Why security questionnaires are a familiar-but ineffective-norm for assessing risk
Security questionnaires are a standard part of almost every due diligence process before companies sign on to work with a new third party. By asking detailed questions via questionnaires, organizations learn about a seller’s security controls and compliance with relevant standards. With that information, they determine how and if a partnership with that third party will expand their attack surface and increase risk—and ultimately decide if the increased risk is acceptable.