|
|
|
|
|
by neilv
1920 days ago
|
|
Three questions about liability and acceptance: 1. How do you handle any liability from having security-sensitive internal docs/info about all your customers? 2. How do you handle any liability from mistakes you make while answering questions? (Of course, both "good" and "bad" incorrect answers can be very bad, for your customer and/or their prospective/customer -- an incorrectly "bad" answer might cost a sale/relationship, and an incorrect "good" one might be relied upon and lead to a compromise incident or regulatory noncompliance.) 3. How many prospective/customers of your customers will accept security questionnaire answers prepared by an outside firm? How many will require the diligence and assurances to come from sufficiently knowledgeable in-house people, with the company standing behind it? |
|
Seriously speaking - you bring up some interesting questions. I used our tool to respond to your questions, because I think it helps illustrate the point (see link below)
https://www.loom.com/share/22ccb2188c3744cd82f17baa31cfb2e9