TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: How do you respond to security questionnaires?

2 pointsby reiderrideralmost 6 years ago
A software company we are integrating with wants their 100 question security assessment questionnaire completed. Any advice?<p>We are a two engineer team without a SOC audit and without a third party pen test that stores medical and financial data.<p>These questionnaires are time consuming and redundant. It seems insecure to produce something that details our security too. Does a &#x2F;security page with some details suffice? Am I just being lazy?

3 comments

ziddoapalmost 6 years ago
&gt;<i>We are a two engineer team without a SOC audit and without a third party pen test that stores medical and financial data.</i><p>&gt;<i>These questionnaires are time consuming and redundant.</i><p>This is how data breaches happen. You should be willing to jump through a few, usually reasonable, hoops if you&#x27;re storing medical and financial data.<p>Instead of looking for a quick-fix that will &quot;suffice&quot;, you may consider actually securing the sensitive data you hold on other people.<p>Edit: After a little googling, I&#x27;m genuinely concerned about the product you are offering, at a firm of your size, with no compliance. Yikes from me.
评论 #20270718 未加载
mtmailalmost 6 years ago
Charge extra, or rather tell the company they need the enterprise pricing plan, to make it worth the time investment. Companies with those questionaires are used to suppliers pushing back, charging extra or dropping out (either not returning the questionaire or answering insuffiently). It&#x27;s part of dealing with enterprise B2B clients. I had to sign anti-slavery and anti-human-traffiking statements...<p>Some questions you won&#x27;t agree with, e.g. I&#x27;ve been asked how often we change our wifi passwords. Better to be honest and let them assess the risk than overpromising.
评论 #20270693 未加载
mokslyalmost 6 years ago
Is it even legal to hand over medical data to a company without SOC 2 compliance?
评论 #20270659 未加载