You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@nifi.apache.org by Niamh Barrett <ba...@lilly.com.INVALID> on 2023/11/28 15:05:26 UTC

RE: [EXTERNAL] Re: Third Party Questionnaire For Apache NiFi

Hello Arnout

I hope you are well.

My name is Niamh Barrett and I am the Risk Assessor for this engagement.

I am reaching out to discuss the completion of an offline Third Part Questionnaire (TPQ) which is attached to this email.

Please note we do not require you to answer the full TPQ , we require you to answer the questions in the sub section called Software Development Engineering Methodology (these are in rows 99 to 115).

Please note for the other questions not in the above listed sub section you can answer N/A or No to these, if you feel a question is relevant to you please feel free to provide  additional information.

I look forward to hearing from you.

Kind Regards


Niamh Barrett
TPRM Risk Assessor
Eli Lilly Cork Ltd – Global Business Solutions Centre
Island House, Eastgate Road, Eastgate Business Park, Little Island, Co. Cork.
barrett_niamh@lilly.com|<mailto:barrett_niamh@lilly.com%7C> www.lilly.ie<https://urldefense.com/v3/__http:/www.lilly.ie/__;!!HFNCLZ7U!xi6H0ZtHdj1NQKgbc9FL3MyjmUw_m8IwjJkhPHhZMAgtwu30Yi71Dl8tCMmN-w$>










From: Ketan Pradeep Dessai <ke...@lilly.com>
Sent: Tuesday, November 28, 2023 9:53 AM
To: engelen@gsuite.cloud.apache.org; Apache Security Team <se...@apache.org>; apache@apache.org; security@nifi.apache.org
Cc: David Adeleke <ad...@lilly.com>; Niamh Barrett <ba...@lilly.com>; dev@nifi.apache.org
Subject: RE: [EXTERNAL] Re: Third Party Questionnaire For Apache NiFi

Hello Arnout,

In lieu of our conversation I’m looping my colleagues Niamh & David to this conversation, they are from the Third Party Engagement team. Since online questionnaire was not of interest, will you or the team be willing to help with some responses over this thread? We’d really appreciate it, as it would help us get through this formal process and on our way.

Niamh will be responding to this note shortly with more information.

Best Regards,
Ketan Dessai
Technical Lead Observability
Hosting & Cloud Services
Eli Lilly and Company
ketan_dessai@lilly.com<ma...@lilly.com> | www.lilly.com<http://www.lilly.com/>
[ogo_EmailSig2.jpg][cid:image002.png@01DA220B.44B63F30][About me - Dauren's personal blog]

From: Ketan Pradeep Dessai
Sent: Thursday, November 23, 2023 5:04 PM
To: 'Apache Security Team' <se...@apache.org>>
Cc: 'apache@apache.org' <ap...@apache.org>>
Subject: RE: [EXTERNAL] Re: Third Party Questionnaire For Apache NiFi

Thank you Arnout for taking the time to respond, Appreciate it! I will try to work with our third party team to sort this out .

PS : The email if received would contain subject as “ Action Required : Third Party Questionnaire Request”

Best Regards,
Ketan Dessai
Technical Lead Observability
Hosting & Cloud Services
Eli Lilly and Company
ketan_dessai@lilly.com<ma...@lilly.com> | www.lilly.com<http://www.lilly.com/>
[ogo_EmailSig2.jpg][cid:image002.png@01DA220B.44B63F30][About me - Dauren's personal blog]

From: engelen@gsuite.cloud.apache.org<ma...@gsuite.cloud.apache.org> <en...@gsuite.cloud.apache.org>> On Behalf Of Apache Security Team
Sent: Thursday, November 23, 2023 4:09 PM
To: Ketan Pradeep Dessai <ke...@lilly.com>>
Subject: [EXTERNAL] Re: Third Party Questionnaire For Apache NiFi

EXTERNAL EMAIL: Use caution before replying, clicking links, and opening attachments.

Hello Ketan,

Thank you for the heads-up. We have not yet received such an email referencing Eli Lilly. However, even if we did, we would likely not participate in it: all information required to verify whether NiFi meets your needs should already be part of the public project information.


Kind regards,

Arnout Engelen
ASF Security

On Fri, Nov 17, 2023 at 12:23 PM Ketan Pradeep Dessai via security <se...@apache.org>> wrote:
Hi Apache Team,

We at Eli Lilly have considered and evaluated to use Apache NiFi as data streaming and processing tool for one of our log management use cases. In doing  so we are required to complete a working with third party assessment for which you would have received an email . Kindly provide your valuable feedback on the assessment so that we can qualify and continue to use this amazing product to meet our data streaming and observability needs.

PS: Please check spam if the email wasn’t routed to the inbox . Expect an email from Eli Lilly Cork Ltd.

Best Regards,
Ketan Dessai
Technical Lead Observability
Hosting & Cloud Services
Eli Lilly and Company
ketan_dessai@lilly.com<ma...@lilly.com> | www.lilly.com<https://nam12.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.lilly.com%2F&data=05%7C01%7Cketan_dessai%40lilly.com%7Cdeaae563a8644bf5323308dbec1069d4%7C18a59a81eea84c30948ad8824cdc2580%7C0%7C0%7C638363327479294516%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=1IiwXGvQXSKyP%2B1L6Fm9DR6hv7SZbljMi8L9ExRMw20%3D&reserved=0>
[ogo_EmailSig2.jpg][cid:image002.png@01DA220B.44B63F30][About me - Dauren's personal blog]