4 ms·
There's a very recently announced (https://security.googleblog.com/2021/10/launching-collaborative-minimum.html https://security.googleblog.com/2021/10/launchin
by arraypad 5y ago
There's a very recently announced (https://security.googleblog.com/2021/10/launching-collaborative-minimum.html https://security.googleblog.com/2021/10/launching-collaborat...) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.
- Mesmoria 5y agoI note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18". That looks larger than all the other requirements.
- wglb 5y agoI think the intent here is to note that there may be business requirements about these that affect the security of your business. For example, if anyone pays you through credit cards, PCI DSS is non-optional. Certain transactions of health information will require Hitrust. Without them, you won't be able to do business, and while they seem large (PCI DSS if you have another company handle the cards, is a very simple self-assessment.)
- ghiculescu 5y agoYes, unsurprisingly, this is set up to protect incumbents that have collected all these certifications.
- sk5t 5y agoIME the human time cost and direct expense associated with obtaining HITRUST, even if you've already done SOC2, is roughly in line with buying a Lamborghini.
- linker3000 5y agoThe 'standard' one I've been asked to complete a few times is the CAIQ: https://cloudsecurityalliance.org/artifacts/consensus-assessments-initiative-questionnaire-v3-1/ https://cloudsecurityalliance.org/artifacts/consensus-assess...