This message was posted by a user wishing to remain anonymous
Having been on both sides of the table...
As a vendor, I never shared policies outside of the organisation as they were considered to be proprietary. There were times when a policy included requirements that might lead to more questions regarding security operations, again not to be shared.
As a buyer, i had few vendors provide policies. Some would provide coverpages and tables of contents to give an idea of what was included in the policy.
If your vendor has an ISO27001 or PCI certification, or a SOC 2 report, policies are reviewed as part of completing these.
Original Message:
Sent: 04-02-2025 01:27 PM
From: Anonymous Member
Subject: Information Security Policy Assessments
This message was posted by a user wishing to remain anonymous
Similar to reviewing and assessing SOC reports, does anyone currently do assessments on your third-party vendors' information security policies? If so, would you be willing to share?
Thanks in advance.