3 ms·
By following the basics of ISO27K1, for example: Good infosec teams keep inventory of all the software used in the org. If they see that the org already pays a
by 300 5y ago
By following the basics of ISO27K1, for example:
Good infosec teams keep inventory of all the software used in the org. If they see that the org already pays a vendor for software doing X, a question should be raised, why we need another one for doing the same thing.
Also, each new vendor or software provider needs go get a "security clearance", after the infosec teams checks their state of security.
These kinds of practices would probably discover the shady intents.