Security Questionnaire
A security questionnaire is a set of questions buyers use to evaluate a vendor's security posture and compliance during procurement.
Definition
A security questionnaire is a structured document containing questions about an organization's security policies, practices, controls, and compliance certifications. Buyers send these to vendors during procurement to assess risk before signing contracts or sharing sensitive data.
Context
Security questionnaires can be buyer-authored or based on published instruments such as SIG, CAIQ, and the Vendor Security Alliance questionnaire. Scope varies by the service, data, integration, buyer risk model, and applicable obligations. A defensible response identifies the exact instrument and version, answers for the product in scope, links claims to current evidence, and records the responsible reviewer.
Why it matters
Questionnaires commonly cover identity, encryption, secure development, vulnerability management, incident response, resilience, privacy, subprocessors, and independent assurance. The answer should state applicable scope and conditions instead of presenting a control as universal across products, regions, or environments.
Reuse creates value only when the prior answer remains supported. Preserve the approved statement, source passage, owner, reviewer, effective version, exceptions, and buyer-specific edits. Re-review when the policy, architecture, audit period, legal commitment, subprocessor set, incident history, or product scope changes.
A questionnaire is one input to a buyer's risk decision, not proof that a vendor is secure. Buyers may validate responses through document review, interviews, technical testing, continuous monitoring, contract terms, or other due-diligence activities. Vendors should avoid unsupported certainty and flag questions whose evidence is incomplete or ambiguous.
Reviewed primary sources
The definition above distinguishes the current publishers and artifacts using these primary sources.