Nutanix Security Standards

Nutanix implements the safeguards and security standards set forth in these Nutanix Security Standards (“Security Standards”) to maintain an enterprise risk management and information security program for the protection of Customer Data in connection with the provision of the Products and secure development of the Nutanix Software and Cloud Services. These Security Standards are incorporated by reference into the terms of the Nutanix License and Services Agreement or other agreement between the Customer and Nutanix pursuant to which Nutanix provides Products to Customer (“Agreement”). Capitalized terms not defined herein shall have the meanings given to them in the Agreement or its constituent parts, including (as applicable) the Nutanix Customer Data Processing Addendum (“DPA”). In the event of a conflict between the terms of these Security Standards and the terms in the Agreement, the terms of these Security Standards shall control Nutanix’s security obligations. Nutanix reserves the right to update these Security Standards to reflect changes in technical, regulatory, or industry standards, provided such changes do not materially diminish the level of security specified herein. Publication of revised Security Standards on Nutanix’s website shall be deemed notice of changes.

1.   DEFINITIONS FOR THESE SECURITY STANDARDS

    1.1   Industry Security Standards means a set of standards outlined in published materials for the purpose of protecting the digital infrastructure of an organization, which are reasonably designed and consistent with generally accepted global information security and cybersecurity industry standards such as those issued by a standards body or regulatory authority such as the National Institute of Standards and Technology (“NIST”) or the International Organization for Standardization (“ISO”).

    1.2   Customer Data means information and data that Customer (or a third party on its behalf) uploads, submits, transmits, or otherwise provides access to Nutanix as part of the Services which is processed by Nutanix or its authorized Sub-processor(s) on Customer’s behalf through Customer’s use of the Services.

    1.3   Nutanix System means the information assets and networks hosted by Nutanix or its authorized Sub-processors that are used to process, store or transmit Customer Data to provide the Services.

    1.4   Nutanix Trust Center means Nutanix’s online trust, security, privacy, and compliance portal made available at Nutanix’s public trust website at https://www.nutanix.com/trust or a successor site designated by Nutanix, through which Nutanix may provide information regarding applicable certifications, attestations, audit reports, security documentation, and related compliance resources for relevant Products and Services.

    1.5   Personnel mean Nutanix’s authorized employees, Sub-processors, and subcontractors that are directly engaged in the provision of Services to customers.

    1.6   Security Incident means a breach of security of a Nutanix System that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. Security Incident shall not include unsuccessful attempts or activities that do not compromise the security of Customer Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks and other network attacks on firewalls or networked systems.

    1.7   Services means, as applicable, Nutanix Cloud Services, Support Services, and/or Professional Services.

    1.8;   Penetration Testing means a test methodology in accordance with Industry Security Standards in which security assessors working under specific constraints attempt to circumvent or defeat the security features protecting Confidential Information, Customer Data, and/or a Nutanix System.

2.   ENTERPRISE RISK AND INFORMATION SECURITY PROGRAM

    2.1   Security Program. Nutanix will maintain a written information security program of policies, procedures, and controls aligned to a current industry-standard framework such as ISO 27001 or a substantially equivalent standard, which governs the processing, storage, transmission, and security of Customer Data (the “Security Program”). The Security Program shall be reasonably designed, taking into account the nature of the Services, the sensitivity of the Customer Data processed, and the likelihood and severity of reasonably foreseeable risks, to: (i) protect against reasonably anticipated threats to the confidentiality, integrity, availability, and resilience of the Services, Customer Data, and Nutanix Systems; (ii) protect against unauthorized or unlawful access, acquisition, use, disclosure, alteration, destruction, or loss of Customer Data; (iii) comply with Nutanix’s obligations under applicable data privacy and security laws; and (iv) remain aligned with Industry Security Standards applicable to the Services provided.

    2.2   Security Program Governance. Nutanix shall designate qualified executive management to oversee and maintain the Security Program and Nutanix’s compliance with these Security Standards.

    2.3   Security Program Assessments and Remediation. Nutanix performs periodic internal control assessments using a risk-based methodology to evaluate the design and operating effectiveness of relevant security controls supporting the Services. Material issues identified through such assessments, audits, testing activities, or Security Incidents are documented, risk-rated, tracked, and remediated in accordance with Nutanix’s documented processes and applicable risk priorities.

    2.4   Security Policies. Nutanix implements and maintains commercially reasonable cybersecurity policies, procedures and controls for managing the Services, Nutanix Systems, and Customer Data, which address change, configuration and release management, capacity management, technical vulnerability and patch management, and network management as well as preventative monitoring and detection controls aligned with Industry Security Standards. Nutanix reviews its security policies, procedures, and controls no less than annually, as well as in the event of a Security Incident.

3.   PHYSICAL, TECHNICAL, AND ORGANIZATIONAL MEASURES

    3.1   Physical Security Measures.

    (a)   Secure Buildings and Premises. The physical facilities where Nutanix Systems are used to provide the Services will be physically secure and will permit the management and monitoring of individuals entering and exiting any such facilities. Access to such facilities will be limited to authorized individuals. The maintenance of secure facilities will include, at a minimum, (i) the availability of onsite security personnel on a 24 x 7 basis and alarms or equivalent monitoring measures designed to prevent unauthorized access or forced entry at locations supporting the delivery of the Services, and (ii) fire detection and suppression systems.

    (b)   Physical Security of Media. Nutanix maintains physical controls to protect Nutanix Systems from environmental hazards and unauthorized access, view, copy, alteration, removal or destruction. Nutanix will use an industry standard (such as NIST 800-88 or a substantially similar equivalent) for the deletion of Customer Data on any media before final disposition of such media.

    3.2   Technical Security Measures.

    (a)   Security-related Events Log. Nutanix logs and monitors security-related events on all levels for production systems (including operating system, database and application) as required by these Security Standards and applicable legal and regulatory obligations.

    (b)   Access Controls. Nutanix maintains controls to limit access to Customer Data in Nutanix Systems to Nutanix Personnel who have a legitimate need for such access and whose access is commensurate with their job responsibilities. Nutanix’s access controls are based on the security principles of “segregation of duties” and “least privilege” and any new user accounts require appropriate Nutanix approval. The access rights of Nutanix’s Personnel and authorized external parties to Nutanix Systems are adjusted upon any change in role or upon termination, whether voluntary or involuntary.

    (c)   Remote Access Controls. Nutanix maintains remote access controls to monitor and manage access to Nutanix Systems, including requiring multifactor authentication for Nutanix Personnel accessing Nutanix Systems from an external system or network, in addition to other relevant protections in line with Nutanix’s policies and procedures.

    (d)   Password Requirements. Nutanix maintains password and authentication controls consistent with Industry Security Standards to establish, manage, and enforce password and authentication requirements (including password complexity and expiration, two-factor authentication, lockout after multiple attempts, and API keys) for all Nutanix Systems. Consistent with Industry Security Standards and to the extent natively supported by Nutanix Systems, Nutanix maintains technical measures that enforce timeout of inactive sessions, lockout of accounts after multiple sequential failed login attempts, strong password or passphrase authentications, and measures requiring secure transfer and storage of such passwords and passphrases.

    (e)   Firewalls. Nutanix uses firewall technology to protect Nutanix Systems used to provide the Services and restrict inbound, outbound, and internal network traffic to only necessary hosts and network resources.

    (f)   Network Security. Nutanix maintains reasonable security controls over its communication networks and standard configurations, including: (i) applying the principles of least privileged and security hardening; (ii) maintaining documentation of network architecture; (iii) measures designed to prevent unauthorized connections to Nutanix Systems, applications, and network devices; and (iv) secure segmentation, isolation, and defense in-depth standards.

    (g)   Segregation. Nutanix logically segregates the Customer Data from the data and accounts of other Nutanix customers, such that information is not accessible by any other customers or unauthorized third parties.

    (h)   Vulnerability Management. Vulnerability scans are performed on Nutanix Systems to determine potential vulnerabilities in accordance with Nutanix’s then-current security operating procedure, including testing for identified weaknesses and common vulnerabilities in relevant Products. When software vulnerabilities become known and the applicable software vendor provides a patch, the patch will be applied within an appropriate risk-based timeframe in accordance with the then-current vulnerability management and security patch management standard operating procedure (and only after such patch has been tested and deemed safe for application in production systems).

    (i)   Antivirus, Malware Protection. Nutanix implements preventative monitoring and other measures to protect against viruses, malware, ransomware, spyware, and other types of malicious code and applies up-to-date security patches to the Nutanix Systems as necessary to deliver the applicable Products. Nutanix regularly updates antivirus software, conducts periodic virus scans (including real-time scanning) and protects the Nutanix Systems used to provide Services to the Customer through properly configured firewalls and security devices designed to prevent unauthorized network access.

    (j)   Encryption. Nutanix uses industry standard encryption to encrypt Customer Data, including Pulse telemetry data, in transit over public networks (using at least TLS 1.2) and stored as part of the relevant Cloud Services (using at least AES-256), in accordance with Nutanix’s data classification policies and procedures. Nutanix manages and stores all cryptographic keys in a secure manner.

    (k)   Change Control. Nutanix maintains change control policies and procedures to ensure that changes to the Services and Nutanix Systems are documented, tested, and approved prior to implementation.

    3.3   Operational Measures.

    (a)   Personnel Security. Nutanix shall ensure all Nutanix authorized Personnel who have access or process Customer Data have: (i) undergone and passed background checks in accordance with applicable standard procedures, subject to applicable law; (ii) completed as necessary for the provision of the Services, appropriate security training at onboarding and at least on an annual basis; and (iii) completed role-based training, as and when appropriate based on the roles and responsibilities of the relevant Personnel.

    (b)   Third Party Risk Management. Nutanix’s written information security program will include policies, procedures, and controls addressing third party risk management and governance for any third parties used to provide the Services in accordance with Industry Security Standards. Where Nutanix has outsourced infrastructure for Nutanix Systems used to provide the Services to a third party, including any Nutanix Sub-processor, Nutanix will review and evaluate the applicable third party’s infrastructure and data center for security and compliance at least annually. Nutanix will obligate such third parties who access, store, process, or transmit Customer Data to maintain data protection measures substantially similar to those in these Security Standards.

    (c)   Inventory and Asset Management. Nutanix maintains an inventory of assets used to provide the Cloud Services, including, without limitation, software components and open-source software, which is reviewed at regular intervals to ensure all critical assets are managed and accounted for. All assets are assigned an owner and are classified according to the data they process and store. Nutanix maintains policies to ensure the proper use and timely return of Nutanix assets in accordance with Industry Security Standards.

    (d)   Personnel Workstation Security. Nutanix maintains administrative, technical, and physical safeguards to protect Customer Data accessed or processed on Personnel workstations and other endpoints used in connection with the Services, including, at a minimum: (i) unique user authentication and strong password or passphrase requirements; (ii) endpoint protection controls reasonably designed to detect and prevent malicious activity; (iii) regular security updates and patching; (iv) automatic session locking after a defined period of inactivity and policies requiring screen locks when devices are unattended; (v) remote access to Nutanix Systems over secure, encrypted channels with multifactor authentication where required by Nutanix policy; (vi) controls requiring reasonable physical security of devices; and (vii) baseline endpoint security measures, as applicable, such as host firewalls, anti-malware protections, and full-disk encryption.

4.   ASSESSMENTS, CERTIFICATIONS, AND AUDITS

    4.1   Ongoing Security Standards. Nutanix will: (i) periodically conduct a security risk assessment to determine whether Nutanix’s enterprise risk management and information Security program meets these Security Standards and reasonably accounts for technological developments and evolving threats; (ii) ensure that security risks are identified, assessed, and addressed; and (iii) that appropriate security controls are applied based on the risk assessed from time to time.

    4.2   Certifications and Attestations. For relevant Cloud Services, Nutanix will engage independent third-party auditors to validate Nutanix’s operational controls, to periodically test the operating effectiveness of the Security Standards, and to provide a certification, attestation, or report of their findings. Nutanix will take appropriate steps to address material issues identified by such auditors. Third-party certifications or attestations for specific Cloud Services, which vary depending on the type of services in scope, are available in the Nutanix Trust Center. The Nutanix corporate network environment is certified under ISO 27001 or an equivalent internationally recognized information security standard. Third‑party certifications or attestations shall satisfy audit obligations except where required by applicable law.

    4.3   Customer Information Security Reports and Audits. Nutanix will allow for, and contribute to inspections, to permit a customer access to reasonable and industry-recognized documentation evidencing the controls for Cloud Services that process Customer Data, including related information and documentation where required by applicable law or a competent supervisory or regulatory authority. Customers may self-access certain documentation, including certifications and attestations, via the Nutanix Trust Center at no additional cost. To the extent the Customer cannot reasonably satisfy any audit requirements with the foregoing information, Nutanix will provide Customer with further information or assistance as may be required, in particular to fulfill any request from a competent supervisory or regulatory authority. Any audit must be scheduled in advance, use reasonable measures to prevent disruption to Nutanix’s business operations, and the parties will mutually agree on the nature and scope of the audit. Any information provided by or obtained by the Customer in connection with an audit, including, without limitation, any third-party audit report, shall be treated as Nutanix Confidential Information. Customer’s audit rights hereunder do not confer any right to obtain or share legally privileged, sensitive information, or information subject to third party confidentiality obligations.

    4.4   Customer Due Diligence and Security Questionnaires. Upon Customer’s reasonable request, and no more than once annually (except if required by a competent supervisory authority or in the event of a Security Incident), Nutanix will provide responses to Customer’s reasonable security questionnaires as part of the Customer’s due diligence and third-party risk process to the extent necessary for Customer to validate Nutanix’s compliance with these Security Standards. All information provided by Nutanix in response to such requests will constitute Nutanix’s confidential information and will be subject to the confidentiality provisions in the Agreement and/or applicable law.

5.   SECURITY MONITORING AND INCIDENT MANAGEMENT

    5.1   Incident Monitoring, Detection, and Management. Nutanix implements preventative monitoring and detection controls in line with Industry Security Standards. Nutanix logs and monitors events in Nutanix Systems in accordance with Nutanix’s applicable policies and procedures and maintains a documented process to (i) detect and analyze anomalous events affecting Customer Data in such Nutanix Systems, and (ii) report and escalate event alerts that may indicate a potential Security Incident. These processes are reviewed by Nutanix no less than on an annual basis.

    5.2   Security Risks Communication. Nutanix will respond to reasonable queries by Customers that are triggered by an industry or government agency announcement related to a recently discovered security or vulnerability or similar threat which has the potential to have a broad, industry-wide impact on technology products similar to those that Nutanix licenses to its customers.

    5.3   Incident Response Plan. Nutanix maintains a written incident response plan designed to detect, investigate, contain, respond to, and recover from Security Incidents. Nutanix also maintains procedures for Security Incident identification, classification, prioritization, internal escalation, evidence preservation, remediation, and post-incident review. These processes are reviewed and tested by Nutanix at least annually.

    5.4   Breach Notification. Nutanix will notify Customer in writing of a Security Incident without undue delay, unless prohibited by applicable law or otherwise instructed by law enforcement or a supervisory authority. Such notice shall include, to the extent then known and reasonably available, information reasonably required by Customer to satisfy its legal obligations, including a description of the nature of the Security Incident, the categories of impacted Customer Data, the measures taken or proposed to address the Security Incident, and any recommended steps for Customer to take to mitigate potential adverse effects. To the extent such information is not known at the time of the initial notice, Nutanix shall provide additional information in phases or through periodic updates as it becomes reasonably available.

    5.5   Breach Response. Nutanix shall investigate, perform a root cause analysis and, where necessary and feasible, implement reasonable measures to mitigate the effects of the Security Incident and prevent a recurrence. Customer is solely responsible for determining whether to notify relevant supervisory authorities and affected individuals in relation to any Security Incident. Any obligation to notify under this Section 5 shall not be construed as an acknowledgment by Nutanix of fault, responsibility or liability, including for any use or disclosure of Customer Data or for any related Security Incident.

 

6.   BUSINESS CONTINUITY

    6.1   Business Continuity Procedures. Nutanix maintains business continuity and disaster recovery plans and procedures reasonably designed to support the ongoing availability and resilience of relevant Cloud Services and the timely restoration of such Cloud Services and related Customer Data following a system failure, natural disaster, cyber event, or other material disruption. Such plans and procedures are reviewed, tested, and updated at least annually. Where applicable, Nutanix’s testing includes evaluation of backup and restoration procedures and other recovery capabilities relevant to the supported Cloud Services. In the event of a material disruption affecting applicable Cloud Services, Nutanix will provide status updates regarding recovery efforts in accordance with the Agreement and Nutanix’s incident management procedures.

7.   DATA DELETION

    7.1   Upon Customer’s written request or once Customer Data is no longer required for Nutanix to fulfill its obligations under the Agreement, Nutanix will securely delete and/or destroy Customer Data on Nutanix Systems, in accordance with applicable NIST data destruction standards, unless prohibited by applicable law.  Nutanix shall not be liable for any impact caused by or relating to Customer Data which has been deleted pursuant to Customer’s request prior to the termination of the Agreement.

8.   SOFTWARE SECURITY AND QUALITY ASSURANCE

    8.1   Secure Software Development. Nutanix implements commercially reasonable policies and procedures to support and manage a secure development lifecycle for applicable Software and Cloud Services, including security-by-design practices, security checkpoints within change management, and segregation of development, testing, and production environments. Nutanix’s practices include, as appropriate to the relevant Product or Service, security architecture reviews, threat modeling, secure code review, and scans of open-source and other third-party software components.

    8.2   Quality Assurance. Nutanix maintains a quality assurance program and validates that any Software licensed in connection with the applicable Products has undergone secure development protocols and quality control testing to identify and correct potential cybersecurity weaknesses and vulnerabilities.

    8.3   Penetration Testing. Nutanix’s secure development lifecycle for its Software and Cloud Services includes Penetration Testing using industry standard tools and methodologies to prevent the introduction of known and exploitable vulnerabilities such as those defined under the OWASP Top 10. Nutanix will periodically perform relevant Penetration Testing in accordance with Industry Security Standards and, upon Customer’s written request, will provide executive summary reports subject to applicable confidentiality obligations.

    8.4   Patching and Vulnerability Remediation. Nutanix maintains measures designed to assess, test, and apply security patches to its Nutanix Systems and utilizes hardened operating systems customized for Nutanix Cloud Services.  When Nutanix determines that a security patch or vulnerability remediation is applicable and appropriate for Software or Cloud Services, Nutanix implements the patch or remediation, as applicable, in accordance with its documented patch-management policy, including established severity and risk-assessment guidelines.  Vulnerabilities are assessed using a Common Vulnerability Scoring System (CVSS) and the corresponding criticality level is assigned and prioritized accordingly. 

9.   SHARED SECURITY RESPONSIBILITIES

    9.1   Shared Security Model. The security of the Services is a shared responsibility between Nutanix and Customer. While Nutanix is responsible for securing the underlying infrastructure and maintaining the security of the Nutanix Systems used to provide the Services, Customer is responsible for its secure use of the Services and the configuration of Customer-controlled security settings within the Products.

    9.2   Customer Security Obligations.  Customer acknowledges that there are certain features and configuration settings within the Products (including but not limited to access controls, authentication mechanisms, and network security policies) which may impact the security of the Customer Data processed by Customer’s use of the Products.  Customer is responsible for: (i) reviewing the Documentation to determine whether the Services meet Customer’s specific security and compliance requirements; (ii) properly configuring, implementing, and maintaining technical and organizational security measures including through the use of features and configuration settings made available by Nutanix, designed to protect Customer Data from a Security Incident and to preserve the security and confidentiality of Customer Data while under Customer’s dominion and control; (iii) securing its account authentication credentials, including enforcing strong password policies and multi-factor authentication where applicable; (iv) protecting the security of Customer Data when in transit to and from the Services and taking appropriate steps to securely encrypt or back up any Customer Data processed in connection with the Services. Nutanix shall not be responsible or liable for any Security Incident, data loss, or unauthorized access to Customer Data that arises from or relates to Customer’s failure to properly configure the Services or implement appropriate security controls within Customer's environment.