Security questionnaire guide
Learn how buyer assessments differ, what evidence reviewers expect, and how responses move through review.
Plain-language definitions for RFP security questions, questionnaire standards, DDQs, vendor risk, trust centers, security controls, and compliance frameworks. Every entry links to related terms and practical guidance.
An RFP evaluates overall solution, delivery, and commercial fit. A security questionnaire focuses on security, privacy, resilience, and compliance controls. Buyers may attach a security questionnaire to an RFP or send it later in due diligence. Keep shared company facts consistent, but route security claims and evidence through the designated control owners and reviewers.
The terms overlap in real procurements, but the decision owners and evidence requirements differ. Use the table below to identify the instrument before reusing prior answers.
| Instrument | Primary purpose | Typical source |
|---|---|---|
| RFP | Compare solution, implementation, service, and commercial fit. | Buyer-authored procurement document |
| Security questionnaire | Assess security, privacy, resilience, and compliance controls. | Buyer-authored or standardized assessment |
| SIG | Standardize broad third-party risk assessment and scoping. | Shared Assessments |
| CAIQ | Assess cloud controls using questions aligned to the Cloud Controls Matrix. | Cloud Security Alliance |
| VSAQ | Review vendor security and privacy using the VSA-Full or VSA-Core instrument. | Vendor Security Alliance |
Definitions include operational context, related controls, and links to deeper guides.
AI hallucination is when a model generates plausible but factually wrong output — a critical risk that evidence-backed questionnaire automation prevents.
An audit trail is a chronological record of system activities providing documentary evidence for compliance and security questionnaire verification.
A BAA is the HIPAA-required contract governing how a vendor handles protected health information. Covered entities must sign one with every vendor touching PHI.
A business continuity plan outlines how an organization continues operations during and after a disruption, commonly evaluated in vendor security reviews.
BYOK AI allows customers to supply their own API keys for AI services, ensuring data never passes through the vendor's AI infrastructure.
CAIQ is a cloud security questionnaire developed by the Cloud Security Alliance (CSA) to evaluate cloud service providers against the CSA Cloud Controls Matrix.
The CSA Cloud Controls Matrix is a cloud security and privacy control framework; CCM v4.1 contains 207 controls across 17 domains and accompanies CAIQ.
A compliance pack is a curated bundle of security docs delivered to buyers during procurement: SOC 2, policies, certifications, and pen test summaries.
A DPA is a contract that governs how a vendor processes personal data on behalf of a customer. GDPR-focused security reviews require one.
Data residency refers to the geographic location where data is stored and processed, a critical concern in security questionnaires for regulated industries.
An evidence library is a centralized repository of approved security docs, policies, and prior responses used as source material for questionnaire answers.
FedRAMP (Federal Risk and Authorization Management Program) is the US government program that standardizes security assessment for federal cloud services.
GDPR (General Data Protection Regulation) is the EU law governing personal data protection, with major implications for vendor security reviews and DDQs.
GRC (Governance, Risk, and Compliance) is an integrated framework for managing governance structures, enterprise risk, and regulatory compliance.
HIPAA (Health Insurance Portability and Accountability Act) establishes standards for protecting sensitive patient health information in the United States.
Incident response is the organized approach to addressing and managing security breaches and cyberattacks, frequently evaluated in buyer questionnaires.
ISO 27001 is the international standard for information security management systems (ISMS), specifying how to establish, implement, and maintain controls.
MFA requires users to verify identity with two or more factors and is one of the most common control checks in enterprise security questionnaires.
An NDA is a legal agreement gating access to sensitive compliance docs. Buyers sign NDAs before viewing SOC 2 reports, pen tests, and security architecture.
The NIST Cybersecurity Framework (CSF) is a set of standards for managing cybersecurity risk. Organizations of all sizes adopt it voluntarily.
PCI DSS is a security standard for organizations that handle credit card data. It mandates specific controls for cardholder data protection.
Penetration testing is authorized simulated attack used to evaluate system security. Pen test results are common evidence in security questionnaires.
A procurement portal is a dedicated workspace where vendors deliver curated security documentation, compliance packs, and follow-up materials to buyers.
RBAC is an access control method that assigns permissions based on user roles, commonly asked about in security questionnaires and compliance reviews.
A security questionnaire is a set of questions buyers use to evaluate a vendor's security posture and compliance during procurement.
Security questionnaire automation structures intake, evidence retrieval, reviewable drafts, ownership, exceptions, approvals, and buyer-ready delivery.
The shared responsibility model defines which security controls the cloud provider owns versus the customer — referenced often in cloud security reviews.
The Shared Assessments SIG is a standardized questionnaire for evaluating third-party technology, security, privacy, resilience, and operational risk.
An SLA is a formal agreement defining service commitments — uptime guarantees, response times, support levels — commonly evaluated in vendor security reviews.
SOC 2 is an AICPA audit framework evaluating service organizations on five Trust Services Criteria covering security, availability, integrity, and privacy.
SSO allows users to authenticate once to access multiple applications. It is a frequently required capability in enterprise security questionnaires.
A subprocessor is a third party that processes personal data on behalf of a data processor. Security reviews require vendors to disclose all subprocessors.
Third-party risk management (TPRM) is the discipline of identifying, assessing, and mitigating risks from external vendors, suppliers, and service providers.
A trust center is a public-facing web page where vendors publish their security posture, compliance certifications, and documentation for buyers.
A vendor risk assessment evaluates a third-party vendor's security, compliance, and operational risks before and during the business relationship.
Vendor risk scoring assigns numerical risk ratings to vendors based on questionnaire responses, compliance documentation, and external threat intelligence.
A vendor security review is the end-to-end process where a buyer assesses a vendor's security posture via questionnaires, documentation, and risk scoring.
VSAQ commonly refers to the Vendor Security Alliance questionnaire, available as VSA-Full and VSA-Core for standardized vendor security reviews.
Zero Trust is a security model requiring strict identity verification for every user and device, increasingly referenced in enterprise security questionnaires.
Learn how buyer assessments differ, what evidence reviewers expect, and how responses move through review.
Compare vendor, investment, regulatory, and transaction DDQs without treating them as one format.
Review cloud, identity, API, resilience, privacy, and evidence questions used in SaaS procurement.
Evaluate access controls, evidence currency, ownership, buyer workflow, and measurable outcomes.
Definitions were checked against the publishers below. Framework versions, licensing, and access terms can change, so confirm the current source before issuing or answering an assessment.