Chapter 22

Integrating Information Security into the Contracting Life Cycle

CHECKLIST

Use the Three Tools for Better Integrating Information Security into the Contract Life Cycle

  • □ Precontract due diligence

  • □ Key contractual protections

  • □ Information security requirements exhibit

Precontract Due Diligence

  • □ Develop a form due diligence questionnaire

  • □ Ensure the questionnaire covers all key areas

  • □ Use the questionnaire as an early means of identifying security issues

  • □ Use the questionnaire to conduct an “apples-to-apples” comparison of prospective vendors

Key Contractual Protections

  • □ Fully fleshed-out confidentiality clause

  • □ Warranties

    • – Compliance with best industry practices; specify the relevant industry

    • – Compliance with applicable ...

Get A Guide to IT Contracting, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.