<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vendor Security Rating Services in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4601#M188</link>
    <description>&lt;P&gt;The problem with the vendor " Security&amp;nbsp; Assessment questionnaire" approach is that it&amp;nbsp; is&amp;nbsp; a point in time and is not reflective of overall security "Hygiene" over time. kind of like asking a child to clean their room. It may be tidy for an hour, but the child is still messy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; the good thing about rating services is that they measure behavior over time,which&amp;nbsp; I believe is more predictive,&lt;/P&gt;</description>
    <pubDate>Thu, 28 Dec 2017 14:33:35 GMT</pubDate>
    <dc:creator>Alex41</dc:creator>
    <dc:date>2017-12-28T14:33:35Z</dc:date>
    <item>
      <title>Vendor Security Rating Services</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4544#M184</link>
      <description>&lt;P&gt;Looking for folks with experience relying on vendor security rating services such as SecurityScorecard. How reliable are these services and from a vendor technology risk perspective, would you recommend using these services?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:23:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4544#M184</guid>
      <dc:creator>yashua</dc:creator>
      <dc:date>2023-10-09T08:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Security Rating Services</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4561#M185</link>
      <description>&lt;P&gt;Yes, we use security ratings in our company and have really good experience with them. Recommend them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Dec 2017 23:11:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4561#M185</guid>
      <dc:creator>johnbatista</dc:creator>
      <dc:date>2017-12-24T23:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Security Rating Services</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4593#M186</link>
      <description>&lt;P&gt;I've looked at a lot of these from a RFP / evaluation process (not going to name names, though).&amp;nbsp; There's a lot to offer, but for me, where the rubber always hit the road was when I asked the question, "Can you viably replace my current vendor risk management process?"&amp;nbsp; The answer was typically in the negative - they always saw themselves as a supplement to the process.&amp;nbsp; Which brings us back to your question.&amp;nbsp; I think if you're seeking a supplement to your current evaluation program, these can add great value and insight, but for a price.&amp;nbsp; However,&amp;nbsp;if you're looking to replace your own vendor management program, it's probably not going to work.&amp;nbsp; A few&amp;nbsp;caveats, I think if you don't have one, and are looking to build one out, this could take you up a level, for the short term.&amp;nbsp; But you shouldn't depend on them in the long term.&amp;nbsp; Also, if you are seeking to gain some level of cyber insurance, there does seem to be some motion in the industry towards these "credit score" like solutions.&amp;nbsp; It's still a little early, IMO, to&amp;nbsp;fully commit to them for this purpose.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 16:31:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4593#M186</guid>
      <dc:creator>greppy73</dc:creator>
      <dc:date>2017-12-27T16:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Security Rating Services</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4595#M187</link>
      <description>&lt;P&gt;I don't have much experience with the rating services. While I think they are useful, I'd place much less emphasis on the rating as compared to vendor service agreements and compliance. In short, I'd rather a vendor provide me documentation they are in compliance with - fill in the blank - than rely on a third party rating. That raises the challenge: What if you have a suspect vendor but they are willing to put in writing they are in compliance compared to a great vendor that doesn't put compliance in writing. From a regulatory standpoint, you are almost forced to go with the former vendor even though, likely, the latter will be better.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 17:06:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4595#M187</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2017-12-27T17:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Security Rating Services</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4601#M188</link>
      <description>&lt;P&gt;The problem with the vendor " Security&amp;nbsp; Assessment questionnaire" approach is that it&amp;nbsp; is&amp;nbsp; a point in time and is not reflective of overall security "Hygiene" over time. kind of like asking a child to clean their room. It may be tidy for an hour, but the child is still messy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; the good thing about rating services is that they measure behavior over time,which&amp;nbsp; I believe is more predictive,&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 14:33:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4601#M188</guid>
      <dc:creator>Alex41</dc:creator>
      <dc:date>2017-12-28T14:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Security Rating Services</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4669#M189</link>
      <description>&lt;P&gt;-Alex41 - I agree with your comments about "point in time"&amp;nbsp;in a vendor assessment.&amp;nbsp; The issues for me are two fold.&amp;nbsp; First, as anyone who has done a vendor assessment knows, it's in the course of doing them you discover things that are specifically important or relevant to your business.&amp;nbsp; These are the "peel you off the ceiling moments" that you don't really discover because you know your business, and what is important to you.&amp;nbsp; A rating service will not give you this.&amp;nbsp; Second, the rating service is still (somewhat) point in time.&amp;nbsp; The service typically requires engagement from the vendor being rated, or a lot of investigation by the vendor, themselves.&amp;nbsp; The other thing I didn't mention in my original post was adoption.&amp;nbsp; I was constantly asking the rating companies, how many companies in your database?&amp;nbsp; The answers I got were not encouraging.&amp;nbsp; Think 100's to 1000's.&amp;nbsp; Of course, they were willing to engage with the vendor "on your behalf" and for a price.&amp;nbsp; This may be getting too deep into the muck, but I always replied to that with a smile, a question and a comment, "So you want me to grow your database of vendors and pay for it too?&amp;nbsp; Good thing you get to use my company's name in order to engage too."&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that's why I'm more or less sticking with my stand point of, they are a good supplement, and may be useful for insurance or regulatory purposes later.&amp;nbsp; Although, I absolutely agree with your point, Alex41, and I think it's very thoughtful.&amp;nbsp; But the better internal vendor assessment programs I have been part of building, typically review the vendor every 1-3 years depending on criticality.&amp;nbsp; For the most part, I think this is sufficient.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 15:28:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Vendor-Security-Rating-Services/m-p/4669#M189</guid>
      <dc:creator>greppy73</dc:creator>
      <dc:date>2018-01-02T15:28:57Z</dc:date>
    </item>
  </channel>
</rss>

