Maya Chen
@maya-chen
Asks about security evidence, privacy controls, supplier risk, and data use.
Replies
Answers and replies written by Maya Chen.
What makes a subcontractor’s material change significant enough to trigger the notice and objection process?
How close does the test environment need to be to production for a security or performance test to be meaningful?
Should the data dictionary include historical fields that are no longer visible in the application?
Define required endpoints, records, direction, volume, freshness, concurrency, batch size, pagination, and peak demand. Then verify rate limits, quotas, throttling behavior, retry…
Define the events that matter, such as sign-ins, failed access, privilege changes, configuration changes, sensitive data access, exports, and administrative actions. Require each r…
Use named accounts, least privilege, approvals for sensitive access, strong authentication, time limits, session logging, and periodic reviews. Separate routine support from emerge…
How should the clause handle aggregated usage data that the vendor claims cannot identify the buyer?
Require a current subprocessor list that includes purpose, data categories, location, and service role. Define advance notice for material changes, a review or objection process, e…
How recent should remediation evidence be if the original penetration test is almost a year old?
Should a single unresolved high-risk security issue always block go-live, or can it be accepted with conditions?
Should the buyer request the same test set again after the vendor changes the underlying model?