Define what you are evaluating

Describe the proposed service and the business activity it supports. Establish what information or access is involved and how dependent the business would become. That context helps distinguish necessary evidence from interesting but unrelated material.

Due diligence is structured investigation, not a guarantee that all problems will be discovered. An initial questionnaire can identify questions for follow-up; it is not automatically independent assurance. NIST treats initial screening as part of a wider assessment rather than an exhaustive result. Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

Ask how the service operates

ACSC’s questions for managed service providers cover security practices and operational matters such as administrative access and incident arrangements. Ask for answers about the proposed service, rather than the supplier’s business in general. Questions to ask managed service providers

Useful questions for an evaluation include who can administer your environment, who handles an incident, what visibility you receive and what happens when the relationship ends. For backup or recovery claims, ask what the claim actually covers and what evidence supports it. These are questions to resolve, not assumptions that every supplier offers the same functions.

Examine the scope of evidence

Record the issuer, date, relevant service, limitations and unresolved questions for each piece of evidence. If a supplier presents an audit report or certification, arrange an appropriately qualified review of what it covers. A logo alone should not decide whether the proposed service meets your requirement.

A demo, questionnaire answer, contract commitment and assurance report serve different purposes. Keep them separate in the decision record. A confident presentation can help explain a service, but it does not fill a missing contractual commitment or establish production functionality.

An invented supplier scorecard

A business is considering a hosted application. Its evaluator creates a row for access removal, another for recovery responsibilities and another for exit/export. Each row records the requirement, supplier answer, evidence, limitations and responsible reviewer. Missing information stays marked as unresolved.

The example does not score a real supplier or prescribe a universal pass mark. The business owner decides which gaps are unacceptable, with technical and specialist advice appropriate to the service.

A practical review checklist

  • Define the exact service and important requirements.
  • Ask who performs and verifies the relevant operational tasks.
  • Record the scope, issuer and date of supporting evidence.
  • Identify dependencies, subcontractor questions and exit arrangements.
  • Separate unanswered questions from confirmed limitations.
  • Assign the acceptance decision and conditions for revisiting it.

Optional depth: involve the right reviewers

An architect can assess dependencies and technical fit; a security specialist can examine relevant assurance. Procurement and legal advisers should review proposed terms and obligations. If personal information is involved, obtain advice about the applicable privacy situation. The Australian NDB overview does not establish a universal supplier-contract clause or notification deadline. About the Notifiable Data Breaches scheme

Assessment effort should reflect the relationship’s importance. No supplier has been contacted, tested or approved for this article, and the questions do not imply that SeraphCode holds particular certifications or provides the services being evaluated.

  • Configure, integrate or build: choosing the next software step — Evaluate configure, integrate and build options.
  • Cloud versus on-premises responsibilities — Clarify the operating model.
  • Recovery planning and business continuity — Examine recovery dependencies.