|
|
|
|
|
by billyhoffman
1920 days ago
|
|
First, thank you so much for this! I hate these things. However answering these questions without nuance and context can at best cause a lot more back and forth between company and vendor, and at worse kill the deal immediately. Example: Bad way, no context: Do you have external certification for HIPPA/PCI compliance: No. Better way: Do you have external certification for HIPPA/PCI compliance: No, because product does not collect, store, or process health data or payment card data. How do you handle cases like this in an automated fashion? |
|
We build a 'profile' of the company - what it does, they systems used, the type of data it handles (and doesn't) to answer these questionnaires.
Part of the purpose of having a human-in-the-loop - especially for the first 1-2 questionnaires, is to support this type of review and ensure that answers are a sufficiently high quality.
As a general rule of thumb when answering security questionnaires (which our system supports), any "negative" answer should have additional clarification. FWIW, I'd say that a more appropriate answer to that question would be N/A instead of No to avoid confusion, assuming that the company doesn't handle any PHI / CHD.