Chapter 22
Integrating Information Security into the Contracting Life Cycle
CHECKLIST
Use the Three Tools for Better Integrating Information Security into the Contract Life Cycle
□ Precontract due diligence
□ Key contractual protections
□ Information security requirements exhibit
Precontract Due Diligence
□ Develop a form due diligence questionnaire
□ Ensure the questionnaire covers all key areas
□ Use the questionnaire as an early means of identifying security issues
□ Use the questionnaire to conduct an “apples-to-apples” comparison of prospective vendors
Key Contractual Protections
□ Fully fleshed-out confidentiality clause
□ Warranties
– Compliance with best industry practices; specify the relevant industry
– Compliance with applicable ...
Get A Guide to IT Contracting, 2nd Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.