LinkedIn and 3rd parties use essential and non-essential cookies to provide, secure, analyze and improve our Services, and to show you relevant ads (including professional and job ads) on and off LinkedIn. Learn more in our Cookie Policy.

Select Accept to consent or Reject to decline non-essential cookies for this use. You can update your choices at any time in your settings.

Agree & Join LinkedIn

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

Skip to main content
LinkedIn
  • Articles
  • People
  • Learning
  • Jobs
  • Games
Join now Sign in
Last updated on Feb 19, 2025
  1. All
  2. Engineering
  3. Network Security

You're debating security levels with internal stakeholders. How do you ensure vendors meet your standards?

Debating security levels with internal stakeholders is critical to protecting your network. To ensure vendors meet your security standards, follow these steps:

  • Set clear expectations: Define and document your security requirements in contracts and service-level agreements \(SLAs\).

  • Conduct regular audits: Schedule periodic reviews of vendors' security practices to ensure ongoing compliance.

  • Implement a vetting process: Use a thorough evaluation process to assess vendors' security measures before engagement.

How do you ensure vendors adhere to your security standards? Share your strategies.

Network Security Network Security

Network Security

+ Follow
Last updated on Feb 19, 2025
  1. All
  2. Engineering
  3. Network Security

You're debating security levels with internal stakeholders. How do you ensure vendors meet your standards?

Debating security levels with internal stakeholders is critical to protecting your network. To ensure vendors meet your security standards, follow these steps:

  • Set clear expectations: Define and document your security requirements in contracts and service-level agreements \(SLAs\).

  • Conduct regular audits: Schedule periodic reviews of vendors' security practices to ensure ongoing compliance.

  • Implement a vetting process: Use a thorough evaluation process to assess vendors' security measures before engagement.

How do you ensure vendors adhere to your security standards? Share your strategies.

Add your perspective
Help others by sharing more (125 characters min.)
27 answers
  • Contributor profile photo
    Contributor profile photo
    Vrushali A.

    Cybersecurity Architect @ Honeywell

    • Report contribution

    Security isn’t a checkbox; it’s a moving target. Vendors need to meet defined standards not just at onboarding but continuously. Establish clear contractual obligations tied to security SLAs and regular compliance audits—trust but verify. Engage vendors with detailed security questionnaires aligned to industry frameworks (ISO 27001, NIST). Demand transparency on breach history, patching cadence, and incident response protocols. Leverage risk-based scoring to quantify gaps and push corrective actions. If a vendor can’t align with evolving security requirements, the partnership becomes a liability, not an asset.

    Like
    7
  • Contributor profile photo
    Contributor profile photo
    Ajay Krishna Manam

    Network Tower Lead | Technical Solutions Architect @ HCL America | Design and implementing: Cisco Enterprise/DC, Cisco Wi-Fi, Velocloud SDWAN, Palo Alto Networks, Azure, and Service Architecture.

    • Report contribution

    IT security should be treated with the same rigor as airline safety standards. Regardless of status, wealth, or affiliation - whether it's a vendor, VIP, or the airport owner - everyone must adhere to established processes and safety protocols.

    Like
    3
  • Contributor profile photo
    Contributor profile photo
    Michael V.

    Inquisitive Problem Solver | Security+

    • Report contribution

    This can vary depending on the vendor and the security standards set by the company, but here are a few considerations: - Provide a security questionnaire - Ensure they meet compliance with an industry standard (ISO, NIST, CIS, etc.) - Perform periodic assessments of their security posture through an audit - Demand a history of data breaches in the company (and what steps were taken to eliminate the root cause) - Maintain transparency (within reason) Vendor risk management is a crucial pillar of information security. Every vendor is a new avenue for attackers, and should be carefully considered when engaging in business.

    Like
    2
  • Contributor profile photo
    Contributor profile photo
    Jose Pablo Morales Martinez

    Mexican and Spanish citizenship | Security, Scrum, Engineering, PM, Software Development

    • Report contribution

    To ensure vendors meet security standards, I'd implement the following: Detailed security requirements: Clearly defined in contracts. Rigorous vendor assessments: Including audits and questionnaires. Continuous monitoring: For ongoing compliance. Right to audit clauses: within contracts. Compliance with industry standards: such as ISO 27001, and NIST.

    Like
    2
  • Contributor profile photo
    Contributor profile photo
    Aderonke Dahunsi, EIT,PhD, COREN®

    Power System Engineer | Advancing Grid Reliability & Renewable Energy Integration | Achieved Significant Cost Savings Through Network Optimization | Sustainability Advocate | Strategic Problem-Solver | Mentor

    • Report contribution

    To ensure vendors meet security standards, I set clear requirements in contracts, conduct thorough assessments, and implement regular audits. Continuous monitoring and transparent communication ensure ongoing compliance and alignment with security expectations.

    Like
    1
  • Contributor profile photo
    Contributor profile photo
    Eder Demari

    Cybersecurity Eecutive ! (ISC)² CC

    • Report contribution

    Clear Service level Objectives, cadency meetings, match the compliance rewuirements, engage the government plan with the vendor.

    Like
    1
  • Contributor profile photo
    Contributor profile photo
    Santosh Kumar CISSP, PMP, CISA, CHFI, CIPP/E, CIPM, AIGP

    Cybersecurity & Data Protection Leader | CISO & DPO | GenAI Architect | Fellow of Information Privacy (FIP) | Navy Veteran 🏫 IIT Madras| IIM Indore

    • Report contribution

    "Trust, but verify" 🎯Develop tiered vendor security questionnaires based on data access levels 🎯Create standardized security clauses for all vendor contracts 🎯Implement vendor risk scoring system with minimum threshold requirements 🎯Establish right-to-audit clauses with specific testing methodologies 🎯Require vendors to provide SOC2 reports or equivalent certifications 🎯Deploy continuous monitoring tools for vendor connection points 🎯Create joint security incident response procedures with key vendors 🎯Implement vendor security performance dashboards for stakeholders 🎯Establish quarterly vendor security reviews for critical service providers 🎯Develop competitive security benchmarking between similar vendors

    Like
    1
  • Contributor profile photo
    Contributor profile photo
    Tim Trakes

    Professional Day Trader

    • Report contribution

    There is no debate when it comes to security. Either comply with strict security measures for the safety of the company and the companies they work with or part ways. This is a much safer bet than being in a legal battle due to a security breach.

    Like
    1
  • Contributor profile photo
    Contributor profile photo
    Donald Davis

    Authorized Dealer Orion Musical Instruments, Houston/South Texas at Orion Musical Instruments, Freelance Trumpet/Flugelhorn/Bugler, Lead Trumpet - BRASS INFERNO Horns

    • Report contribution

    All the nuts and bolts are already stated by others; I would add that it's fundamental to understand that security levels are determined by industry best practices and the current state of technology. So, whatever that standard turns out to be, it is, by definition, only a MINIMUM standard, that one should be pleased to comply with, because the standard is necessarily always on the rise. It is a fundamental and critical component of competence and professionalism in any position that must access an enterprise network.

    Like
    1
  • Contributor profile photo
    Contributor profile photo
    David Ortiz Garcia

    SSE Solution Architect, EMEA at Check Point Software

    • Report contribution

    As a vendor, IT is crucial to have empathy with the customer needs. You should have several meetings with the customer, so it is clear you understand the customer’s expectations. You have also to ensure your product meets the security standards that needed for that industry. This is an evolving process, that starts at the development side of the product

    Like
    1
View more answers
Network Security Network Security

Network Security

+ Follow

Rate this article

We created this article with the help of AI. What do you think of it?
It’s great It’s not so great

Thanks for your feedback

Your feedback is private. Like or react to bring the conversation to your network.

Tell us more

Report this article

More articles on Network Security

No more previous content
  • Your network security is at risk due to an insecure IoT device. How will you prevent a potential data breach?

    10 contributions

  • Your team is accused of a security breach they didn't cause. How do you prove their innocence?

    14 contributions

  • Struggling to explain network security protocols to non-technical colleagues in a remote work setup?

    14 contributions

  • Employees are bypassing VPN protocols in your company. Are your network security measures enough?

    7 contributions

  • Your remote team relies heavily on VPNs. How can you safeguard against potential vulnerabilities?

    13 contributions

  • You're integrating third-party software into your network. How do you mitigate the security risks?

    6 contributions

  • You need to address a diverse audience on network security. How do you make your presentation effective?

    9 contributions

  • Clients are worried about complex access control measures. How do you ease their concerns?

    7 contributions

  • Ensuring robust security is critical for your network. How do you maintain seamless access?

    2 contributions

  • You're facing pushback from your IT team on network security updates. How can you get them on board?

    9 contributions

No more next content
See all

Explore Other Skills

  • Programming
  • Web Development
  • Agile Methodologies
  • Machine Learning
  • Software Development
  • Data Engineering
  • Data Analytics
  • Data Science
  • Artificial Intelligence (AI)
  • Cloud Computing

Are you sure you want to delete your contribution?

Are you sure you want to delete your reply?

  • LinkedIn © 2025
  • About
  • Accessibility
  • User Agreement
  • Privacy Policy
  • Cookie Policy
  • Copyright Policy
  • Brand Policy
  • Guest Controls
  • Community Guidelines
Like
9
27 Contributions