Settings

Theme

Refocusing Vendor Security on Risk Reduction

engseclabs.com

3 points by alexsmolen 3 months ago · 1 comment

Reader

tptacek 3 months ago

I was psyched for Alex to post this here because I think it's a super valuable bit of understanding for startups that need to do vendorsec† that mostly gets hand-waved away in writing about startup security programs. The bit about the power differential in particular!

There's a startup vendorsec playbook that mostly revolves around SOC2 and security people increasingly call out how performative it is. This piece is about non-performative stuff.

vendorsec: the part of your security program where you do something about all your third-party vendors

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection