Question by question
How to answer a security questionnaire, one question at a time.
For each question: what it is really asking, which of your documents answers it, what to attach, and the specific ways that one goes wrong. Written from the questions in CAIQ v4, SIG Lite and ISO 27001 Annex A.
41 questions so far · more added every month
Or read them grouped by the questionnaire that asks them, if you already know which one you were sent.
Access control
Are user access rights reviewed periodically?
Implied, not statedPolicies say quarterly. The reviewer is asking about the person who left in March, and periodic review is the wrong instrument for finding them.
Do you support single sign-on (SAML or OIDC)?
Answered “no” from your documentsA product question wearing a security costume, and the best example of a documented "no" being a better answer than a hedged yes.
How quickly is access revoked when someone leaves?
Confirmed in your documentsThe strongest version of this answer is not a time. It is a single action that covers everything, plus a list of what it does not.
Is access granted on a least-privilege basis?
Implied, not statedThe honest small-company answer is rarely a clean yes, and the answer that names its exceptions is stronger than the one that does not.
Is multi-factor authentication enforced for administrative access?
Confirmed in your documentsThe gap here is almost always between "enabled" and "enforced", and between staff logins and the two or three accounts that could not take a second factor.
What is your password policy?
Confirmed in your documentsOne of the few questions where the modern answer looks weaker than the old one and is in fact much stronger.
Certifications and audits
Do you allow customers to audit your security controls?
Answered “no” from your documentsAnswering yes to be agreeable grants a contractual right to send an assessor. Answering no with nothing offered instead leaves a gap in the reviewer's file. The useful answer is no, and here is what you get.
Do you hold ISO 27001 certification?
Answered “no” from your documentsOne of the few questions where the answer is usually no, and where no is a perfectly good answer.
Do you maintain a current SOC 2 Type II report?
Confirmed in your documentsIf you have one, the cover page answers this question. The mistakes are all in the details it also contains: the type, the criteria, and the dates.
Data governance
Do you classify data by sensitivity?
Not in your documentsOne of the few questions where most small companies genuinely have nothing, and where inventing a scheme is worse than saying so.
Do you use customer data to train AI models?
Answered “no” from your documentsThe fastest-growing question on vendor questionnaires, and the one where a careless yes is hardest to walk back.
How do you handle international transfers of personal data?
Confirmed in your documentsWhere the servers are is only half of it. Who can reach the data, from which country, is the other half.
How is one customer's data kept separate from another's?
Implied, not statedLogical separation is the true answer for nearly every SaaS, and also what somebody says when they have not thought about it. The difference is whether you can say how the boundary is enforced and tested.
What is your data retention period, and how is customer data deleted after termination?
Reused from your libraryThe number is easy. What separates a good answer from one that unravels is whether it accounts for backups, logs and every other place a copy came to rest.
Where is customer data hosted, and can it be kept in a specific region?
Reused from your libraryThe database is the easy half. A reviewer at an EU company is asking about every sub-processor and about who can read a record from where.
Encryption and key management
How are credentials, API keys and other secrets managed?
Confirmed in your documentsThe question is about the credentials your software runs on, not the password manager the team uses. Rotation is the part most likely to be aspirational, and the follow-up is always the date of the last one.
Is customer data encrypted at rest?
Confirmed in your documentsOne of the most common questions on any questionnaire, and one of the most commonly over-answered: most teams encrypt the database and forget the backups.
Is customer data encrypted in transit?
Confirmed in your documentsEasy to answer yes to and easy to check from the outside, which makes it one of the few questions where a wrong answer is found rather than believed.
Engineering practice
Do you have a documented change management process?
Confirmed in your documentsAt fifteen people this is not a change advisory board. It is whether your pipeline records who changed what.
Do you have a secure software development lifecycle?
Confirmed in your documentsReviewers are testing one thing: what prevents an unreviewed change from reaching your customers' data.
Governance
Do you carry cyber liability insurance, and what is the coverage limit?
Not in your documentsThe question FillTrust most often leaves deliberately blank. No security document contains the answer, and guessing a coverage limit is a representation you cannot support.
Do you perform regular security risk assessments?
Not in your documentsThe most enterprise-shaped question on the questionnaire, and the one small teams most often answer with an aspiration.
Incident response
Do you have a documented incident response plan, and what is your breach notification window?
Confirmed in your documentsTwo questions in one, and the second half, the notification window, is the one with contractual teeth. It comes from your DPA, not from GDPR.
How quickly will you notify us of a data breach?
Confirmed in your documentsThe one answer that must match your contract word for word, because the contract is what a court reads.
Infrastructure
Do you maintain an inventory of systems and assets?
Implied, not statedYou probably have three inventories already and have never called them that.
What physical security controls protect your data centres?
Confirmed in your documentsYou do not run a data centre. Saying so, and naming who does, is the complete answer.
Logging and monitoring
Can customers access audit logs of activity in their account?
Answered “no” from your documentsThis one is a product question, not a security question, and the honest answer for most young products is no with an offer attached.
Do you log and monitor access to production systems?
Confirmed in your documentsTwo questions in one: what you record, and what happens when something in the record is worth waking up for.
People
Are background checks performed on employees with access to customer data?
Confirmed in your documentsOne of the few questions answered from an HR document rather than a security one, which is exactly why it is often answered from memory.
Do employees complete security awareness training?
Confirmed in your documentsAn easy yes for most teams, and one of the few questions where the follow-up is a date rather than a document.
Resilience
Are backups tested by performing restores?
Implied, not statedEverybody takes backups. This question is about the last time one was proved to work.
Do you maintain a business continuity and disaster recovery plan, and is it tested?
Reused from your libraryTwo numbers carry this answer, RTO and RPO, and they are the two a reviewer can hold you to during a real outage. Do not publish ones you have not measured.
What are your recovery time and recovery point objectives?
Not in your documentsTwo numbers with no scenario attached mean nothing, and a reviewer who has to guess will assume the flattering reading and hold you to it.
What availability do you commit to, and how is it measured?
Implied, not statedA number with no measurement behind it is trivially checkable, against a status page and against the reviewer's memory of your last outage.
Third-party risk
Do you assess the security of your vendors and sub-processors?
Implied, not statedThe question your customer is really asking is whether their data can reach somewhere they have not been told about.
Do you use sub-processors, and can you provide a current list?
Confirmed in your documentsThe list is easy. What reviewers actually check is whether the unglamorous ones are on it: the error tracker, the support desk, the AI provider.
Will you notify us before adding or changing a sub-processor?
Confirmed in your documents"We will notify you" and "we will notify you thirty days before" are different commitments, and this question is asking for the second.
Vulnerability management
Do you have a vulnerability disclosure policy or bug bounty programme?
Not in your documentsVery few small companies run a bounty. Almost all of them should have the one-page policy, and it takes an afternoon.
Do you perform annual penetration testing by an independent third party?
Implied, not statedThis is the question FillTrust most often grades as inferred rather than confirmed, because policies state a cadence and cadences are not evidence that a test happened.
How quickly do you patch known vulnerabilities?
Implied, not statedThe question is not whether you patch. It is whether you can name the window and show that you meet it.
Or answer all of them at once.
FillTrust drafts every one of these from your own documents, and shows the passage behind each answer.