Our payment page has 23 third party scripts on it. how do people manage 6.4.3 at this scale?

Audit found 23 scripts running on our payment page, many we didn't know about. 6.4.3 needs integrity monitoring on all of them. Feels impossible manually. Any method or tools to handle this?

reddit.com
u/Dull_Appearance_1828 — 4 days ago
▲ 1 r/gdpr

No visibility into what our third party scripts are actually transmitting. How are you handling this for GDPR?

We load about 12 third party tools on our site, analytics, heatmaps, chat widget. Just realised we have no visibility into what data they're actually transmitting. How are people handling this for GDPR?

reddit.com
u/Dull_Appearance_1828 — 5 days ago

For those doing third-party risk assessments, how do you handle SaaS vendors that refuse to provide a recent SOC 2 report?

Do you usually accept an ISO 27001 certificate / security questionnaire instead, or treat the lack of SOC 2 evidence as a red flag?

What actual thresholds do you use?

reddit.com
u/Dull_Appearance_1828 — 6 days ago