5 ms·
Exactly, that set of standard questions and responses (ie controls) is exactly what a VSA is. However, SOC2 takes it a step further and requires an formalized
by jamiesonbecker 6y ago
Exactly, that set of standard questions and responses (ie controls) is exactly what a VSA is.
However, SOC2 takes it a step further and requires an formalized audit from a AICPA certified security auditing firm[0].
Therefore, a security questionnaire should be for follow-up items that the customer feels were not adequately addressed in one or more of the vendor's compliance attestations.
Otherwise, the customer is asking the vendor to step through redundant check-the-box busywork that actually requires a higher level of skill that can not be adequately completed by a junior engineer. To wax hyperbolic, it's like an engineering DoS attack which serves neither the customer nor the vendor well (unless the goal is to slow down the vendor from making new and better products)
0. https://www.aicpa.org/interestareas/frc/assuranceadvisoryservices/aicpasoc2report.html https://www.aicpa.org/interestareas/frc/assuranceadvisoryser...