<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.mozilla.org/index.php?action=history&amp;feed=atom&amp;title=Security%2FProcess%2FVendor_Reviews%2FReview_Questions</id>
	<title>Security/Process/Vendor Reviews/Review Questions - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.mozilla.org/index.php?action=history&amp;feed=atom&amp;title=Security%2FProcess%2FVendor_Reviews%2FReview_Questions"/>
	<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Process/Vendor_Reviews/Review_Questions&amp;action=history"/>
	<updated>2026-04-06T22:30:46Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.10</generator>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Process/Vendor_Reviews/Review_Questions&amp;diff=843058&amp;oldid=prev</id>
		<title>Curtisk: Created page with &quot;=&#039;&#039;&#039;Security Assurance Vendor Review Request&#039;&#039;&#039;= == Review Questions ==  The following basic questions are used to begin the security assessment of a particular vendor that wi...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Process/Vendor_Reviews/Review_Questions&amp;diff=843058&amp;oldid=prev"/>
		<updated>2013-12-31T16:43:24Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;=&amp;#039;&amp;#039;&amp;#039;Security Assurance Vendor Review Request&amp;#039;&amp;#039;&amp;#039;= == Review Questions ==  The following basic questions are used to begin the security assessment of a particular vendor that wi...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=&amp;#039;&amp;#039;&amp;#039;Security Assurance Vendor Review Request&amp;#039;&amp;#039;&amp;#039;=&lt;br /&gt;
== Review Questions ==&lt;br /&gt;
&lt;br /&gt;
The following basic questions are used to begin the security assessment of a particular vendor that will interact with Mozilla.&lt;br /&gt;
&lt;br /&gt;
#Overall&lt;br /&gt;
#*Please describe the overall purpose of the system and how Mozilla data will be integrated&lt;br /&gt;
#Security Management&lt;br /&gt;
#*Have you performed internal security audits of your code or application that, at a minimum, addressed the OWASP Top 10? If so, please provide a description of the review and results.&lt;br /&gt;
#*Has a security audit been performed by an external third party? If so, who performed this audit and are the results available?&lt;br /&gt;
#*How do you protect Mozilla data that will be stored on your servers or within your applications?&lt;br /&gt;
#*How do you prevent other customers of your service from obtaining access to data provided by Mozilla?&lt;br /&gt;
#*What is your disclosure policy to customers in the event of a compromise of your servers, applications or any related infrastructure that interacts with the applications holding Mozilla data?&lt;br /&gt;
#*Have you suffered a security compromise in the past 24 months? If so, please provide details and remediation that occurred as a result.&lt;br /&gt;
#*What other large engagements/clients have you supported with this application?&lt;br /&gt;
#Technical Design&lt;br /&gt;
#*Do you support full SSL communication for all inbound and outbound communications?&lt;br /&gt;
#*Describe the technology stack of the application and infrastructure.&lt;br /&gt;
#*What options do your support for authentication?&lt;br /&gt;
#**username/password&lt;br /&gt;
#**certificate based authentication&lt;br /&gt;
#**secret token&lt;br /&gt;
#*Are authentication secrets (e.g. passwords) stored in a non-reversible form within your database (e.g. hashing)?&lt;br /&gt;
#* What type of hashing algorithm do you use (e.g. sha512, md5, bcrypt)?&lt;br /&gt;
#* Are salts added to the hashing algorithm which are unique for each user? &lt;br /&gt;
#* Will user passwords (or authentication secrets) be available to any other users via any functionality (example, admin users can see clear text passwords of users)?&lt;br /&gt;
#*Do you use third party servers or do you host the servers yourself?&lt;br /&gt;
#*Do you use any third party services or communicate with any third parties from this application?&lt;br /&gt;
#Security Verification&lt;br /&gt;
#*Will testing of the running application be possible?&lt;br /&gt;
#*Will source code for their application be available?&lt;br /&gt;
#*Do you have attestation reports from any other vendors regarding your security posture?&lt;br /&gt;
#*Do you have any other security certifications that may be relevant?&lt;/div&gt;</summary>
		<author><name>Curtisk</name></author>
	</entry>
</feed>