Hi all,
We currently utilize the CIS20 as guidance for our security reviews (the process is still being developed), but I feel like we have some major process flaws, and so I would like to know how others here conduct security reviews for comparison, specifically:
- Scope: How do you determine when to punt on it, and when to engage? I feel like we shouldn't be wasting valuable time engaging on every piece of computer software or Outlook add-in review request that comes our way, but technically our user laptops are rated "Medium" sensitivity, and so by our Data Classification standards we need to engage (almost) fully. How do you determine at a glance whether something is worth time in a world where cloud-delivered solutions mean that technically EVERYTHING is "connected"? Do certain vendors/products tend to warrant more of cursory review simply because of who they are? (e.g. a Docusign e-sig solution versus a-developer-working-out-of-his-house e-sig solution...)
- Does your security team (Ops, Engineering, etc.) conduct reviews, or have you largely streamlined the process to push it to Support? ITIL best practices (for example), would tell us this is something that can be largely automated/offloaded to lower cost resources, but I don't think the current process we have developed is easily repeatable by Support resources (given that our own team members are struggling with it). How complex is your ticket management lifecycle? (Do you just track the entire review under one ticket, or spawn multiple child tickets based on phase needs?)
- Time invested: how long, on average, do you spend reviewing a platform or product from first intake/recon, to following up on risk remediation post report delivery? How long/in-depth is the ultimate report you deliver to the customer?
Thanks!
submitted by [comments]
SOCIAL SHARE CARD GENERATOR