Sign up & enjoy 10% off
Reduce Your Compliance Cost By 60%
Welcome to Make Audit Easy
Austin - Atlanta - Seattle
Reduce Your Compliance Cost By 60%
Austin - Atlanta - Seattle

How to Respond to a Client Security Questionnaire – Supplier/Client Audit Cycle

ABC Small / Medium Service Pvt. Ltd. is an existing ISO/IEC 27001-certified company and a customer sends a security questionnaire as part of its supplier/client audit cycle.

Link – https://docs.google.com/spreadsheets/d/1BvJ7VULOfJuAmyFFlmYqZk8OF_SFrKYw/edit?usp=sharing&ouid=106296367252736735726&rtpof=true&sd=true

SectionSr. No.Customer QuestionSuggested ResponseEvidenceOwnerISO 27001 Reference
1. Company & ISMS1Is your organization ISO 27001 certified?Yes. ABC maintains an ISO/IEC 27001-certified ISMS.ISO CertificateISMS ManagerClause 4–10
2Provide your ISO certificate.Provide current certificate, scope and validity.ISO CertificateISMS ManagerClause 4.3
3What is the scope of certification?State the exact scope from the certificate.Certificate / Scope DocumentISMS ManagerClause 4.3
4Is the certificate issued by an accredited certification body?Yes, if applicable. Provide certification-body details.Certificate / Accreditation DetailsISMS ManagerClause 9.2
5Do you conduct internal audits?Yes. Internal audits are conducted as part of the ISMS audit programme.Audit Plan / Audit ReportInternal AuditorClause 9.2
6Do you conduct management reviews?Yes. Management reviews are performed periodically.Management Review MinutesTop ManagementClause 9.3
7Do you maintain a risk assessment process?Yes. Information-security risks are identified, assessed, treated and reviewed.Risk Assessment / Risk RegisterRisk ManagerClauses 6.1.2, 6.1.3
8Do you maintain a Statement of Applicability?Yes. The SoA is maintained and reviewed as part of the ISMS.Statement of ApplicabilityISMS ManagerClause 6.1.3(d)
2. Information Security Governance9Do you have an information security policy?Yes. An approved Information Security Policy is maintained and communicated.Information Security PolicyISMS ManagerA.5.1
10Who is responsible for information security?Information-security responsibilities are formally assigned.Organization Chart / RACIManagement / ISMS ManagerA.5.2
11Are security responsibilities documented?Yes. Roles and responsibilities are formally defined.RACI / Job DescriptionsHR / ISMSA.5.2
12Do you have security objectives?Yes. Information-security objectives are established, monitored and reviewed.Security Objectives / KPIISMS ManagerClause 6.2
13How are security incidents managed?Through a documented incident-management process covering reporting, response and closure.Incident Procedure / RegisterCISO / IT SecurityA.5.24–A.5.28
3. Personnel Security14Are background checks performed?Background verification is performed for applicable employees/roles.BGV Policy / RecordsHRA.6.1
15Do employees sign confidentiality agreements?Yes, where applicable.NDA / Employment AgreementHR / LegalA.6.6
16Is security awareness training provided?Yes. Security-awareness training is provided during onboarding and periodically.Training Records / MaterialHR / ISMSA.6.3
17Are employees trained on phishing/security threats?Yes. Training covers relevant cybersecurity threats and safe practices.Awareness / Phishing Training RecordsIT Security / HRA.6.3
18Is access removed when an employee leaves?Yes. Access revocation is part of the offboarding process.Exit Checklist / Access RevocationHR / ITA.6.5
19Is there a disciplinary process for security violations?Yes. Violations are handled through the disciplinary process.Disciplinary PolicyHRA.6.4
4. Access Control20Do you have access-control policies?Yes. Access is governed through documented requirements.Access Control PolicyIT / ISMSA.5.15
21Is least privilege implemented?Yes. Access is provisioned according to role and business need.Access MatrixIT ManagerA.5.15, A.8.2
22Are privileged accounts restricted?Yes. Privileged access is restricted to authorized personnel.Privileged Account ListIT SecurityA.8.2
23Are user access reviews performed?Yes. Access rights are periodically reviewed.Access Review RecordsIT / Application OwnerA.5.18
24Is MFA implemented?MFA is implemented for applicable systems and accounts.MFA Configuration / ScreenshotIT SecurityA.5.17, A.8.5
25Are shared accounts permitted?Shared accounts are restricted except where specifically justified and controlled.Account Policy / Account RegisterITA.5.16, A.5.18
26How are passwords managed?Password requirements follow organizational security standards and technical controls.Password Policy / ConfigurationIT SecurityA.5.17, A.8.5
5. Infrastructure & Network Security27Do you use firewalls?Yes, where applicable.Firewall ConfigurationNetwork / ITA.8.20
28Do you use endpoint protection?Yes. Appropriate endpoint-security controls are implemented.EDR/AV DashboardITA.8.1, A.8.7
29Is network traffic monitored?Security monitoring/logging is implemented based on risk and requirements.SIEM / Monitoring LogsIT SecurityA.8.15, A.8.16
30Are systems patched regularly?Yes. A patch-management process is maintained.Patch ReportsITA.8.8, A.8.9
31Do you conduct vulnerability assessments?Yes. Vulnerabilities are identified, assessed and remediated based on risk.VA Report / TrackerIT SecurityA.8.8
32Do you conduct penetration testing?Where applicable, penetration testing is conducted based on risk and requirements.VAPT ReportSecurity TeamA.8.8, A.8.29
6. Application Security33Do you follow secure software-development practices?Yes, where development is within scope.SDLC PolicyEngineering ManagerA.8.25
34Is source code access restricted?Yes. Source-code access is restricted based on role and business need.Repository Access ListEngineeringA.8.4
35Is code review performed?Yes, for applicable development activities.Pull Requests / Review RecordsEngineeringA.8.28, A.8.25
36Do you perform security testing?Appropriate security testing is performed based on application risk.Security Test ReportSecurity / EngineeringA.8.29
37Are vulnerabilities tracked?Yes. Identified vulnerabilities are recorded and tracked through remediation.Vulnerability RegisterSecurity TeamA.8.8
7. Data Protection38What types of customer data do you process?Specify only the categories actually processed.Data Inventory / Data FlowData OwnerA.5.9, A.5.12
39Is customer data encrypted?Appropriate encryption is used for data in transit and, where applicable, at rest.Encryption ConfigurationIT SecurityA.8.24
40Is customer data segregated?Logical/technical segregation is implemented where applicable.Architecture / ConfigurationITA.8.22
41Who can access customer data?Access is limited to authorized personnel based on business need.Access Matrix / User ListData Owner / ITA.5.15, A.5.18
42Do you have a data-retention policy?Yes. Retention requirements are defined based on business, contractual and legal requirements.Retention PolicyLegal / ISMSA.5.33, A.5.34
43How is data securely deleted?Data is securely deleted/disposed of according to defined requirements.Disposal / Deletion RecordsIT / Data OwnerA.8.10
8. Cloud Security44Do you use cloud services?Yes. Identify relevant cloud service providers.Cloud Provider RegisterIT ManagerA.5.23
45How is cloud access controlled?Cloud access is controlled using IAM, least privilege and MFA where applicable.IAM ConfigurationCloud AdministratorA.5.23, A.8.2, A.8.5
46Are cloud configurations reviewed?Yes. Applicable configurations are reviewed/monitored.Configuration ReviewCloud SecurityA.5.23, A.8.9
47Are cloud logs maintained?Relevant security and operational logs are maintained.Cloud Logs / SIEMIT SecurityA.8.15
48Do you review your cloud provider’s security?Cloud providers are evaluated based on security, compliance and risk.Vendor Assessment / SOC ReportVendor ManagerA.5.19–A.5.22, A.5.23
49Do you have a cloud-security policy?Yes, where cloud services are within ISMS scope.Cloud Security PolicyIT / ISMSA.5.23
9. Backup & Disaster Recovery50Are customer data backups performed?Yes, where applicable.Backup Policy / LogsITA.8.13
51Are backups encrypted/protected?Appropriate security controls are applied to backups.Backup ConfigurationIT SecurityA.8.13, A.8.24
52Are backups tested?Backup restoration/recovery is tested periodically.Restore Test ReportITA.8.13
53Do you have a Business Continuity Plan?Yes. Business continuity arrangements are maintained.BCPBCM OwnerA.5.29, A.5.30
54Do you have a Disaster Recovery Plan?Yes, where applicable.DR PlanIT / BCMA.5.30, A.8.14
55What is your RTO/RPO?Provide the actual approved RTO/RPO for the service.BIA / DR PlanBCM / ITA.5.30, A.8.14
10. Incident Management56Do you have an incident-response process?Yes. ABC maintains a documented incident-response process.Incident Response ProcedureCISO / IT SecurityA.5.24
57How can customers report incidents?Customers can report incidents through the designated security/support channel.Incident Contact Procedure / ContractCISO / SupportA.5.24
58Do you notify customers of security incidents?Yes, where required by contract or applicable law.Incident Notification ProcedureCISO / LegalA.5.26
59Do you perform root-cause analysis?Yes, for applicable security incidents.RCA ReportIT SecurityA.5.27
60Are corrective actions tracked?Yes. Corrective actions are assigned and tracked through closure.CAPA / Action TrackerISMS ManagerA.5.27, Clause 10.2
11. Third-Party / Vendor Management61Do you assess vendors?Yes. Relevant third parties are evaluated based on security and business risk.Vendor Risk AssessmentVendor ManagerA.5.19
62Do vendor contracts contain security requirements?Yes, applicable contracts include security and confidentiality requirements.Contract / NDAProcurement / LegalA.5.20
63Are critical vendors reviewed periodically?Yes, based on risk and contractual requirements.Vendor ReviewVendor ManagerA.5.22
64Do you monitor third-party security?Relevant third-party risks are monitored through supplier management.Vendor Monitoring / Risk RegisterVendor ManagerA.5.21, A.5.22
12. Privacy & Compliance65Do you have a privacy policy?Yes, where applicable.Privacy PolicyLegal / DPOA.5.34
66Do you comply with applicable privacy laws?Applicable legal, regulatory and contractual requirements are identified and addressed.Legal Register / Compliance AssessmentLegal / DPOA.5.31, A.5.34
67Do you have a data-subject request process?Implemented where applicable to the data and jurisdiction.DSAR Procedure / RegisterDPO / LegalA.5.34
68Do you have a data-breach notification process?Yes. Applicable incidents are assessed and notified according to requirements.Breach ProcedureDPO / CISOA.5.26, A.5.34
69Do you have regulatory compliance monitoring?Applicable legal, regulatory and contractual requirements are identified and monitored.Legal & Regulatory RegisterCompliance / LegalA.5.31
13. Audit & Assurance70Do you undergo independent audits?Yes, including applicable ISO/IEC 27001 certification/surveillance audits.Audit Reports / CertificateISMS ManagerA.5.35, Clause 9.2
71Can you provide your latest audit report?Relevant audit documentation may be shared subject to confidentiality restrictions.Audit Report / Executive SummaryISMS ManagerA.5.35
72Were there any major non-conformities?Answer based on the latest certification audit outcome.Latest Audit ReportISMS ManagerClause 10.2
73Do you track audit findings?Yes. Findings and corrective actions are documented and tracked through closure.Audit Finding / CAPA TrackerISMS ManagerA.5.36, Clause 10.2
74Do you maintain audit evidence?Yes. Relevant ISMS records and evidence are maintained.ISMS Evidence RepositoryISMS ManagerA.5.35, A.5.36
14. Physical Security75Is office access controlled?Yes. Physical access is controlled using appropriate mechanisms.Access Logs / Physical Security PolicyAdmin / FacilitiesA.7.2
76Are visitors controlled?Yes. Visitor-management procedures are implemented.Visitor Register / ProcedureAdmin / FacilitiesA.7.2
77Is CCTV used?Answer according to the actual facility.CCTV Policy / RecordsFacilitiesA.7.4
78Are critical areas restricted?Yes. Access to restricted areas is limited to authorized personnel.Access List / LogsFacilities / ITA.7.3, A.7.6
79Are environmental protections implemented?Appropriate controls are implemented for critical equipment/facilities.Facility Inspection / Environmental ControlsFacilities / ITA.7.5, A.7.11

Important Note

This questionnaire and its suggested responses are provided by Make Audit Easy for informational and preparation purposes only. Suggested responses should be reviewed and customized according to the organization’s actual controls, policies, scope, contractual obligations, regulatory requirements, and available evidence.

The questionnaire does not constitute legal, regulatory, certification, audit, or professional advice. Make Audit Easy does not assume liability for inaccurate, incomplete, outdated, misleading, unauthorized, or inappropriate use of this material.

Unauthorized reproduction, modification, distribution, misrepresentation, or misuse of this material is not permitted.

© Make Audit Easy. All rights reserved.

Shopping cart

0
image/svg+xml

No products in the cart.

Continue Shopping