The most backwards practice in cybersecurity is to allow sales to answer secques and not also have them do due diligence on their own vendors for security compliance.
“Point-in-time security questionnaires are a legal requirement, not a preventive control. The number of third-party providers can be staggering, with security teams having to assess hundreds of providers,” he said.https://t.co/6bT8W83e41
We have been really focused on #risk#assessments recently. As required by SOC2 and ISO 27001, it forces you to put to paper the logic of your assessment of risks. The hardest part? writing down the risk.
#infosec vendors please never cold call personal phone numbers - it is a terrible practice. Most #security folks will block the number and may not do business with the vendor. I have posted about this before, but the number of vendor calls have significantly increased.