Hacker News new | past | comments | ask | show | jobs | submit login

These are often knocked back with "We charge $4,000 to answer Security Questionnaires, or you can download our pre-made pack [that answers none of these questions] here."



Author here: weird, I've never experienced that (10+ years doing this silly exercise, on both sides).

Various vendors have offered their own compliance frameworks - PCI reports, SOC2, whatever -- and I'm happy to read those instead; they tend to have (most of) what I'm looking for. I've never been charged for the pleasure, though. Guess I have something to look forward to!


What is a "pre-made pack" ?

An overview of your security stance which is fundamentally fluff ?

Thanks.


> What is a "pre-made pack"

"I took the last DSQ I got and answered it pretty fully so here's a copy, and I'm not going to waste time answering the weird extra questions your CISO decided to add into the mix"


Correct. Some do a good enough job, but I find most lacking.


Which vendors charge for their DSQ?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: