Security Requirements in Third Party Contracts
If a penetration test is the first time you’ve considered the security of your new IT project, you’re doing it very wrong. Much of any project’s security effort should be in the early stages, from risk assessing to agreeing with your developers, either in-house or external, just what security measures are being implemented, and validated.. Security, just like any other metric, needs to be objectified, quantified, and agreed upon before development begins. And this leads us to a very common oversight so beautifully documented in ISO27001; Security requirements in third party contracts.
