May 22, 2023, 7:56 p.m. | /u/Mundane-Moment-8873

cybersecurity www.reddit.com

When vendor's reject filling out a security questionnaire, and then hand over 3+ reports usually totaling over 100 pages of information. I'm curious, what sections in the SOC 2 Type 2 report do you always take a deep dive and what areas are not crucial but still informative?

Edit: To make this a little more general, let's say the vendor points you to their trust website with all their reports. Which reports are you taking time to review in detail?

cybersecurity deep dive dive information questionnaire reject report reports security security questionnaire soc soc 2 vendor

Principal Security Engineer

@ Elsevier | Home based-Georgia

Infrastructure Compliance Engineer

@ NVIDIA | US, CA, Santa Clara

Information Systems Security Engineer (ISSE) / Cybersecurity SME

@ Green Cell Consulting | Twentynine Palms, CA, United States

Sales Security Analyst

@ Everbridge | Bengaluru

Alternance – Analyste Threat Intelligence – Cybersécurité - Île-de-France

@ Sopra Steria | Courbevoie, France

Third Party Cyber Risk Analyst

@ Chubb | Philippines