Do you have a security questionnaire for all third parties you partner with? How long is it?

1.8k views1 Upvote4 Comments
Sort By:
Director in Manufacturing2 years ago
Our CISO has about a two page security document that our vendors need to complete as part of our RFP process. Procurement actually deliverers it as part of the requirements to bid.
CISO in Governmenta year ago
We do have a set of questions we call the External Dependency Matrix, derived from CIS Critical Security Controls. I recommend starting with that. Depending on the solution, sensitivity of data, and what level of compliances you are required to follow, you can demand different levels of control (1, 2, or 3). 
Executive Director of Technology in Healthcare and Biotecha year ago
Yes, we have a pretty comprehensive security questionnaire that covers just about every topic that vendors must fill out before purchasing can be considered. It basically covers everything and is pretty time intensive. We do not have levels of control built into the document, but I think that is a great idea for the future. 
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Information Security Director in Mediaa year ago
We have a security questionnaire for 3rd party vendors, but depending how they interact with our infrastructure, access to certain types of data (PII, Confidential etc.) or if their processes/systems have been audit from a ISO or SOC2 perspective the quantity of questions differ as questions would be added/excluded accordingly.

Content you might like

Strongly agree4%




Strongly disagree1%

View Results
3.8k views2 Upvotes3 Comments
Director of IT in Education2 months ago
We do a combination of both.
931 views1 Comment
CTO3 months ago
E-scraping and obtain green certificate
582 views1 Comment

Very important. I want to work with an innovative partner.39%

Nice to have, but not a deal-breaker.57%

Innovation is not something I'm looking for in a partner.3%

View Results
2.7k views1 Upvote