A business-critical supplier refuses a security audit and refuses an offboarding clause with teardown evidence — what do you require, and what do you build anyway?
answer
- trade the audit right for a testable clause
- the right to disable beats the right to inspect
- build what needs nobody's consent
- the tunnel expires, not just the contract
- residual risk gets accepted by a name and a date
basics
~20 sRequire what a supplier will actually sign: breach notification to a tested contact, declared flows, and the right to disable. Build default-deny and a tunnel expiry that fails closed. Escalate the residual risk for named acceptance.
solid answer
~50 sAccept first that you will not win an exercisable audit right, and stop spending negotiating capital there. Ask instead for clauses a supplier will sign and you can test: breach notification within a stated time to a named contact you rehearse annually, the specific prefixes and flows the integration uses, and the right to disable the tunnel unilaterally without it counting as a service failure. Then build what needs nobody's consent: a per-partner extranet zone at default-deny, accepted routes limited to the agreed prefixes, and an expiry expressed as configuration rather than a contract date, so a tunnel that nobody renews fails closed. Finally, price the residual risk and take it to the executive who owns the supplier relationship — you cannot cancel them, but you can make someone accept it by name, with a review date.
go deeper
Understand that partner tunnels come from contracts, and that the network team usually inherits an arrangement it did not negotiate and cannot audit.
Be able to describe the controls that do not need the supplier's agreement — default-deny extranet zone, agreed prefixes only, source filtering — and why they matter more than the questionnaire.
Show how you would find and prove decommissioning of an orphaned tunnel: configuration removed, routes withdrawn, policy deleted, credentials revoked, and an alert if it tries to re-establish.
Own the split between what you require contractually, what you build unilaterally and what you escalate for named acceptance with a review date, and be able to argue for the right to disable over the right to audit.
## The constraint is the question A principal-level answer here starts by naming what cannot be changed. The supplier is business-critical, which means security cannot end the relationship. The supplier has refused an audit, which means every statement about their controls is an attestation you can never verify. And they have refused a teardown-evidence clause, which means the end of the contract will not produce proof that the tunnel is gone. Those are three organisational facts. Everything technical follows from them. The wrong answer is to escalate the audit demand until it becomes someone else's problem, or to accept the questionnaire and treat the file as closed. Both are common and both are visible in an interview. ## What to require, chosen for winnability and testability Ask for less, and ask for things you can exercise: - **Breach notification within a stated period to a named human**, with a contact you test once a year. An untested contact is a phone number in a document. - **A declared list of the prefixes, hosts, ports and directions the integration uses.** This is not a security control for them; it is the input to yours, and suppliers usually agree because it is engineering detail rather than an audit. - **The unilateral right to disable the tunnel** for a security reason without it counting as your breach of the SLA. This one clause is worth more than an audit right, because it converts a fight during an incident into an action. - **Notification when their own subcontractors change**, if they are a provider whose tenancy touches other customers. - **An end date on the tunnel**, distinct from the end date of the contract, with a renewal that is an action rather than an assumption. When a clause is refused, record the refusal. A documented refusal is the artefact that lets someone senior make a decision; an undocumented one is just a gap you own quietly. ## What to build regardless, because it needs nobody's consent - **A per-partner extranet zone at default-deny**, permitting only the declared flows in the declared direction, with denies logged. - **Accepted routes limited to the agreed prefixes**, and a source filter on the tunnel interface, so what they can reach is decided by your configuration rather than by their announcements. - **A named internal owner per tunnel** — not a team, a person — recorded next to the configuration, because ownership is what makes the annual review happen. - **The termination expressed as a technical artefact.** This is the heart of the leaf: the tunnel that is still up two years after the contract ended is not a paperwork failure, it is the predictable result of an arrangement whose only expiry lived in a document nobody re-read. Give the tunnel a configured expiry that fails closed: a dated rule that must be actively renewed, a peer certificate whose validity matches the term, a scheduled review that disables on no response. Then monitor for tunnels with no traffic and no owner, because those are the ones already orphaned. ## Proving it is gone If they will not give you teardown evidence, produce your own. Decommissioning is done when: the peer configuration is removed from your terminator, the routes toward that partner are withdrawn, the zone policy is deleted rather than disabled, every credential the supplier held inside your estate is revoked, and an alert exists for the tunnel attempting to re-establish. That last item is the one that catches the mistake, because a tunnel that comes back up after decommissioning means a configuration you did not know about still exists somewhere. ## Then take it to somebody who can accept it The part that makes this a principal question rather than a senior one: after the technical work, a residual risk remains that you cannot engineer away — an unassessed estate with a routed path into yours. Security does not own that decision. Write it in one page: what the supplier does for us, what they can reach, what we could not obtain, what we built instead, what remains, and what it would cost to reduce it further (a second enforcement layer, a broker, moving the integration to a data exchange rather than network reach). Take it to the executive who owns the supplier relationship and ask them to accept it by name, with a review date. That is not paperwork theatre. It puts the decision where the authority and the budget are, it gives you a scheduled reason to revisit an arrangement that would otherwise outlive everyone who understood it, and it means the answer to *who signed for this* is a name rather than a shrug. ## Interview framing Show the three-way split — what you require, what you build without asking, what you escalate for acceptance — and make the offboarding expiry a piece of configuration rather than a clause. A candidate who says the words *the tunnel expires, not just the contract* has understood the leaf.
- How do you find the partner tunnels nobody remembers?Reconcile three lists that are never the same: the tunnels configured on your terminators, the supplier register the business keeps, and observed traffic. The interesting rows are configured tunnels with no register entry, and tunnels carrying no traffic for months with no named owner. Those get an owner or a disable-and-wait, and you keep the reconciliation as a scheduled job rather than a one-off cleanup.
- The business owner accepts the risk and refuses to fund anything further. Is that a failure?No, provided the acceptance is explicit, named, dated and revisited. Your job is to make the risk legible and priced, not to hold a veto you do not have. What would be a failure is an undocumented acceptance, or one with no review date, because the arrangement will outlive both the decision and the people who made it.
- What is the single most valuable clause to fight for if you can only have one?The unilateral right to disable the tunnel for a security reason without it constituting a service failure. It is cheap for the supplier to grant, and during an incident it converts a contractual argument you would lose under time pressure into an action you can simply take.
- Why express the offboarding as configuration rather than relying on the contract end date?Because contract dates are tracked by people who do not touch firewalls, and network configuration has no memory of them. An expiry that fails closed — a dated rule requiring active renewal, a peer certificate matching the term — turns forgetting into a safe outcome instead of a permanent path into your estate from an estate that no longer has any reason to be connected.
saying these in an interview costs you the question
- Insists on an audit right the supplier will never grant and calls that a plan
- Treats a completed questionnaire as closure
- Relies on the contract end date to remove network access
- Accepts residual risk personally instead of escalating it to the owner
- Has no owner recorded per tunnel and no reconciliation against the supplier register
- Disables a decommissioned tunnel instead of removing it, with no alert if it returns