Risk Assessments

 View Only
  • 1.  Vetting New Vendors

    Posted 12-10-2019 02:17 PM
    Currently my Company uses BitSight to help with vetting vendors along with the documentation that we request from them. ​I am wondering what tools/websites that most use to vet or find out information on a particular Vendor.


  • 2.  RE: Vetting New Vendors

    Posted 12-14-2019 01:04 PM
    For us, tools like BitSight are terrific but somewhat narrowly focused. RiskRecon is a lesser known competitor of BitSight and has some cool features. If you are interested in more than that, besides SOC reports here's a site that collects info on data breaches: https://privacyrights.org/categories/data-breaches Some states like CA have a data breach database for published breaches. https://oag.ca.gov/privacy/databreach/list