Security Schedule

(v20231221)

This Security Schedule (“Security Schedule”) shall be incorporated under Agreement by and between SodaStream International Ltd. (“SodaStream”), an Israeli corporation, having a principal place of business at 1 Atir Yeda St., Kfar Saba Israel and <insert Supplier Name> (“Supplier”). Capitalized terms not specifically defined herein shall have the meaning set forth in the Agreement.

1. Purpose of the Security Schedule and Order of Precedence

1.1 Purpose. This Security Schedule establishes the minimum security standards to be met by Supplier in the Processing of Data, provisioning of Services or Products, and accessing SodaStream Information Systems.

1.2 Order of Precedence. In the event any term or condition in this Security Schedule conflicts with a term or condition of any agreement with Supplier, including the Agreement, then the term or condition of this Security Schedule shall take precedence and control as long as the conflicting term or condition does not grant a higher level of security.

2. Definitions

2.1 Authorized Supplier Employees means Supplier’s employees who are approved by SodaStream to authenticate and access SodaStream information systems or network connectivity.

2.2 “Data” means Personal Data and all Confidential Information Processed by Supplier in connection with the Services, whether in tangible or intangible form, whether or not marked or designated as “confidential”.

2.3 “Industry Standards” means the highest, then-current industry standard(s) as appropriate, given the associated activity, risk and/or requirement, and in any event no less than a reasonable level of protection.

2.4 “Information Systems” means any system and its associated authentication methodology, including but not limited to net-services, networks, computers, personal computing devices, mobile devices, removable media, communication systems, applications, websites, and collaboration tools such as SharePoint sites. 

2.5 “Personal Data” means any information relating to an identified or identifiable natural person or as otherwise defined by applicable Privacy Law. 

2.6 “Process” “Processing” or “Processed” means any operation or set of operations performed on or with Data, whether or not by automatic means (including, without limitation, accessing, collecting, recording, organizing, retaining, storing, adapting or altering, retrieving, consulting, using, disclosing, making available, aligning, combining, blocking, erasing and destroying Data) and any equivalent definitions in Applicable Laws exceeding this definition. 

2.7 “Product” or “Products” means any tangible deliverable to be provided by Supplier pursuant to the Agreement.

2.8 “Security Incident”  means any suspected or actual breach of security (including physical intrusion of facilities) that has resulted or is reasonably likely to result in the accidental, unlawful or unauthorized acquisition, destruction, loss, exfiltration, alteration, modification, encryption, unauthorized disclosure of, or access to or use of (a) Data transmitted, stored or otherwise Processed, (b) Information Systems, (c) Product or (d) Service. 

2.9 “Service” or “Services” means the services to be provided by Supplier pursuant to this Agreement.  

3. Supplier Requirements

3.1 Information Security Management System (ISMS). Supplier must maintain an Information Security Management System (ISMS) with supporting policies consistent with applicable security related Industry Standards (by way of example ISO27001, NIST 800-53, and PCI). The Supplier’s ISMS must protect the confidentiality, integrity, and availability of all Data, Services and Products, and comply with all Applicable Laws relevant to the Processing and use of Data and provisioning of Services or Products.

At a minimum, Supplier’s ISMS must cover:  

      1. Access Control. Supplier will establish and implement controls and safeguards to protect systems used to manage, process or store Data against unauthorized access, disclosure, modification, destruction, interference or downtime in a manner consistent with Industry Standards.

Supplier should have at least the following but not limited to:

- Multi-factor authentication
- Encryption at rest and in motion
- SSO using SAML2 or OAuth2 or higher

        2. Security Operations. Supplier will have a documented patch management plan or patching process and should supply it to SodaStream upon request. The Supplier shall notify SodaStream if there is increased risk to the application.

        3. Secure Development/Code Review. Supplier shall follow secure development lifecycle for the applications and systems. Supplier should conduct, or alternatively, have an independent security organization conduct, an application security code review and supply the report and the remediation plan to SodaStream upon request

        4. Security Testing. Supplier will conduct vulnerability scanning and penetration testing to all applications  and devices handling Data at least on a yearly basis. Supplier will remediate all critical and high level risks identified by such scans and make such scan reports and evidence of remediation available to Sodastream for review upon request.

        5. Network Security. Supplier will maintain the security of Supplier Information Systems in compliance with practices that are consistent with Industry Standards. The security should include at least but not limited to :

  • Anti Virus/Anti malware systems
  • The network should be protected by a firewall
  • Physically and logically segmenting Data on infrastructure from non-SodaStream data;
  • boundary network components having IDS/IPS and automated notification elements enabled and being routinely monitored for configuration/rule changes.
  • Prevent download or copy data to removable devices
  • Establish controlled access to source code to prevent unauthorized access.

        6. Remote Access. If Supplier is utilizing a remote network connect, a connectivity method into SodaStream  Information Systems, or is located within a SodaStream network, Supplier must use a SodaStream-approved information technology standard remote access solution. Duration of access shall be restricted to periods where access is necessary for provision of Services. Supplier shall ensure all Authorized Supplier Employee access is terminated immediately when such Authorized Supplier Employee no longer requires access to SodaStream information systems or network connectivity. 

        7. Product Network Connectivity. If Supplier is providing to SodaStream a Product with connectivity to SodaStream network or information system, Supplier shall implement connectivity only according to the Machine Network Connectivity procedures required by SodaStream before delivery of the Products. Such requirements are subject to acceptance tests by SodaStream. Any other network connectivity of such Product is not permitted. 

3.2 Secure Data Destruction and Return. Supplier shall retain Data only for the period necessary to provide the Services or Products. Upon termination of the Agreement, Supplier shall return to SodaStream all Data, and delete it (including from its archives), unless otherwise requested from SodaStream in writing. If deleted, Supplier must provide a certificate of destruction of the Data in accordance with industry standard methodology for secure deletion, such as NIST 800-88. If SodaStream provided written consent to retain data post termination, Supplier shall retain Data in compliance with Supplier’s data retention policy subject to confidentiality obligations and the applicable law requirements.

3.3 Supplier Relationships. Supplier shall contractually flow down the material obligations of the Security Schedule to each subcontractor utilized in the provisioning of Services or Products. Supplier shall be responsible for the acts and omissions of its subcontractors and must regularly monitor, review, and audit subcontractor security controls.

3.4 Notifications. All notifications related to a Security Incident, Security Schedule noncompliance shall be made to SodaStream via SodastreamSECIT@sodastream.com. Supplier shall notify SodaStream without undue delay (and, in any event, within 24 hours) after Supplier becomes aware of, or reasonably suspects there has been, a Security Incident. Supplier will also notify SodaStream in the event that identified critical and high vulnerabilities cannot be repaired prior to commencement of Services or within 30 days from discovery. The notification shall include sufficient information to allow SodaStream to meet its obligations under applicable Privacy Laws to inform Data Subjects and/or Supervisory Authority(ies) of the Security Incident and take all necessary measures and steps to identify the cause of such Security Incident, mitigate its effects, and prevent further incidents. In respect of any relevant Security Incident, to the extent such information is known, or in phases as it becomes known, Supplier shall provide SodaStream with true, complete and accurate details of: (i) the nature of the Security Incident, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned; (ii) the name and contact details of the data protection officer or other relevant contact from whom SodaStream may obtain more information relating to that Security Incident; (iii) the likely or reasonably anticipated consequences of the Security Incident; and (iv) the measures taken or proposed to be taken to address the Security Incident.

3.5 Timely Response to Vulnerabilities. Supplier will remediate, within industry best practice timelines, security vulnerabilities that may impact Data. 

3.6 Tnformation Security Assessments (ISAs). Upon SodaStream’s request, on an annual basis, Supplier shall provide copies of applicable independent security assessments and certifications (such as PCI DSS, SOC 1, SOC 2, ISO 27001), and summaries of vulnerability scans and penetration tests. Summary reports must include an overview with the scope of what was tested, tools and methodologies used, identified vulnerabilities and remediation efforts. Code snippets or other sensitive infrastructure information may be redacted from summary reports. SodaStream or a third party chosen by SodaStream may no more frequently than annually, other than in the event of a Security Incident, conduct a noninvasive ISA of the Supplier’s ISMS. The noninvasive ISA may include one or more of the following: questionnaire, requests for supporting documentation to illustrate an ISMS comprised of applicable Industry Standards, and clarifying discussions.  

3.6.1 Supplier shall promptly cooperate with SodaStream to complete an ISA. 

3.6.2 An onsite ISA, if necessary, will occur at a mutually agreed time upon ten calendar days’ advanced written notice and, in the event of a Security Incident, upon three calendar days’ prior written notice. SodaStream will be responsible for its own travel costs. 

3.6.3 The results of the ISA shall be treated as Confidential Information.

3.6.4 Supplier will resolve issues identified in the ISA within a reasonably agreed-upon timeframe. 

4 . Special Considerations

Supplier should undertake the following supplementary actions on top of the previous actions:

4.1 Human Resource Security 

  • Supplier should establish a process to prevent, report, cease and return any misuse or unauthorized access of Data or Information Systems or Services by Supplier, Supplier personnel or subcontractor.
  • To the extent permitted by the Applicable Law, perform background checks to Supplier personnel in sensitive position having access to the Data
  • Supplier will conduct a yearly Cyber awareness training to personnel with access to Data.

4.2 Incident Management Program. Supplier will maintain and implement a documented information security event management process, which includes incident reporting, response, prioritization, escalation and remediation and will submit a full incident report upon SodaStream request in case of incident related  to the Data.

4.3 Business Continuity and Disaster Recovery. Supplier will document and maintain a “Business Continuity and Disaster Recovery Plan,” according to the industry best practice and complying with the Industry Standards like NIST and perform a yearly DRP (disaster recovery plan) exercise, Supplier should send a full report on the exercise to SodaStream upon request.

4.4 Processing Payment Cards. If Supplier will be Processing Payment Card Data on behalf of SodaStream, Supplier must comply with the current Payment Card Industry Security Standards Council Data Security Standards (PCI SSC DSS) and will provide a Report on Compliance or formal letter of compliance signed by a Qualified Security Assessor and an Attestation of Compliance to SodaStream prior to commencement of Services and annually thereafter. Supplier will immediately notify SodaStream of noncompliance with PCI SSC DSS. (Capitalized terms used in this section shall have the meaning as defined by the PCI SSC DSS. https://www.pcisecuritystandards.org)  

4.5 Call Recording. If Supplier is Processing or performing call recordings, Supplier must perform call recordings notice, collection, and Processing in accordance with Applicable Laws, this Security Schedule and the Agreement. Supplier must not enable any call-recording capabilities unless approved by SodaStream in writing.  Supplier must redact all Personal Data from any call recordings used by Supplier for internal training or quality purposes.

4.6 Manufacturing Security. If Supplier is providing supply chain or manufactured Products, Supplier must:  

4.6.1 Perform security and integrity testing on components and final Products prior to shipment.

4.6.2 Ensure that Products are free from any unauthorized components and use only SodaStream authorized parts. 

4.6.3 Maintain inventory-control processes and documentation, such as Bill of Material (BOM). 

4.6.4 Maintain accurate documentation of damaged or destroyed components, parts and/or Products, and upon SodaStream’s request, provide a certificate of physical destruction for any failed or faulty Product.  

4.6.5 Any Product returned from a Customer must be securely erased or disposed of using industry standard methodology, such as NIST 800-88. Upon SodaStream’s request, Supplier must provide a certificate of secure erasure for any returned Product that has been erased.  

4.7 Logistics Security. If Supplier is providing logistics Services, such as, logistics functions, order fulfillment, packaging, shipping or delivery, on behalf of SodaStream and/or SodaStream customers, Supplier must: 

4.7.1 Ensure compliance with the Customs Trade Partnership against Terrorism (C-TPAT) shipping and logistics program.

4.7.2 Ensure the end-to-end logistic service is secured against prohibited access to SodaStream assets.

4.7.3 Ensure that software, hardware, components, and system related documentation for SodaStream Products are not unbundled and are not otherwise tampered with.

4.7.4 Prohibit Processes that compromise Product security and integrity; for example, avoid changing BIOS, using admin passwords, or installing testing software during post-build testing.