ReadyNine | [email protected] | 500 W. Madison Street, Suite 1000, Chicago, IL 60661 Frameworks/Compliance These questions are designed to ensure your provider can meet your data security and regulatory obligations and that they are compliant themselves. 1. Do you manage your systems following a cybersecurity framework? If the answer is yes, which framework? 2. Do you document your compliance? 3. Is your compliance audited? 4. Are your systems audited for compliance with policies? 5. Can you support governance requirements or cyber insurance obligations?

A CEO's Guide to Choosing an IT Service Provider - Page 7 A CEO's Guide to Choosing an IT Service Provider Page 6 Page 8