April 26, 2022, 11:12 a.m. | /u/DeWorst

cybersecurity www.reddit.com

I have recently been tasked with performing due diligence checks on our suppliers and if their security is up to snuff (Certifications, relevant security controls, ect).

However, some of the suppliers listed simply provide native based software. For instance, Norton antivirus.

Seeing as Norton don't host the application on the cloud, and it simply being natively installed, Is a review of the supplier still required? And If so, what aspects of Norton do I review?

cybersecurity due diligence security

Cybersecurity Consultant

@ Devoteam | Cité Mahrajène, Tunisia

GTI Manager of Cybersecurity Operations

@ Grant Thornton | Phoenix, AZ, United States

(Senior) Director of Information Governance, Risk, and Compliance

@ SIXT | Munich, Germany

Information System Security Engineer

@ Space Dynamics Laboratory | North Logan, UT

Intelligence Specialist (Threat/DCO) - Level 3

@ Constellation Technologies | Fort Meade, MD

Cybersecurity GRC Specialist (On-site)

@ EnerSys | Reading, PA, US, 19605