operator becomes unreachable, the handover procedure passes to the backup member while preserving the chain of evidence. This discipline ensures that the customer finds an uninterrupted communication line throughout the engagement.

Basis: ISO/IEC 27001:2022 A.6.5 (segregation of duties); SIG Core J

K8

Third Party and Supply Chain

Subprocessor, cloud service provider, and open source tool management

Using a subprocessor is not a default practice; when needed, it is applied only in well-defined roles and with the customer’s written consent. The subprocessor agreement includes NDA, KVKK compliance obligation, and scope limitation clauses. The subprocessor list and roles are disclosed to the customer at the start of the engagement.

Basis: ISO/IEC 27001:2022 A.5.19-A.5.22 (supplier relationships); KVKK Art. 12/2

The cloud service providers used in the test tooling infrastructure, the region preferences, and the components that touch customer data are maintained in a separate technology inventory. Open source tools are tracked with a software bill of materials discipline; security advisories are monitored and affected components are updated. When the customer requests it, we share a summary of the inventory.

Basis: CSA CAIQ v4 STA (Supply Chain Management); SLSA framework; CycloneDX SBOM

// CUSTOMER REVIEW

Is your security review form awaiting an answer?

The framework answers on this page cover the large majority of typical questions. If there are specific questions on your form, or if your organization’s risk management process requires additional verification, you can request answers directly through the contact line. In a pre-contract discovery call, the scope and the controlled engagement framework are reviewed together.