Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If every customer asked the same questions, such as these, it would be worthwhile compiling the answers once for everybody and keeping them up to date.


Exactly, that set of standard questions and responses (ie controls) is exactly what a VSA is.

However, SOC2 takes it a step further and requires an formalized audit from a AICPA certified security auditing firm[0].

Therefore, a security questionnaire should be for follow-up items that the customer feels were not adequately addressed in one or more of the vendor's compliance attestations.

Otherwise, the customer is asking the vendor to step through redundant check-the-box busywork that actually requires a higher level of skill that can not be adequately completed by a junior engineer. To wax hyperbolic, it's like an engineering DoS attack which serves neither the customer nor the vendor well (unless the goal is to slow down the vendor from making new and better products)

0. https://www.aicpa.org/interestareas/frc/assuranceadvisoryser...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: