Providers by service and requirement
Managed Security Service Provider Capabilities
A capability page pairs one managed security service with one requirement a buyer has to meet, then lists the providers that satisfy both. Use these pages when the service alone is not the question and the contract detail is: a response target written into a service level agreement, a compliance program the engagement has to support, or an attestation report a reviewer will read.
Capability pages
SIEM Providers With a 15-Minute Response SLA for Security Information and Event Management
Compare SIEM management providers that commit to a 15 minute response target, and the contract questions that decide whether the number is real.
Pen Testing Providers With PCI DSS Compliance Support
Compare penetration testing firms that support PCI DSS, and the scope, reporting and retest questions a qualified assessor will ask about the work.
FedRAMP Vulnerability Management Providers for Federal Cloud Programs
Compare vulnerability management providers that support FedRAMP, and the cadence, deviation and monthly package questions that decide operational fit.
IAM Providers With ISO 27001 Certification for Identity and Access Management
Compare identity and access management providers that support ISO 27001, and the scope, leaver handling and access review questions worth asking.
Security Training Providers With HIPAA Compliance Support
Compare security awareness training providers that support HIPAA, and the workforce coverage, simulation and record questions an investigator asks.
Firewall Providers With a SOC 2 Type II Attestation Report
Compare firewall management providers holding a SOC 2 Type II report, and the trust criteria, exception and bridge letter questions that matter.