[LT-06]
The Security Questionnaire Gauntlet
Enterprise procurement for software handling personal data involves a security assessment process that can be as time-consuming as the procurement decision itself. For vendors without recognized security certifications, the typical process is:
The enterprise security team sends a custom questionnaire: 100–200 questions covering access controls, encryption standards, vulnerability management, incident response, business continuity, physical security, and ...