“Vendor security questionnaire” — three innocuous-sounding words that can leave security folks trembling. If you’re in security — no matter what company you’re with — there’s a good chance you know exactly what I’m talking about, either because you’ve experienced firsthand the pain of trying to vet the information security controls of the multitude of third parties that your organization exchanges data with, or because you work for a company in the “channel,” and you’ve gone through the process of being actively vetted by your customers.
Walking a Mile in Their Shoes: Vendor Security Questionnaires
Posted by: Ed Moyle April 21, 2009 04:00 AM“Vendor security questionnaire” — three innocuous-sounding words that can leave security folks trembling. If you’re in security — no matter what company you’re with — there’s a good chance you know exactly what I’m talking about, either because you’ve experienced firsthand the pain of trying to vet the information security controls of the multitude of third parties that your organization exchanges data with, or because you work for a company in the “channel,” and you’ve gone through the process of being actively vetted by your customers.