Questions tagged [vendor-selection]

19 questions
0
votes
0 answers

What strategies can I use to negotiate security terms in vendor contracts for vendors in high geopolitical risk countries?

Please assume the following in responding: Data being passed to vendor is subject to data protection laws in the USA such as GLBA Data itself resides within the United States Switching vendors will be difficult due to tight integration with…
Anthony
  • 1,736
  • 1
  • 12
  • 22
0
votes
1 answer

How should potential (unverified) security vulnerabilities be best reported?

As an IT auditor, part of my job duties includes vendor risk assessment / conducting security due diligence. Based on documentation obtained from the vendor, (SOC 2 report, SIG survey ) , I and several members of the team, (I am the lead of the…
Anthony
  • 1,736
  • 1
  • 12
  • 22
-1
votes
4 answers

Vendor Security Review. When is it overkill?

Looking for everyone's opinion here. One of my buddies was doing a vendor security review for a company that sells different types of software. The software allows you to create 3D models for home and office design (think HGTV home improvement).…
Nina G
  • 133
  • 6
-2
votes
1 answer

Network product (software and hardware) vendors independent from NSA in 2018

Which vendors of network products like firewalls, routers, switches, VPN softwares and similar are likely to be free from backdoors, already built in surveillance capabilities, secretly broken encryption keys inserted by NSA? Is there an independent…
John
  • 167
  • 4
1
2