# Dumb security questionnaires

DevFeed: [Dumb security questionnaires](<https://devfeed.tech/articles/dumb-security-questionnaires-29162.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2018/05/04/dumb-security-questionnaires/>)

Published: 2018-05-05T01:46:00Z

Content type: opinion

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [atlassian](<https://devfeed.tech/topics/atlassian.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [atlassian](<https://devfeed.tech/tags/atlassian.md>), [aws](<https://devfeed.tech/tags/aws.md>), [docker](<https://devfeed.tech/tags/docker.md>), [dropbox](<https://devfeed.tech/tags/dropbox.md>), [security](<https://devfeed.tech/tags/security.md>), [twitter](<https://devfeed.tech/tags/twitter.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article argues that security questionnaires are often outdated, performative, and liable to encourage organizations to deploy controls without demonstrating meaningful security value. It criticizes questionnaire practices inherited from older IT security processes and questions whether organizations creating such questionnaires are qualified to evaluate detailed security standards.

## Source excerpt

It's weird to say this but a significant part of the value we provide clients is filling out Dumb Security Questionnaires (hereafter DSQs, since the only thing more irritating than a questionnaire is spelling "questionnaire"). Daniel Meiessler complains about DSQs, arguing that self-assessment is an intrinsically flawed concept. Meh. I have bigger problems with them. First, most DSQs are terrible. We get on calls with prospective clients, tell them "these DSQs were all first written in the early 1990s and lovingly handed down from generation to generation of midwestern IT secops staff. Oh, how clients laugh and laugh. But, not joking. That's really how those DSQs got written.