3 ms·
Good advice. I've filled in dozens of those questionnaires from big corps on behalf of clients, and they can be gruelling, but in general the infosec team on th
by johnorourke 6y ago
Good advice. I've filled in dozens of those questionnaires from big corps on behalf of clients, and they can be gruelling, but in general the infosec team on the other end are usually cooperative / collaborative - eg. they'll often take a "we'll work on this" or "we don't need this because X" over "won't fix".
The most important thing is committed spend - eg. it's common for Big Corp Inc's infosec team to put you through compliance, potentially asking you to spend $0000's on time and services, without comparing that to the value of the contract you could have with them. You could spend a lot based on zero commitment it you take your eye off this.
- sk5t 6y ago> The most important thing is committed spend Yes, that's the thing--the grueling infosec process is independent of commitment. It's a catch-22.
- smu 6y agoMany big corps do have a tiered process (depending on perceived risk). A trick is to get yourself classified in the lowest possible tier. Teaching your salespersons to help their contacts/champions with convincing their internal security to lower classification will be great ROI for you :)