LASSX
Aegis Defense Systems — Production
Demo retrieval
Sources

Vendor Security Questionnaire

Baseline questionnaire for suppliers with system or data access

Indexed
pdf
Vendor & Subcontractor
Updated Jul 28

Chunks (2)

Minimum security controls for subcontractors

~86 tok

Minimum security controls for subcontractors with CUI or system access include: documented information security policy; MFA for remote and privileged access; encrypted data in transit (TLS 1.2+) and at rest; vulnerability management with critical patch SLAs of 15 days; incident notification to Aegis within 24 hours of confirmed incidents; and willingness to flow down DFARS 252.204-7012 / CMMC obligations. Subcontractors without these controls cannot process CUI.

Evidence requirements

~36 tok

Vendors provide SOC 2 Type II or equivalent, penetration test summary (within 12 months), and a data flow diagram. Residual risks are accepted only by the CISO.