TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How do you respond to security questionnaires?

2 点作者 reiderrider将近 6 年前
A software company we are integrating with wants their 100 question security assessment questionnaire completed. Any advice?<p>We are a two engineer team without a SOC audit and without a third party pen test that stores medical and financial data.<p>These questionnaires are time consuming and redundant. It seems insecure to produce something that details our security too. Does a &#x2F;security page with some details suffice? Am I just being lazy?

3 条评论

ziddoap将近 6 年前
&gt;<i>We are a two engineer team without a SOC audit and without a third party pen test that stores medical and financial data.</i><p>&gt;<i>These questionnaires are time consuming and redundant.</i><p>This is how data breaches happen. You should be willing to jump through a few, usually reasonable, hoops if you&#x27;re storing medical and financial data.<p>Instead of looking for a quick-fix that will &quot;suffice&quot;, you may consider actually securing the sensitive data you hold on other people.<p>Edit: After a little googling, I&#x27;m genuinely concerned about the product you are offering, at a firm of your size, with no compliance. Yikes from me.
评论 #20270718 未加载
mtmail将近 6 年前
Charge extra, or rather tell the company they need the enterprise pricing plan, to make it worth the time investment. Companies with those questionaires are used to suppliers pushing back, charging extra or dropping out (either not returning the questionaire or answering insuffiently). It&#x27;s part of dealing with enterprise B2B clients. I had to sign anti-slavery and anti-human-traffiking statements...<p>Some questions you won&#x27;t agree with, e.g. I&#x27;ve been asked how often we change our wifi passwords. Better to be honest and let them assess the risk than overpromising.
评论 #20270693 未加载
moksly将近 6 年前
Is it even legal to hand over medical data to a company without SOC 2 compliance?
评论 #20270659 未加载