The SolarWinds supply chain breach in December 2020 is among the most sophisticated and widespread cyber attacks ever deployed. The attack was estimated to have affected nearly 20,000 customers, including the U.S. Federal Government and high-level organizations in the private sector after attackers mobilized hidden code within SolarWinds products and the company’s Orion platform.
Sending a SolarWinds questionnaire to third-party vendors is now an essential step in vendor due diligence for organizations across multiple industries, including education, technology, finance, and government services. By gaining insight into how a vendor uses SolarWinds application monitoring services and/or was affected by the breach, your organization will better understand a vendor’s overall security posture and commitment to healthy risk hygiene.
Keep reading to discover sample questions your organization can include in its SolarWinds vendor questionnaire.
Learn how UpGuard streamlines the vendor questionnaire process.>
.jpeg)
The SolarWinds Orion Platform is a stack of database management products that allow IT security professionals to track database metrics and manage infrastructure and performance. The stack of applications available from SolarWinds.com includes programs that assist organizations with the following tasks:
Here are several questions your organization can use to build out its own SolarWinds security questionnaire and assess the status of your vendors.
1. Was your organization impacted by the recent SolarWinds Orion malware cyber attack?
2. Has your organization ever run an affected version of a SolarWinds Product?
3. Have you updated the affected SolarWinds products to unaffected versions?
4. Are you aware of any suspicious activity or compromised data related to a SolarWinds incident?
5. Do you partner with any third parties affected by the SolarWinds breach?
6. If yes, please list the vendors below
7. If you do partner with any vendors who were affected by the breach, what level of data is shared with them?
8. How significantly did the SolarWinds attack impact your organization?
9. Did the SolarWinds attack disrupt critical services your organization delivers to clients and partners?
10. Does your organization’s cybersecurity program possess a developed incident response plan?
11. Who is your organization’s point of contact for additional security queries?
12. Has your organization implemented new protections, installed new controls, or updated existing infrastructure to resolve the SolarWinds attack's impact on the business?
13. If your organization has yet to install new controls, has it implemented workaround methods or compensating controls to avoid similar attacks in the future?
UpGuard’s questionnaire library includes a comprehensive SolarWinds vendor questionnaire and other security questionnaires that meet industry standards. Organizations looking to improve their vendor due diligence protocols and develop robust Third-Party Risk Management programs can use UpGuard’s library of questionnaires to identify and mitigate risks throughout the vendor lifecycle.
In addition to its comprehensive library of security questionnaires, UpGuard Vendor Risk also provides organizations access to several other powerful Cyber Vendor Risk Management tools.
Notable features and use cases of UpGuard Vendor Risk include:
Start your UpGuard free trial right now.