Skip to content

10 Security Questions to Ask Your Tech Vendors 

Yuri Byun  | 22 May 2023  |  < 1 minute read


10 Security Questions to Ask Your Tech Vendors 

  1. Does the Vendor have a recent SOC2 & SOC3 Report (Annual) they can share w/ you? 
  1. Does the Vendor have any of the following certifications: FedRAMP, StateRAMP, ISO, CSA? 
  1. Does the Vendor follow a Secure Software Development Lifecycle (SSDLC)? 
  1. What is the Vendor’s Software Bill of Materials (SBOM)? 
  1. What does the Vendor’s Incident Response Program entail? 
  1. Can the Vendor explain their Vulnerability Testing processes? 
  1. What Penetration Testing does the Vendor do? 
  1. How does the Vendor leverage Multi-Factor Authentication? 
  1. Does the Vendor offer Single Sign-On functionality for customers? 
  1. Can the Vendor provide background checks that map to CJIS requirements? 

Interested in hearing more from our speakers? 

Check out Larry Zorio’s, CISO at Mark43, resources for public safety: 

  1. Securing your public safety agency from catastrophic malware attacks 
  1. 3 Pillars of Data Security: Confidentiality, Integrity & Availability 
  1. Whitepaper: Making data security a priority 
  1. TechRepublic interview: Fighting cybersecurity risks for law enforcement: On-premises vs. cloud native systems 

Watch Chief Ishii’s fireside chat around Taking the Leap and Reaping the Benefits of a Modern Tech Strategy 

Ready to schedule a demo? Fill out the form and a member of our team will be in touch!

Request a Demo