[Cross-posted on the Google Open Source Blog]
At Google, we assess the security of hundreds of vendors every year. We scale our efforts through automating much of the initial information gathering and triage portions of the vendor review process. To do this we’ve developed the Vendor Security Assessment Questionnaire (VSAQ), a collection of self-adapting questionnaires for evaluating multiple aspects of a vendor’s security and privacy posture.
We’ve received feedback from many vendors who completed the questionnaires. Most vendors found them intuitive and flexible — and, even better, they’ve been able to use the embedded tips and recommendations to improve their security posture. Some also expressed interest in using the questionnaires to assess their own suppliers.
Based on this positive response, we’ve decided to open source the VSAQ Framework (Apache License Version 2) and the generally applicable parts of our questionnaires on GitHub: https://github.com/google/vsaq. We hope it will help companies spin up, or further improve their own vendor security programs. We also hope the base questionnaires can serve as a self-assessment tool for security-conscious companies and developers looking to improve their security posture.
The VSAQ Framework comes with four security questionnaire templates that can be used with the VSAQ rendering engine:
- Web Application Security Questionnaire
- Security & Privacy Program Questionnaire
- Infrastructure Security Questionnaire
- Physical & Data Center Security Questionnaire