-

Whistic Announces Support of Google’s Minimum Viable Secure Product Framework

Support for recently introduced security baseline helps vendors streamline security reviews for customers

SALT LAKE CITY--(BUSINESS WIRE)--Today, Whistic, the proactive vendor security network for both buyers and sellers, announced support for the Minimum Viable Secure Product (MVSP) framework, a security baseline developed by Google in a collaborative effort with Okta, Slack, and Salesforce.

Until the introduction of MVSP, there was no commonly accepted baseline available among security professionals that indicated the importance of security controls. With MVSP, vendors can demonstrate to their customers that they are meeting, at a minimum, the baseline of security as outlined by some of the industry’s top security professionals.

“We believe a vendor-neutral security baseline is an important step in establishing minimum acceptable security requirements for enterprise software and services,” says Chris John Riley, Senior Security Engineer at Google. “By assuring enterprise solutions include the core security building blocks, we can work to reduce third-party risk, and promote security as a key part of the product development lifecycle.”

Vendors that utilize Whistic to share security documentation via the MVSP help streamline and accelerate the security review process for their customers, helping them to rapidly understand the vendor’s security posture.

“Enabling companies to showcase their security posture using the MVSP and other industry frameworks is a key step toward ensuring transparent relationships between vendors and their customers,” stated Nick Sorensen, Whistic CEO. “In addition to announcing support of MVSP, we recently launched Whistic Basic Profile that enables any business regardless of size to proactively share their security posture with customers and publish it to the Whistic Vendor Security Network for free.”

Basic Profile allows vendors to self-assess against industry standard frameworks, including MVSP. It also includes a limited number of Profile shares, and the ability to publish to the Whistic Trust Catalog, enabling Whistic customers to conduct Zero-Touch Assessments of the vendor’s security posture.

“Okta has already added MVSP to our Whistic Profile and we look forward to seeing more and more of our vendors adopt this baseline in their Profiles,” said Gen Buckley, Director, Customer Assurance Customer Trust at Okta Security and founding committee member of MVSP. “We are always looking for ways to streamline our vendor security reviews and drive a more secure ecosystem, and MVSP helps accomplish that while also promoting transparency and collaboration between vendors and customers.”

Marat Vyshegorodtsev, Enterprise Security JAPAC representative at Salesforce adds, “Organizations of all sizes often purchase dozens of software products managed by third parties. The onboarding process alone can take weeks or months, especially when it comes to vetting the security posture for each. MVSP helps solve this—it standardizes this process and eliminates overhead, complexity, and confusion for both parties while ensuring the minimum-security requirements.”

To learn more about Whistic’s support of the MVSP framework and Basic Profile, visit basic-profile.whistic.com.

About Whistic

Located in the heart of the Silicon Slopes in Utah, Whistic is the network for assessing, publishing, and sharing vendor security information. The Whistic Vendor Security Network accelerates the vendor assessment process by enabling businesses to access and evaluate a vendor’s Whistic Profile and create trusted connections that last well beyond the initial assessment. Make security your competitive advantage and join businesses like Airbnb, Okta, Betterment, and Atlassian who are leveraging Whistic to modernize their vendor security programs. For more information, visit Whistic.com.

Contacts

PR Contacts:
Cheryl Conner or Paul Murphy
SnappConner PR
801-806-0150
info@snappconner.com

Whistic


Release Versions

Contacts

PR Contacts:
Cheryl Conner or Paul Murphy
SnappConner PR
801-806-0150
info@snappconner.com

More News From Whistic

Whistic Drives Proactive Vendor Security Through the Whistic Trust Catalog in Partnership with Google Cloud

SALT LAKE CITY--(BUSINESS WIRE)--Whistic, the network for assessing, publishing and sharing vendor security information, today announced a collaboration with Google Cloud to provide customers with a transparent security profile, which includes a full Google Cloud Assessment Report. Google Cloud customers can now leverage Whistic’s Trust Catalog to view the latest security information. More organizations are undergoing digital transformation initiatives and migrating to cloud service providers s...

Whistic Wins Awards for Best Cyber Security Risk Management Solution and Best Place to Work for in Utah

SALT LAKE CITY--(BUSINESS WIRE)--Whistic, the network for assessing, publishing and sharing vendor security information, is being honored this month for the value and effectiveness of its vendor security risk management solution and as one of the Best Places to Work for in Utah. American Security Today acknowledged Whistic on November 16 with its Platinum Homeland Security Award for Best Cyber Security Risk Management Solution. Utah Business also named Whistic to its roster of Best Places to Wo...

Whistic Integrates the 2023 Shared Assessments (SIG) Questionnaire into Vendor Security Network

SALT LAKE CITY--(BUSINESS WIRE)--Whistic, the leading vendor security network for both buyers and sellers, today announced the release of the Shared Assessments 2023 Standardized Information Gathering (SIG) Questionnaire for users of the Whistic Assess and Whistic Profile product offerings. The 2023 SIG assimilates third-party risk assessments by providing a database of predictable, standardized questions organized by risk control domains, mapping reference and risk control categories. “Whistic...
Back to Newsroom