A SaaS vendor that hosts the city’s permit portal sends its own penetration-test report as proof of security. What is the most appropriate way for the city to treat that evidence?
Select an answer to reveal the explanation.
Short Explanation
Vendor-run tests are like a restaurant grading its own kitchen—helpful, but not the whole story. Use the report, then check who tested what, how independent they were, and whether fixes actually landed.
Full Explanation
Vendor-supplied penetration testing can inform third-party risk decisions, but it is not blind trust. Buyers should review engagement scope, tester independence, residual findings, and evidence of remediation rather than treating a self-provided report as conclusive assurance. Verification may include independent testing, questionnaires, or follow-up on critical issues tied to the city’s data and systems.