How to Respond to a Client Security Questionnaire – Supplier/Client Audit Cycle
ABC Small / Medium Service Pvt. Ltd. is an existing ISO/IEC 27001-certified company and a customer sends a security questionnaire as part of its supplier/client audit cycle.
| Section | Sr. No. | Customer Question | Suggested Response | Evidence | Owner | ISO 27001 Reference |
|---|---|---|---|---|---|---|
| 1. Company & ISMS | 1 | Is your organization ISO 27001 certified? | Yes. ABC maintains an ISO/IEC 27001-certified ISMS. | ISO Certificate | ISMS Manager | Clause 4–10 |
| 2 | Provide your ISO certificate. | Provide current certificate, scope and validity. | ISO Certificate | ISMS Manager | Clause 4.3 | |
| 3 | What is the scope of certification? | State the exact scope from the certificate. | Certificate / Scope Document | ISMS Manager | Clause 4.3 | |
| 4 | Is the certificate issued by an accredited certification body? | Yes, if applicable. Provide certification-body details. | Certificate / Accreditation Details | ISMS Manager | Clause 9.2 | |
| 5 | Do you conduct internal audits? | Yes. Internal audits are conducted as part of the ISMS audit programme. | Audit Plan / Audit Report | Internal Auditor | Clause 9.2 | |
| 6 | Do you conduct management reviews? | Yes. Management reviews are performed periodically. | Management Review Minutes | Top Management | Clause 9.3 | |
| 7 | Do you maintain a risk assessment process? | Yes. Information-security risks are identified, assessed, treated and reviewed. | Risk Assessment / Risk Register | Risk Manager | Clauses 6.1.2, 6.1.3 | |
| 8 | Do you maintain a Statement of Applicability? | Yes. The SoA is maintained and reviewed as part of the ISMS. | Statement of Applicability | ISMS Manager | Clause 6.1.3(d) | |
| 2. Information Security Governance | 9 | Do you have an information security policy? | Yes. An approved Information Security Policy is maintained and communicated. | Information Security Policy | ISMS Manager | A.5.1 |
| 10 | Who is responsible for information security? | Information-security responsibilities are formally assigned. | Organization Chart / RACI | Management / ISMS Manager | A.5.2 | |
| 11 | Are security responsibilities documented? | Yes. Roles and responsibilities are formally defined. | RACI / Job Descriptions | HR / ISMS | A.5.2 | |
| 12 | Do you have security objectives? | Yes. Information-security objectives are established, monitored and reviewed. | Security Objectives / KPI | ISMS Manager | Clause 6.2 | |
| 13 | How are security incidents managed? | Through a documented incident-management process covering reporting, response and closure. | Incident Procedure / Register | CISO / IT Security | A.5.24–A.5.28 | |
| 3. Personnel Security | 14 | Are background checks performed? | Background verification is performed for applicable employees/roles. | BGV Policy / Records | HR | A.6.1 |
| 15 | Do employees sign confidentiality agreements? | Yes, where applicable. | NDA / Employment Agreement | HR / Legal | A.6.6 | |
| 16 | Is security awareness training provided? | Yes. Security-awareness training is provided during onboarding and periodically. | Training Records / Material | HR / ISMS | A.6.3 | |
| 17 | Are employees trained on phishing/security threats? | Yes. Training covers relevant cybersecurity threats and safe practices. | Awareness / Phishing Training Records | IT Security / HR | A.6.3 | |
| 18 | Is access removed when an employee leaves? | Yes. Access revocation is part of the offboarding process. | Exit Checklist / Access Revocation | HR / IT | A.6.5 | |
| 19 | Is there a disciplinary process for security violations? | Yes. Violations are handled through the disciplinary process. | Disciplinary Policy | HR | A.6.4 | |
| 4. Access Control | 20 | Do you have access-control policies? | Yes. Access is governed through documented requirements. | Access Control Policy | IT / ISMS | A.5.15 |
| 21 | Is least privilege implemented? | Yes. Access is provisioned according to role and business need. | Access Matrix | IT Manager | A.5.15, A.8.2 | |
| 22 | Are privileged accounts restricted? | Yes. Privileged access is restricted to authorized personnel. | Privileged Account List | IT Security | A.8.2 | |
| 23 | Are user access reviews performed? | Yes. Access rights are periodically reviewed. | Access Review Records | IT / Application Owner | A.5.18 | |
| 24 | Is MFA implemented? | MFA is implemented for applicable systems and accounts. | MFA Configuration / Screenshot | IT Security | A.5.17, A.8.5 | |
| 25 | Are shared accounts permitted? | Shared accounts are restricted except where specifically justified and controlled. | Account Policy / Account Register | IT | A.5.16, A.5.18 | |
| 26 | How are passwords managed? | Password requirements follow organizational security standards and technical controls. | Password Policy / Configuration | IT Security | A.5.17, A.8.5 | |
| 5. Infrastructure & Network Security | 27 | Do you use firewalls? | Yes, where applicable. | Firewall Configuration | Network / IT | A.8.20 |
| 28 | Do you use endpoint protection? | Yes. Appropriate endpoint-security controls are implemented. | EDR/AV Dashboard | IT | A.8.1, A.8.7 | |
| 29 | Is network traffic monitored? | Security monitoring/logging is implemented based on risk and requirements. | SIEM / Monitoring Logs | IT Security | A.8.15, A.8.16 | |
| 30 | Are systems patched regularly? | Yes. A patch-management process is maintained. | Patch Reports | IT | A.8.8, A.8.9 | |
| 31 | Do you conduct vulnerability assessments? | Yes. Vulnerabilities are identified, assessed and remediated based on risk. | VA Report / Tracker | IT Security | A.8.8 | |
| 32 | Do you conduct penetration testing? | Where applicable, penetration testing is conducted based on risk and requirements. | VAPT Report | Security Team | A.8.8, A.8.29 | |
| 6. Application Security | 33 | Do you follow secure software-development practices? | Yes, where development is within scope. | SDLC Policy | Engineering Manager | A.8.25 |
| 34 | Is source code access restricted? | Yes. Source-code access is restricted based on role and business need. | Repository Access List | Engineering | A.8.4 | |
| 35 | Is code review performed? | Yes, for applicable development activities. | Pull Requests / Review Records | Engineering | A.8.28, A.8.25 | |
| 36 | Do you perform security testing? | Appropriate security testing is performed based on application risk. | Security Test Report | Security / Engineering | A.8.29 | |
| 37 | Are vulnerabilities tracked? | Yes. Identified vulnerabilities are recorded and tracked through remediation. | Vulnerability Register | Security Team | A.8.8 | |
| 7. Data Protection | 38 | What types of customer data do you process? | Specify only the categories actually processed. | Data Inventory / Data Flow | Data Owner | A.5.9, A.5.12 |
| 39 | Is customer data encrypted? | Appropriate encryption is used for data in transit and, where applicable, at rest. | Encryption Configuration | IT Security | A.8.24 | |
| 40 | Is customer data segregated? | Logical/technical segregation is implemented where applicable. | Architecture / Configuration | IT | A.8.22 | |
| 41 | Who can access customer data? | Access is limited to authorized personnel based on business need. | Access Matrix / User List | Data Owner / IT | A.5.15, A.5.18 | |
| 42 | Do you have a data-retention policy? | Yes. Retention requirements are defined based on business, contractual and legal requirements. | Retention Policy | Legal / ISMS | A.5.33, A.5.34 | |
| 43 | How is data securely deleted? | Data is securely deleted/disposed of according to defined requirements. | Disposal / Deletion Records | IT / Data Owner | A.8.10 | |
| 8. Cloud Security | 44 | Do you use cloud services? | Yes. Identify relevant cloud service providers. | Cloud Provider Register | IT Manager | A.5.23 |
| 45 | How is cloud access controlled? | Cloud access is controlled using IAM, least privilege and MFA where applicable. | IAM Configuration | Cloud Administrator | A.5.23, A.8.2, A.8.5 | |
| 46 | Are cloud configurations reviewed? | Yes. Applicable configurations are reviewed/monitored. | Configuration Review | Cloud Security | A.5.23, A.8.9 | |
| 47 | Are cloud logs maintained? | Relevant security and operational logs are maintained. | Cloud Logs / SIEM | IT Security | A.8.15 | |
| 48 | Do you review your cloud provider’s security? | Cloud providers are evaluated based on security, compliance and risk. | Vendor Assessment / SOC Report | Vendor Manager | A.5.19–A.5.22, A.5.23 | |
| 49 | Do you have a cloud-security policy? | Yes, where cloud services are within ISMS scope. | Cloud Security Policy | IT / ISMS | A.5.23 | |
| 9. Backup & Disaster Recovery | 50 | Are customer data backups performed? | Yes, where applicable. | Backup Policy / Logs | IT | A.8.13 |
| 51 | Are backups encrypted/protected? | Appropriate security controls are applied to backups. | Backup Configuration | IT Security | A.8.13, A.8.24 | |
| 52 | Are backups tested? | Backup restoration/recovery is tested periodically. | Restore Test Report | IT | A.8.13 | |
| 53 | Do you have a Business Continuity Plan? | Yes. Business continuity arrangements are maintained. | BCP | BCM Owner | A.5.29, A.5.30 | |
| 54 | Do you have a Disaster Recovery Plan? | Yes, where applicable. | DR Plan | IT / BCM | A.5.30, A.8.14 | |
| 55 | What is your RTO/RPO? | Provide the actual approved RTO/RPO for the service. | BIA / DR Plan | BCM / IT | A.5.30, A.8.14 | |
| 10. Incident Management | 56 | Do you have an incident-response process? | Yes. ABC maintains a documented incident-response process. | Incident Response Procedure | CISO / IT Security | A.5.24 |
| 57 | How can customers report incidents? | Customers can report incidents through the designated security/support channel. | Incident Contact Procedure / Contract | CISO / Support | A.5.24 | |
| 58 | Do you notify customers of security incidents? | Yes, where required by contract or applicable law. | Incident Notification Procedure | CISO / Legal | A.5.26 | |
| 59 | Do you perform root-cause analysis? | Yes, for applicable security incidents. | RCA Report | IT Security | A.5.27 | |
| 60 | Are corrective actions tracked? | Yes. Corrective actions are assigned and tracked through closure. | CAPA / Action Tracker | ISMS Manager | A.5.27, Clause 10.2 | |
| 11. Third-Party / Vendor Management | 61 | Do you assess vendors? | Yes. Relevant third parties are evaluated based on security and business risk. | Vendor Risk Assessment | Vendor Manager | A.5.19 |
| 62 | Do vendor contracts contain security requirements? | Yes, applicable contracts include security and confidentiality requirements. | Contract / NDA | Procurement / Legal | A.5.20 | |
| 63 | Are critical vendors reviewed periodically? | Yes, based on risk and contractual requirements. | Vendor Review | Vendor Manager | A.5.22 | |
| 64 | Do you monitor third-party security? | Relevant third-party risks are monitored through supplier management. | Vendor Monitoring / Risk Register | Vendor Manager | A.5.21, A.5.22 | |
| 12. Privacy & Compliance | 65 | Do you have a privacy policy? | Yes, where applicable. | Privacy Policy | Legal / DPO | A.5.34 |
| 66 | Do you comply with applicable privacy laws? | Applicable legal, regulatory and contractual requirements are identified and addressed. | Legal Register / Compliance Assessment | Legal / DPO | A.5.31, A.5.34 | |
| 67 | Do you have a data-subject request process? | Implemented where applicable to the data and jurisdiction. | DSAR Procedure / Register | DPO / Legal | A.5.34 | |
| 68 | Do you have a data-breach notification process? | Yes. Applicable incidents are assessed and notified according to requirements. | Breach Procedure | DPO / CISO | A.5.26, A.5.34 | |
| 69 | Do you have regulatory compliance monitoring? | Applicable legal, regulatory and contractual requirements are identified and monitored. | Legal & Regulatory Register | Compliance / Legal | A.5.31 | |
| 13. Audit & Assurance | 70 | Do you undergo independent audits? | Yes, including applicable ISO/IEC 27001 certification/surveillance audits. | Audit Reports / Certificate | ISMS Manager | A.5.35, Clause 9.2 |
| 71 | Can you provide your latest audit report? | Relevant audit documentation may be shared subject to confidentiality restrictions. | Audit Report / Executive Summary | ISMS Manager | A.5.35 | |
| 72 | Were there any major non-conformities? | Answer based on the latest certification audit outcome. | Latest Audit Report | ISMS Manager | Clause 10.2 | |
| 73 | Do you track audit findings? | Yes. Findings and corrective actions are documented and tracked through closure. | Audit Finding / CAPA Tracker | ISMS Manager | A.5.36, Clause 10.2 | |
| 74 | Do you maintain audit evidence? | Yes. Relevant ISMS records and evidence are maintained. | ISMS Evidence Repository | ISMS Manager | A.5.35, A.5.36 | |
| 14. Physical Security | 75 | Is office access controlled? | Yes. Physical access is controlled using appropriate mechanisms. | Access Logs / Physical Security Policy | Admin / Facilities | A.7.2 |
| 76 | Are visitors controlled? | Yes. Visitor-management procedures are implemented. | Visitor Register / Procedure | Admin / Facilities | A.7.2 | |
| 77 | Is CCTV used? | Answer according to the actual facility. | CCTV Policy / Records | Facilities | A.7.4 | |
| 78 | Are critical areas restricted? | Yes. Access to restricted areas is limited to authorized personnel. | Access List / Logs | Facilities / IT | A.7.3, A.7.6 | |
| 79 | Are environmental protections implemented? | Appropriate controls are implemented for critical equipment/facilities. | Facility Inspection / Environmental Controls | Facilities / IT | A.7.5, A.7.11 |
Important Note
This questionnaire and its suggested responses are provided by Make Audit Easy for informational and preparation purposes only. Suggested responses should be reviewed and customized according to the organization’s actual controls, policies, scope, contractual obligations, regulatory requirements, and available evidence.
The questionnaire does not constitute legal, regulatory, certification, audit, or professional advice. Make Audit Easy does not assume liability for inaccurate, incomplete, outdated, misleading, unauthorized, or inappropriate use of this material.
Unauthorized reproduction, modification, distribution, misrepresentation, or misuse of this material is not permitted.
© Make Audit Easy. All rights reserved.
