Xylem
Vendor Selection for Cybersecurity Partnership
Pages
3
Time to read
5 mins
Publication
Language
English
Pages
3
Time to read
5 mins
Publication
Language
English
This guide outlines the essential questions to ask potential vendors when selecting a partner for cybersecurity. It emphasizes the importance of understanding not only what services vendors provide but also how they deliver them. The document references the System of Trust Framework developed in partnership with MITRE, which serves as a basis for evaluating vendor trustworthiness. Key questions include inquiries about general cybersecurity practices, secure development processes, and secure deployment guidance. The guide highlights relevant standards such as ISO 27001, ISA/IEC 62443, and NIST SP800-218, which can help assess a vendor's security posture. Additionally, it discusses the importance of obtaining a software bill of materials (SBOM) and understanding incident response practices. The document concludes with a recommendation for establishing minimum expectations with vendors and considering audit rights in contracts to ensure ongoing compliance and security.