<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDQ Archives - Jay Longley</title>
	<atom:link href="https://jaylongley.com/tag/ddq/feed/" rel="self" type="application/rss+xml" />
	<link>https://jaylongley.com/tag/ddq/</link>
	<description>Innovator, Technologist &#38; Aviator</description>
	<lastBuildDate>Thu, 28 Mar 2024 20:32:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://jaylongley.com/wp-content/uploads/2022/09/cropped-skull01-32x32.jpg</url>
	<title>DDQ Archives - Jay Longley</title>
	<link>https://jaylongley.com/tag/ddq/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Due Diligence Questionnaire &#8211; Cybersecurity</title>
		<link>https://jaylongley.com/due-diligence-questionnaire-cybersecurity/</link>
		
		<dc:creator><![CDATA[Jay]]></dc:creator>
		<pubDate>Wed, 31 May 2023 01:19:49 +0000</pubDate>
				<category><![CDATA[CISO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[DDQ]]></category>
		<category><![CDATA[Due Diligence Questionnaire]]></category>
		<category><![CDATA[Questionnaire]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<guid isPermaLink="false">https://jaylongley.com/?p=842</guid>

					<description><![CDATA[<p>Below you will find a simplified due diligence questionnaire focusing on cybersecurity....</p>
<p>The post <a href="https://jaylongley.com/due-diligence-questionnaire-cybersecurity/">Due Diligence Questionnaire &#8211; Cybersecurity</a> appeared first on <a href="https://jaylongley.com">Jay Longley</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2>Introduction</h2>
<p>Below you will find a simplified due diligence questionnaire focusing on cybersecurity.  While I personally recommend using a framework such as the <a href="https://sharedassessments.org/sig/">Standard Information Gathering Assessment</a>, not all need something that comprehensive.</p>



<h4>Due Diligence Questionnaire</h4>
<p>1. Do you have a documented cybersecurity policy in place?<br>2. Are there designated personnel responsible for cybersecurity within your organization?<br>3. How do you identify and assess cybersecurity risks?<br>4. Do you have a process for regularly updating and patching software and systems?<br>5. How do you protect your network and systems from unauthorized access?<br>6. Have you implemented multi-factor authentication for accessing sensitive systems and data?<br>7. How do you manage and protect user accounts and access privileges?<br>8. Do you conduct regular security awareness training for employees?<br>9. How do you monitor and detect cybersecurity incidents or breaches?<br>10. Do you have an incident response plan in place? If so, how often is it tested?<br>11. Have you experienced any significant cybersecurity incidents in the past? If so, how were they addressed?<br>12. How do you secure sensitive data and ensure its confidentiality?<br>13. Do you encrypt data in transit and at rest?<br>14. Are your systems and applications regularly scanned for vulnerabilities?<br>15. How do you protect against malware, including ransomware?<br>16. Do you have intrusion detection and prevention systems in place?<br>17. Have you implemented secure coding practices for your software development processes?<br>18. Do you perform regular penetration testing to identify vulnerabilities?<br>19. How do you ensure third-party vendors or partners adhere to your cybersecurity requirements?<br>20. Do you comply with relevant cybersecurity standards and regulations, such as GDPR or HIPAA?</p>



<p>To create a customized Due Diligence Questionnaire / DDQ for your organization, you can copy and modify the above code, or you can contact me for assistance in creating a comprehensive questionnaire.</p>



<p>For more CISO Articles, please see:<br><a href="https://jaylongley.com/category/ciso/" target="_blank" rel="noreferrer noopener">https://jaylongley.com/category/ciso/</a></p>
<p>The post <a href="https://jaylongley.com/due-diligence-questionnaire-cybersecurity/">Due Diligence Questionnaire &#8211; Cybersecurity</a> appeared first on <a href="https://jaylongley.com">Jay Longley</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
