Hacker News new | ask | show | jobs
by brendan0powers 1456 days ago
This looks like a form Epic would send to software vendors who have not passed one of the industry standard security certifications (SOC 2, for example). This is common practice for large enterprises when engaging with new vendors. These are super obnoxious to fill out, but usually come with very large enterprise contracts, so vendors put up with them. It's certainly not normal to send these to maintainers of open source projects...

In this case I suspect the employee in question simply misunderstood the company process, and had no malicious intent.

2 comments

Yep, even with certification you'll get these from time to time.

Two options:

1) point them to your existing policies and processes for SOC2, IRAP, ISO27001 and similar, the questionnaire is already filled

2) fill it out as best you can if it's going to earn you bank.

Yep, somehow this project got included in a spreadsheet of vendors, and somebody told the new guy in the compliance department, "email this compliance form to all of the vendors in this spreadsheet".