While company’s work …show more content…
It is a non-regulatory government agency that develops technology, metrics and standards for innovation. It encompasses best practices across a range of industries at US based organizations. A widely adopted NIST standard is the NIST Cybersecurity Framework which is based on best practices from several security documents, organizations, and publications. This is a framework for federal agencies that require stringent security measure to follow. As these standards are endorsed by the government, companies comply with NIST standards as it helps them comply with other regulations such as HIPAA, FISMA and …show more content…
If the business is reviewing their business design and are evaluating vendors to contribute to an architectural design, they may require that the vendor be reviewed and approved by the Security team. If the business is merely contracting for a specific service, they may also request a review be completed by security before proceeding. Groups or business units may also approach the procurement department first before requesting a security review especially if they are in the process of requesting information for a final decision. In that scenario, the request will come from procurement for one or more of those potential vendors. Once the request is in the Security queue, the first step will be to contact the vendor and request a SOC 2 final report for review. If the vendor has not had a SOC 2 review done, the Security team will provide a questionnaire to be completed and submitted for review to the security team. The team will then review the document to identify any gaps in the reporting that must be addressed. If gaps are identified, the Security team will reach out to the vendor to review and discuss. Updates are made to the questionnaire until no further information can be provided or the form is complete. Once this is done, the Security team will complete a “Findings” document and determine if the vendor is “Approved” or “Denied”. If a vendor is “Approved”, then the procurement department is notified if the