Security questionnaire
The long vendor-risk form an enterprise buyer sends to check your security controls before it purchases or shares data.
What it is
A security questionnaire is the buyer's due-diligence form for a vendor that will touch its systems or data. It asks how the vendor handles access, encryption, development, vulnerabilities, incidents, continuity, privacy, subprocessors, and dozens of other risks. Some buyers use standard sets such as Shared Assessments SIG or the Cloud Security Alliance CAIQ; many send a custom spreadsheet.
Reach for a maintained answer library before enterprise sales begins. Each answer needs a control owner, approved wording, scope, evidence, and review date. Reuse is valuable, but the final response still has to match the product, hosting model, and data flow in the deal being assessed.
Gotcha: confident absolutes create contract trouble. 'All data is always encrypted' may be false for a support export or an old backup, and a copied 'yes' can become a promise the company cannot prove. Answer the question asked, state scope and exceptions plainly, and route legal, privacy, and security claims to their actual owners.
Ask AI for it
Create a reusable security-questionnaire response pack based on Shared Assessments SIG Lite and the Cloud Security Alliance CAIQ. Cover governance, identity and access, encryption, secure development, vulnerability management, logging, incident response, resilience, privacy, data deletion, subprocessors, and physical security. For every question, provide a direct answer, product scope, control owner, evidence link, last-reviewed date, reviewer, and approved exception language. Cross-reference AWS Artifact reports, Okta access-review records, GitHub branch-protection settings, and Jira remediation tickets. Mark unknowns as assigned follow-ups with deadlines, never as guessed yes answers.