Information Security

 View Only
  • 1.  Vetting SaaS Vendors

    Posted 14 days ago

    Does anyone have template that they would like to share on Vetting SaaS vendors?



  • 2.  RE: Vetting SaaS Vendors

    Posted 11 days ago

    It might be difficult to develop a template to vet SaaS vendors, since this is such a broad category. However, I'll provide some best practices and recommendations that should help you get started in vetting SaaS vendors.

    Best practices for assessing risk:

    • Evaluate some general information such as the vendor's qualifications, service level agreements, billing, ease of use, and the SaaS interface.
    • Ask the vendor relevant security questions about their standards, encryption practices, data migration process, and who will have access to your data.
    • Also consider asking the vendor questions about the vendor's business continuity and disaster recovery plans and incident response management.
    • And make sure you're aware of the type of support the vendor provides and how it handles changes and manages controls.

    Best practices for due diligence:

    • Start by collecting all of the foundational documents like business license, credit report, list of subcontractors and any negative news search findings.
    • You should also review the vendor's audited financial statements, as well as any relevant insurance certificates and licenses or certifications.
    • It's important to know how your SaaS vendors are managing their own third parties, so you should also collect and review their vendor management policy.
    • One due diligence document that can really help in vetting a SaaS vendor is a Consensus Assessments Initiative Questionnaire (CAIQ). This is a questionnaire developed by Cloud Security Alliance and covers 16 categories of controls. Once you collect this from the vendor, have it reviewed by a qualified subject matter expert who can identify any gaps in the vendor's security controls.

    These best practices and recommendations are just a starting point, and you'll want to make sure that you're asking questions and collecting documentation that is specific to the vendor's product.

    I hope these best practices are helpful and I'd like to know how other members are vetting their SaaS vendors.




  • 3.  RE: Vetting SaaS Vendors

    This message was posted by a user wishing to remain anonymous
    Posted 10 days ago
    This message was posted by a user wishing to remain anonymous

    Thank you for this insightful information Christine!

    How would you recommend vetting for IaaS and PaaS supplier (only in terms of the Security Controls)?

    Anyone in the community using any tools / checks for credibility in terms of a COTS application suppliers?

    Thanx All!




  • 4.  RE: Vetting SaaS Vendors

    Posted 10 days ago

    I'm glad my answer was helpful! The CAIQ I mentioned before is designed to assess the security controls of all three providers – SaaS, IaaS, and PaaS. The questionnaire contains yes/no questions, which makes it easy to determine whether the provider is compliant with the Cloud Security Alliance's Cloud Controls Matrix (CCM).




  • 5.  RE: Vetting SaaS Vendors

    Posted 11 days ago
      |   view attached
    Michael, please see the HECVAT (Higher Education Cloud Vendor Assessment Tool) that's used by Universities to assess cloud vendors.  These questions apply to any cloud vendor.
    Here's the link: Higher Education Community Vendor Assessment Toolkit | EDUCAUSE Library
    Regards,

    Jose Morales
    Virginia Commonwealth University
    Program Manager, Information Security 




    Attachment(s)

    xlsx
    hecvat306rc3.xlsx   1.28 MB 1 version