Showing 25 question(s) for "Service Provider Process"
Is there a user guide for TPN+?
Yes, you can find a comprehensive "how to guide" on our website under the "Links & Resources" page
How do I get my Company details published in the TPN+ Company registry and visible to the member Content Owners?
Upon payment of the TPN annual membership fee, your details are visible in the TPN+ Company (and Application if applicable) registry and to Content Owners.
Can I start to complete my profile and TPN questionnaire before I pay the membership fee?
Yes, we have designed the TPN process to remove as many bottlenecks as possible. For this reason, you are able to create a TPN+ account, complete your profile and complete a TPN Best Practices questionnaire for your sites and/or owned applications ahead of signing the TPN membership agreement paying the annual fee. Please note that you cannot use the TPN Blue Shield, and your information will not be visible in TPN+, until you have comleted the TPN Best Practices questionnaire and paid the annual membership fee.
How many questions are in the TPN Best Practices assessment questionnaire?
Although the actual number can slightly change as we regularly update the MPA Best Practices to stay current with industry changes, in the current version 5.3 there are 16 Scoping Baseline questions that are used to define the questions in your TPN site or application assessment. The maximum number of starting questions is 82. The TPN+ platform applies logic based on your answers, that may or may not ask you a subsequent question depending on how you answered the initial question. The total maximum number of questions is 167.
Who can see my TPN Best Practice Questionnaire answers?
Your answers are only visible to: participating Content Owners; your selected accredited assessor, if you choose to obtain a TPN assessment.
I’ve created my TPN+ account. What’s next?
After you have created your TPN+ account, you can set up your profile by adding services, sites and owned and/or licensed applications. You can also add non-TPN security certificates and use the Document section to share any legacy TPN assessments or other information you would like the content owners to be aware of. Once complete, you can start to answer the TPN baseline and Best Practice questionnaire. Once complete and submitted, you may schedule your 3rd party TPN assessment. You can also reference the process map on the Membership page of the ttpn.org website for a full workflow overview.
Does TPN+ apply a watermark to any documents downloaded from my TPN+ profile?
TPN+ applies a watermark to any TPN Gold assessment report created on the platform. Any other document uploaded to TPN+ will not be watermarked. (Please note that all legacy TPN assessments are watermarked if downloaded from the TPN Box repository.)
Does my annual TPN membership include the 3rd party assessment cost?
No, TPN membership does not include the third-party assessment cost. This cost is wholly controlled by the 3rd party assessors. We do recommend that you request at least 3 bids from different TPN assessors to ensure competitive pricing.
How do I achieve the TPN Blue Shield?
Once you have completed the self-reported TPN Best Practices questionnaire for a site or application and clicked the submit button, you have earned the TPN Blue Shield. An image of the TPN Blue Shield can be downloaded and used as outlined in the Membership Agreement once you have paid the annual TPN membership fee.
How long can I use the TPN Blue Shield?
If you wish to maintain Blue Shield status and the right to use the TPN Blue Shield, TPN requires that the self-reported TPN Best Practices questionnaire is updated on an annual basis. (Please note that your TPN+ shield status is automatically updated upon expiration, and the TPN Blue Shield will no longer be displayed on your profile.)
How do I achieve the TPN Gold Shield?
Once the selected TPN-accredited assessor has completed your assessment, TPN has reviewed and published the final report, and you have entered your remediation plans (if applicable), you will have earned the TPN Gold Shield and it will be available for you to download in your TPN+ profile.
How long can I use the TPN Gold Shield?
If you wish to maintain Gold Status and the right to use the TPN Gold Shield, you must receive a TPN security assessment at least once every two years. (Please note that your TPN+ shield status is automatically updated upon expiration, and the TPN+ Gold Shield will no longer be displayed on your profile.)
I have multiple sites. How can I avoid filling out a TPN questionnaire for every site?
For those Companies with more than 5 sites or apps with the same security implementation, TPN offers a "Global Pass" process. Please contact us for details at support@ttpn.org.
If I have multiple facilities or locations how do I get assessment(s)?
You must list the service and the associated sites and applications in your TPN+ profile, and complete the TPN Best Practices Questionnaire for the site and/or application before you can schedule an assessment in respect of it. Contact us about a "Global Pass" if you have more than 5 sites or apps with the same security implementation at support@ttpn.org. When you select your TPN assessor to assign the assessment request, you may also multi-select sites and apps. Note that each site and/or application will require the assessor to complete a separate assessment.
How long does a 3rd party TPN assessment take?
TPN Assessments are (generally) to be completed within 15 business days of their start date (eg: the date the Assessor accepted the assessment). This timeline includes the pre-assessment phase when the Assessor and Service Provider are reviewing the TPN questionnaire responses and reviewing evidence, and the assessment phase when the Assessor is updating status and findings in the TPN+ platform.
What happens if an assessment takes longer than 15 business days?
Please contact TPN to request an extension or explain the delay. TPN will consider each situation on a case-by-case basis. The TPN Assessor scoring considers the timeliness of the assessment, so all exceptions must be well understood and documented.
How do I know if my TPN Questionnaire answers are meeting the MPA Best Practices? Do I need to pay for an assessment to know my security status?
The TPN+ platform logic will capture your self-reported answers and indicate by color whether you are fully compliant with the MPA Best Practice. This information is available to you as self-report so you are aware of your status before incurring cost for a 3rd party assessment. Remediation is not required at the TPN Blue Shield level.
What happens if I don’t want to share all evidence on the TPN+ platform due to confidentiality concerns?
Due to confidentiality, evidence uploaded to TPN+ is only visible to your assigned TPN accredited 3rd party assessor. If you prefer that Content Owners can also see your uploaded evidence, you must select "Visible to CO" for each piece of evidence.
How do I prepare for an assessment?
We recommend that you download a copy of the most current MPA Best Practices found on the TPN website under the "Links & Resources" and our home page to determine your current compliance and gaps in advance of completing the TPN Best Practices questionnaire upon which the 3rd party assessment will be based.
Can I “fail” a TPN assessment?
TPN assessments do not provide “pass/fail” grades, certifications, or ratings. TPN assessments provide Content Owners with information about a site or application's conformance with the MPA Content Security Best Practices at the time of the assessment. Aspects of security not fully in conformance with with the Best Practices will be listed as a remediation item. Content Owners use this information to make their own independent risk-based decisions.
What happens if, in a TPN Assessment, aspects of my security are found to fall short of the MPA Best Practices?
After the TPN assessment is complete and published, those items that are not fully compliant with MPA Best Practices are listed as remediation items (both Best Practices and Additional Recommendations) in the assessment report. In order to obtain their Gold Shield, the Service Provider is required to submit a remediation plan that includes a description of whether the non-conforming controls have already been remediated; whether they will be remediated; and the planned date of remediation (if applicable). All TPN Content Owner members will have the ability to view the remediation items and Service Provider remediation plans, and TPN Gold Content Owner members are able to indicate that the remediation item is a priority, if needed.
How long do I have to handle any remediation items?
To be awarded the Gold Shield, the Service Providers must provide an update for each remediation item. If you are unable to provide full remediation, you can select "will remediate later" and provide comments and an ETA. You are encouraged to update remediation items within 3 business days of assessment completion.
Who gets to see my TPN Assessment Report?
Content Owners are able to view your site or application final assessment report via the TPN+ platform, and can also download a watermarked copy.
How can I share a Blue or Gold report with another Service Provider?
The Super Service Provider function allows you to securely share your TPN security Blue and Gold reports via the TPN+ platform with other trusted Service Provider TPN members. As an admin user of a paid Service Provider member, you can share your reports by clicking “Share New Report” in the Shared Reports section on the left panel of your profile.
Who pays for the TPN assessment?
In most cases Service Providers are responsible for Assessment fees.