Security builder & leader

Information Security Assessment RFP Cheat Sheet

Effective security assessment RFPs require understanding what's driving the need, ensuring staff availability, and defining realistic timelines and budgets. Key elements include specifying assessment objectives, expected deliverables, and criteria for vendor selection based on staff expertise and project management capabilities.

Information Security Assessment RFP Cheat Sheet - illustration

This cheat sheet offers tips for planning, issuing and reviewing Request for Proposal (RFP) documents for information security assessments. To print, use the one-sheet PDF version; you can also edit the Word version for you own needs.

Planning the Security Assessment RFP

Supporting the RFP Process

Defining the Assessment’s Details

Distributing the RFP

Selecting the Security Assessment Vendor

Typical Elements of an RFP Document

Definitions

Additional RFP References

Post-Scriptum

Special thanks for feedback to Hana Park and Jefferey Saiger. If you have suggestions for improving this cheat sheet, please let me know. This cheat sheet is distributed according to the Creative Commons v3 “Attribution” License. File version 1.4. Take a look at my other security cheat sheets.

About the Author

Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. Lenny shares his perspectives on security leadership and technology at zeltser.com.

Learn more →