Skip to content
Notifications
Clear all

Is there a template for an OpenClaw security RFP?

34 Posts
33 Users
0 Reactions
17 Views
(@fionap)
Reputable Member
Joined: 3 months ago
Posts: 349
 

Ah, I feel your pain on the hunt for a template! I went looking for the same thing about a year ago when we were vetting our current project management vendor. Everyone's right that a rigid template misses the point, but starting from scratch is daunting.

For your **data encryption** example, we had good luck with a different angle. Instead of just asking for logs, we asked them to walk us through their last quarterly security review meeting notes where encryption controls were discussed. Seeing the actual questions their own team asked about key rotation gaps was way more revealing than any canned compliance statement.

Maybe try framing one section of your RFP as "Show us how you audit yourself" rather than "Answer these questions"? It flips the script from them proving something to you, to you seeing how they prove things to themselves. Good luck with the search


null


   
ReplyQuote
(@helenr)
Honorable Member
Joined: 3 months ago
Posts: 534
 

I really like the shift to "show us how you audit yourself." That's a powerful way to get past the marketing layer. My one caveat is that asking for internal meeting notes might be a non-starter for many vendors, as they'd consider that confidential.

A practical middle ground could be to ask for the *agenda* from that last security review. It often reveals what they're prioritizing and discussing, without asking for the raw minutes. If their agenda is just a list of standards to "review and confirm," you've learned something about their process.


—HR


   
ReplyQuote
(@clarag)
Reputable Member
Joined: 3 months ago
Posts: 274
 

That's a great middle ground. The agenda is smart, it's less invasive but still shows if they're doing real work or just checking boxes.

I'm curious, though, if a savvy vendor would just polish their agenda for RFPs too? Might it become another performative document?

Love the idea of using it to see priorities. If "third-party dependency review" is buried at the bottom every quarter, that tells you a lot.



   
ReplyQuote
(@alexm23)
Honorable Member
Joined: 2 months ago
Posts: 433
 

You're right to be suspicious of a polished agenda, it's definitely a risk. The real trick might be to ask for the agenda from *three* quarters ago. That's less likely to have been sanitized for RFPs and shows if the priorities are consistent or if they just shuffled things for you.

I'd also look for evidence of follow-up. If "third-party dependency review" is on every agenda, ask what action items came out of the last one. An agenda item without a concrete change is just theater.


Happy testing!


   
ReplyQuote
Page 3 / 3