customer number three sent a 74 question security questionnaire and wants a signed dpa - answer it or walk
A 60 person company wants to buy the $89 a month plan. Their procurement sent a spreadsheet with 74 questions covering encryption, penetration testing, incident response, employee background checks and business continuity, plus a data processing agreement to sign.
I am one person. The honest answer to about twenty of those questions is no or not applicable. At $1,068 a year I cannot tell whether this is a customer or a research project.
Do people answer these at this size, and does saying no to half the questions automatically kill the deal?
@stdlib_stef · 6mo ago · 3 replies
Answer it, honestly, and do not pretend. Reviewers see a lot of these and an inflated one is obvious and fatal. A clean no with a sentence explaining what you do instead reads as competent. A yes you cannot evidence reads as a liability.
So for background checks: no, single person company, here is the identity verification my payment provider ran. For penetration testing: no third party test, here is what I do use, here is my dependency scanning, and I am open to their test at their cost. For business continuity: honestly describe the backup schedule, the restore procedure and the last time you tested a restore. If the answer to that last one is never, go test a restore before you send the spreadsheet back, because it is the question that most deserves a real answer.
The DPA itself is usually the easy part. Their template, your subprocessor list, a review by someone who reads contracts.
Reply
Report
@pandl_paula · 6mo ago
I have never tested a restore. That is a genuinely alarming realisation to have arrived at through a procurement form.
Reply
Report
@cloze_kai · 6mo ago
The questionnaire being the thing that finally makes you test your backups is the most common story in this whole genre. It is the best free consulting you will ever receive.
Reply
Report