4 ms·
I would. A critical part of having a robust security program is having an effective third party risk management program which evaluates all third parties that
by arrakeenrevived 3y ago
I would.
A critical part of having a robust security program is having an effective third party risk management program which evaluates all third parties that you do business with and holds them to high security standards. Okta is the ultimate party that is responsible for protecting this data, and that still remains true even if they subcontract out the protection of that data. If you aren't doing third party risk management, then it calls into question what other critical parts of security you're failing at.
For a company like Okta, which supposedly is a "security" company, to have _repeated_ security failings like this should make everyone question them.