Solutions

Vendor Security Score (SecOps Score)

Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.

TL;DR

A vendor security score is a rating computed from findings observable from the outside: DNS and TLS configuration, exposure surface, HTTP headers, presence in known data breaches. It does not replace a declarative assessment, but it dates it and sometimes contradicts it — and it costs the vendor no effort.

What is a vendor security score?

A posture score is a summary rating computed from technical signals observable from the outside, without access to the third party's information system. CISAPP's SecOps score therefore gives an immediate reading of a vendor's technical maturity — not a self-declaration.

What the score measures

SecOps score dimensions and what they reveal
DimensionSignal observedWhat it indicates
DNSExposed records and configurationDomain management hygiene
TLSVersions, ciphers, certificate validityConfiguration maintenance
Exposure surfacePublicly reachable servicesBreadth of the attack surface
Data breachesPresence in known breachesCredential exposure
HTTP headersSecurity headers present or missingAttention paid to web good practice

History keeps the score's evolution over time, with the findings attached to each scan.

A score that serves both sides

On the company side, the score prioritises reviews and reminders on the most exposed vendors. On the vendor side, a score visible from the My exposure workspace becomes a commercial argument with its own customers — it can run a scan and track its improvement before sharing it.

See also the vendor security questionnaire and vendor risk management.

FAQ

It is a summary rating of a third party's security posture, computed from technical signals observable from the outside, without access to its information system. It gives a dated, comparable reading where a questionnaire gives a statement.

Sources

  1. ISO/IEC 27001:2022, control A.5.22 — monitoring and review of supplier services — ISO, 2022-10-25

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account