I have been answering quite a few security assessment RFP’s lately, most specifically geared towards penetration testing of the external and internal environment (you guessed it – PCI).  And what I have noticed is that the writers of the RFP typically do not include enough detail in the RFP for the organizations attempting to answer […] ↓ Read the rest of this entry…