1. Purpose
This questionnaire is used to assess the information-security practices of suppliers and third-party service providers before onboarding and during periodic supplier reviews.
It helps the organization understand:
- What services the supplier provides
- What information and systems are involved
- How information is protected
- How access is controlled
- How incidents are managed
- How vulnerabilities are handled
- How business continuity is maintained
- Whether subcontractors or subprocessors are involved
- What security assurance is available
The questionnaire should be completed based on the supplier’s actual services and environment. Not every question will apply to every supplier.
Core Principle
Understand the Supplier → Assess the Risk → Verify Controls → Identify Gaps → Treat Risk → Monitor
2. Supplier Information
| Field | Supplier Response |
|---|---|
| Supplier Name | |
| Legal Entity Name | |
| Service/Product Name | |
| Service Description | |
| Supplier Contact | |
| Security Contact | |
| Privacy Contact | |
| Business Owner | |
| Contract/SOW Reference | |
| Service Start Date | |
| Service Location | |
| Data Processing Location | |
| Countries of Operation | |
| Number of Employees | |
| Number of Security Personnel | |
| Questionnaire Completion Date | |
| Completed By | |
| Reviewed By |
3. Instructions to Supplier
Please answer each question using:
- Yes
- No
- Partially
- Not Applicable
Where the answer is Yes or Partially, provide supporting information or evidence where appropriate.
Where the answer is No, explain whether an alternative control exists.
Where Not Applicable is selected, provide a brief justification where the question may reasonably appear relevant.
Evidence
Do not provide passwords, API keys, private keys, access tokens, authentication secrets, or other confidential credentials.
Sensitive security evidence should be shared through an approved secure channel.
4. Service and Security Scope
4.1 Service Description
Q1. Please describe the service being provided.
Response:
Q2. What business functions does the service support?
Response:
Q3. Is the service business-critical?
☐ Yes ☐ No ☐ Partially
Q4. What would be the expected impact if the service became unavailable?
Q5. Does the service connect to the customer’s systems?
☐ Yes ☐ No
If yes, describe the integration:
5. Information and Data
Q6. Does the supplier access, process, store, or transmit customer information?
☐ Yes ☐ No
Q7. Does the supplier process personal data?
☐ Yes ☐ No
Q8. Does the supplier process financial or payment information?
☐ Yes ☐ No
Q9. Does the supplier process confidential business information?
☐ Yes ☐ No
Q10. Does the supplier process security-related information?
☐ Yes ☐ No
Q11. Does the supplier store customer information?
☐ Yes ☐ No
Q12. What categories of information are processed?
Q13. What is the information retention period?
Q14. Can customers request deletion or return of information?
☐ Yes ☐ No ☐ Contract-dependent
Details:
6. Data Classification and Protection
Q15. Does the supplier have an information-classification process?
☐ Yes ☐ No
Q16. Are customer information and confidential information handled according to defined security requirements?
☐ Yes ☐ No ☐ Partially
Q17. Are appropriate controls applied based on information sensitivity?
☐ Yes ☐ No ☐ Partially
Q18. Is customer information logically separated from other customers?
☐ Yes ☐ No ☐ N/A
Details:
7. Information Security Governance
Q19. Does the supplier maintain a formal information-security program?
☐ Yes ☐ No
Q20. Is there a person or team responsible for information security?
☐ Yes ☐ No
Q21. Does senior management have oversight of information security?
☐ Yes ☐ No
Q22. Does the supplier maintain information-security policies?
☐ Yes ☐ No
Q23. Are security policies periodically reviewed?
☐ Yes ☐ No
Q24. Does the supplier conduct periodic information-security risk assessments?
☐ Yes ☐ No
8. Security Certifications and Assurance
Q25. Is the organization certified against ISO/IEC 27001?
☐ Yes ☐ No
If yes:
Certificate Number: __________________
Certification Body: __________________
Expiry Date: __________________
Scope:
Q26. Does the supplier have a SOC 2 report?
☐ Yes ☐ No
If yes:
☐ Type I
☐ Type II
Report Period: __________________
Scope:
Q27. Does the supplier have other relevant security certifications or independent assessments?
☐ Yes ☐ No
Details:
Q28. Can relevant security assurance documentation be provided for review?
☐ Yes ☐ No ☐ Subject to NDA/contract
9. Risk Management
Q29. Does the supplier maintain a formal security-risk management process?
☐ Yes ☐ No
Q30. Are information-security risks documented?
☐ Yes ☐ No
Q31. Are risk owners assigned?
☐ Yes ☐ No
Q32. Are identified risks periodically reviewed?
☐ Yes ☐ No
Q33. Are significant security risks reported to management?
☐ Yes ☐ No
10. Identity and Access Management
Q34. Are individual user accounts used instead of shared accounts?
☐ Yes ☐ No ☐ Where practical
Q35. Is access granted based on business need?
☐ Yes ☐ No
Q36. Is least privilege applied?
☐ Yes ☐ No
Q37. Is user access periodically reviewed?
☐ Yes ☐ No
Q38. Are access rights removed when personnel leave or change roles?
☐ Yes ☐ No
Q39. Are privileged accounts separately controlled?
☐ Yes ☐ No ☐ N/A
Q40. Is privileged access periodically reviewed?
☐ Yes ☐ No ☐ N/A
11. Authentication and MFA
Q41. Is MFA implemented for administrative or privileged access?
☐ Yes ☐ No ☐ N/A
Q42. Is MFA implemented for remote access?
☐ Yes ☐ No ☐ N/A
Q43. Is MFA available to customer users?
☐ Yes ☐ No ☐ N/A
Q44. Are passwords protected against common or compromised passwords?
☐ Yes ☐ No ☐ N/A
Q45. Are authentication credentials securely stored?
☐ Yes ☐ No
Q46. Are authentication failures monitored?
☐ Yes ☐ No
12. Privileged Access
Q47. Does the supplier provide privileged access to customer environments?
☐ Yes ☐ No
Q48. Is privileged access restricted to authorized personnel?
☐ Yes ☐ No
Q49. Is privileged access individually attributable?
☐ Yes ☐ No
Q50. Is privileged access logged?
☐ Yes ☐ No
Q51. Is privileged access reviewed periodically?
☐ Yes ☐ No
Q52. Is temporary or just-in-time privileged access used where practical?
☐ Yes ☐ No ☐ N/A
13. Personnel Security
Q53. Are personnel subject to appropriate pre-employment screening where legally permitted and appropriate?
☐ Yes ☐ No ☐ Role-dependent
Q54. Are employees required to sign confidentiality agreements?
☐ Yes ☐ No
Q55. Do employees receive security-awareness training?
☐ Yes ☐ No
Q56. Is security training provided periodically?
☐ Yes ☐ No
Q57. Are personnel security responsibilities defined?
☐ Yes ☐ No
Q58. Is access revoked promptly when personnel leave?
☐ Yes ☐ No
14. Security Awareness
Q59. Does the supplier conduct security-awareness training?
☐ Yes ☐ No
Q60. Does training cover phishing and social engineering?
☐ Yes ☐ No
Q61. Does training cover protection of customer information?
☐ Yes ☐ No
Q62. Does training cover incident reporting?
☐ Yes ☐ No
Q63. Is security awareness tailored to privileged or technical roles?
☐ Yes ☐ No ☐ Partially
15. Physical Security
Q64. Are facilities hosting customer systems or information physically secured?
☐ Yes ☐ No ☐ N/A
Q65. Is physical access controlled?
☐ Yes ☐ No ☐ N/A
Q66. Are visitors controlled and monitored?
☐ Yes ☐ No ☐ N/A
Q67. Are critical facilities protected against environmental threats?
☐ Yes ☐ No ☐ N/A
Q68. Are physical-security controls periodically reviewed?
☐ Yes ☐ No ☐ N/A
16. Endpoint Security
Q69. Are company-managed endpoints protected against malware?
☐ Yes ☐ No ☐ N/A
Q70. Are security patches applied to endpoints?
☐ Yes ☐ No
Q71. Is disk encryption used where appropriate?
☐ Yes ☐ No ☐ N/A
Q72. Are administrative privileges restricted on employee devices?
☐ Yes ☐ No ☐ N/A
Q73. Are lost or stolen devices subject to security controls such as remote lock/wipe where appropriate?
☐ Yes ☐ No ☐ N/A
17. Network Security
Q74. Are network security controls implemented?
☐ Yes ☐ No
Q75. Are network boundaries and trust zones defined?
☐ Yes ☐ No ☐ N/A
Q76. Are firewalls or equivalent controls implemented?
☐ Yes ☐ No ☐ N/A
Q77. Is network traffic monitored where appropriate?
☐ Yes ☐ No
Q78. Are unauthorized network connections restricted?
☐ Yes ☐ No
18. Cloud Security
Complete this section where cloud services are used.
Q79. Does the supplier use public cloud infrastructure?
☐ Yes ☐ No
Q80. Which cloud providers are used?
Q81. Are cloud accounts centrally managed?
☐ Yes ☐ No ☐ N/A
Q82. Is cloud administrative access protected with MFA?
☐ Yes ☐ No ☐ N/A
Q83. Are cloud permissions based on least privilege?
☐ Yes ☐ No ☐ N/A
Q84. Are cloud activities logged?
☐ Yes ☐ No ☐ N/A
Q85. Are cloud configurations periodically reviewed?
☐ Yes ☐ No ☐ N/A
Q86. Are cloud backups implemented where required?
☐ Yes ☐ No ☐ N/A
19. Application Security
Q87. Does the supplier follow a secure software-development lifecycle?
☐ Yes ☐ No ☐ N/A
Q88. Are security requirements defined during application development?
☐ Yes ☐ No ☐ N/A
Q89. Is source code reviewed?
☐ Yes ☐ No ☐ N/A
Q90. Are security vulnerabilities identified during development?
☐ Yes ☐ No ☐ N/A
Q91. Is security testing performed before significant releases?
☐ Yes ☐ No ☐ N/A
Q92. Are security defects tracked and remediated?
☐ Yes ☐ No ☐ N/A
20. Vulnerability Management
Q93. Does the supplier maintain a vulnerability-management process?
☐ Yes ☐ No
Q94. Are systems periodically scanned for vulnerabilities?
☐ Yes ☐ No ☐ N/A
Q95. Are critical vulnerabilities prioritized for remediation?
☐ Yes ☐ No
Q96. Are vulnerabilities tracked until closure?
☐ Yes ☐ No
Q97. Is penetration testing performed where appropriate?
☐ Yes ☐ No ☐ N/A
Q98. Are significant vulnerabilities communicated to customers where contractually or operationally required?
☐ Yes ☐ No ☐ N/A
21. Malware and Endpoint Protection
Q99. Are anti-malware or equivalent endpoint security controls implemented?
☐ Yes ☐ No ☐ N/A
Q100. Are security alerts monitored?
☐ Yes ☐ No
Q101. Are malware incidents investigated?
☐ Yes ☐ No
22. Logging and Monitoring
Q102. Are security-relevant events logged?
☐ Yes ☐ No
Q103. Are administrative activities logged?
☐ Yes ☐ No
Q104. Are authentication events logged?
☐ Yes ☐ No
Q105. Are logs protected against unauthorized modification?
☐ Yes ☐ No
Q106. Are security logs monitored?
☐ Yes ☐ No
Q107. Are logs retained according to defined requirements?
☐ Yes ☐ No
23. Security Incident Management
Q108. Does the supplier maintain a formal incident-response process?
☐ Yes ☐ No
Q109. Is there a defined security incident-response team or responsible function?
☐ Yes ☐ No
Q110. Are security incidents documented?
☐ Yes ☐ No
Q111. Are incidents investigated and contained?
☐ Yes ☐ No
Q112. Is there a process for notifying customers of relevant security incidents?
☐ Yes ☐ No
Q113. Are incident notification timelines defined contractually where appropriate?
☐ Yes ☐ No ☐ Contract-dependent
Q114. Are lessons learned performed after significant incidents?
☐ Yes ☐ No
24. Data Breach Management
Q115. Does the supplier maintain a process for responding to personal-data breaches?
☐ Yes ☐ No ☐ N/A
Q116. Can the supplier identify affected information and customers during an incident?
☐ Yes ☐ No
Q117. Does the supplier support investigation and evidence preservation?
☐ Yes ☐ No
Q118. Does the supplier support applicable customer/regulatory notification requirements?
☐ Yes ☐ No ☐ Contract-dependent
25. Encryption
Q119. Is sensitive information encrypted during transmission?
☐ Yes ☐ No ☐ N/A
Q120. Is sensitive information encrypted at rest?
☐ Yes ☐ No ☐ N/A
Q121. Are cryptographic keys appropriately protected?
☐ Yes ☐ No ☐ N/A
Q122. Is access to encryption keys restricted?
☐ Yes ☐ No ☐ N/A
Q123. Are keys/certificates managed throughout their lifecycle?
☐ Yes ☐ No ☐ N/A
26. Secrets and Credentials
Q124. Are passwords, API keys, tokens, and other secrets stored securely?
☐ Yes ☐ No ☐ N/A
Q125. Are secrets prevented from being stored in source code?
☐ Yes ☐ No ☐ N/A
Q126. Are exposed or compromised credentials promptly revoked or rotated?
☐ Yes ☐ No
Q127. Are service-account credentials managed securely?
☐ Yes ☐ No ☐ N/A
27. Backup and Recovery
Q128. Is customer information backed up where required?
☐ Yes ☐ No ☐ N/A
Q129. Are backups protected from unauthorized access?
☐ Yes ☐ No
Q130. Are backups encrypted where appropriate?
☐ Yes ☐ No ☐ N/A
Q131. Are backup restoration procedures tested?
☐ Yes ☐ No
Q132. Are recovery objectives defined for critical services?
☐ Yes ☐ No ☐ N/A
28. Business Continuity and Disaster Recovery
Q133. Does the supplier maintain a business-continuity plan?
☐ Yes ☐ No
Q134. Does the supplier maintain disaster-recovery procedures?
☐ Yes ☐ No
Q135. Are recovery procedures periodically tested?
☐ Yes ☐ No
Q136. Are critical services supported by appropriate resilience measures?
☐ Yes ☐ No ☐ N/A
Q137. Can the supplier provide relevant continuity assurance?
☐ Yes ☐ No
29. Availability and Service Resilience
Q138. Are service availability requirements defined?
☐ Yes ☐ No
Q139. Are critical components designed for resilience?
☐ Yes ☐ No ☐ N/A
Q140. Is service availability monitored?
☐ Yes ☐ No
Q141. Are major outages investigated?
☐ Yes ☐ No
Q142. Are customers notified of significant service disruptions where appropriate?
☐ Yes ☐ No
30. Change Management
Q143. Does the supplier have a formal change-management process?
☐ Yes ☐ No
Q144. Are security impacts assessed before significant changes?
☐ Yes ☐ No
Q145. Are changes tested before production deployment where appropriate?
☐ Yes ☐ No
Q146. Are emergency changes documented and reviewed?
☐ Yes ☐ No ☐ N/A
31. Information Transfer
Q147. Are customer information transfers controlled?
☐ Yes ☐ No
Q148. Are approved secure communication channels used?
☐ Yes ☐ No
Q149. Is sensitive information protected during transfer?
☐ Yes ☐ No
Q150. Are external recipients verified before sensitive information is shared?
☐ Yes ☐ No ☐ N/A
32. Third-Party and Subprocessor Management
Q151. Does the supplier use subcontractors or subprocessors?
☐ Yes ☐ No
If yes, identify significant subprocessors:
Q152. Does the supplier assess the security of its subprocessors?
☐ Yes ☐ No
Q153. Are security requirements flowed down to relevant subprocessors?
☐ Yes ☐ No
Q154. Are customers informed of material subprocessor changes where required?
☐ Yes ☐ No ☐ Contract-dependent
Q155. Can the supplier identify where subprocessors process customer information?
☐ Yes ☐ No
33. Data Location and International Transfers
Q156. In which countries is customer information stored?
Q157. In which countries is customer information processed?
Q158. Is customer information transferred across borders?
☐ Yes ☐ No
Q159. Are applicable data-transfer requirements assessed?
☐ Yes ☐ No ☐ N/A
34. Privacy and Data Protection
Q160. Does the supplier maintain a privacy/data-protection program?
☐ Yes ☐ No ☐ N/A
Q161. Is there a designated privacy responsibility?
☐ Yes ☐ No ☐ N/A
Q162. Are personal-data processing activities documented?
☐ Yes ☐ No ☐ N/A
Q163. Are data-subject rights supported where applicable?
☐ Yes ☐ No ☐ N/A
Q164. Is personal data retained only for defined purposes and periods?
☐ Yes ☐ No ☐ N/A
35. AI and Generative AI
Complete where the supplier uses AI in providing the service.
Q165. Does the service use generative AI or machine-learning technologies?
☐ Yes ☐ No
Q166. Is customer information used as input to AI systems?
☐ Yes ☐ No
Q167. Is customer information used to train AI models?
☐ Yes ☐ No ☐ Contract-dependent
Q168. Can customers opt out of model training where applicable?
☐ Yes ☐ No ☐ N/A
Q169. Are AI-related security and privacy risks assessed?
☐ Yes ☐ No ☐ N/A
Q170. Are AI service providers/subprocessors disclosed where relevant?
☐ Yes ☐ No ☐ N/A
36. Secure Development and Software Supply Chain
Where applicable:
Q171. Are third-party software dependencies identified?
☐ Yes ☐ No ☐ N/A
Q172. Are software dependencies monitored for vulnerabilities?
☐ Yes ☐ No ☐ N/A
Q173. Is software composition analysis performed?
☐ Yes ☐ No ☐ N/A
Q174. Is source-code access restricted?
☐ Yes ☐ No ☐ N/A
Q175. Is code-signing or equivalent release integrity protection used where appropriate?
☐ Yes ☐ No ☐ N/A
37. Security Testing
Q176. Does the supplier conduct periodic security testing?
☐ Yes ☐ No
Q177. Is penetration testing performed where appropriate?
☐ Yes ☐ No ☐ N/A
Q178. Are critical findings tracked through remediation?
☐ Yes ☐ No
Q179. Is retesting performed after significant remediation?
☐ Yes ☐ No ☐ N/A
38. Supplier Security Monitoring
Q180. Does the supplier monitor security events continuously or according to defined risk-based requirements?
☐ Yes ☐ No
Q181. Are critical security alerts escalated?
☐ Yes ☐ No
Q182. Are supplier security metrics reported to management?
☐ Yes ☐ No
39. Security Incident History
Please disclose relevant significant security incidents affecting the service within the period requested by the customer, subject to legal and contractual restrictions.
Q183. Has the service experienced a significant security incident?
☐ Yes ☐ No
If yes:
Date: __________________
Description:
Impact:
Corrective Actions:
Customer Notification:
40. Regulatory and Legal Requirements
Q184. What laws, regulations, or industry requirements are relevant to the service?
Q185. Does the supplier maintain a process for monitoring applicable regulatory changes?
☐ Yes ☐ No
Q186. Are contractual security requirements reviewed periodically?
☐ Yes ☐ No
41. Contractual Security Requirements
Q187. Does the supplier agree to appropriate confidentiality requirements?
☐ Yes ☐ No
Q188. Does the supplier agree to defined security requirements?
☐ Yes ☐ No
Q189. Are security incident notification obligations defined?
☐ Yes ☐ No
Q190. Are data-return/deletion requirements defined?
☐ Yes ☐ No
Q191. Are subprocessor requirements defined?
☐ Yes ☐ No
Q192. Are termination and access-revocation requirements defined?
☐ Yes ☐ No
42. Audit and Assurance
Q193. Can the supplier provide independent security assurance?
☐ Yes ☐ No
Q194. Can relevant security documentation be reviewed?
☐ Yes ☐ No ☐ Subject to NDA
Q195. Are security assessments or audits performed periodically?
☐ Yes ☐ No
Q196. Are material security findings tracked to closure?
☐ Yes ☐ No
43. Supplier Termination and Data Disposal
Q197. Does the supplier have a documented termination process?
☐ Yes ☐ No
Q198. Can customer information be returned upon termination?
☐ Yes ☐ No ☐ Contract-dependent
Q199. Can customer information be securely deleted upon termination?
☐ Yes ☐ No ☐ Contract-dependent
Q200. Can deletion or return be evidenced where required?
☐ Yes ☐ No
Q201. Is customer access revoked after termination?
☐ Yes ☐ No
44. Security Contacts
| Contact | Name | Role | Phone | |
|---|---|---|---|---|
| Security Contact | ||||
| Incident Contact | ||||
| Privacy Contact | ||||
| Technical Contact | ||||
| Business Contact |
45. Supporting Evidence
Please identify documents that can support questionnaire responses.
| Evidence | Available | Reference/Location |
|---|---|---|
| ISO 27001 Certificate | ☐ | |
| SOC 2 Report | ☐ | |
| Security Policy | ☐ | |
| Penetration Test | ☐ | |
| Vulnerability Assessment | ☐ | |
| Business Continuity Evidence | ☐ | |
| Incident Response Procedure | ☐ | |
| Privacy Documentation | ☐ | |
| Security Architecture | ☐ | |
| Data Processing Agreement | ☐ | |
| Other | ☐ |
46. Supplier Declaration
The supplier confirms that the information provided in this questionnaire is accurate to the best of its knowledge as of the completion date.
The supplier agrees to notify the organization of material changes that may significantly affect the security of the service, where required by contract or applicable arrangements.
Supplier Representative
Name: ______________________________
Title: _______________________________
Organization: ________________________
Signature/Approval: ___________________
Date: ________________________________
47. Internal Review Section
This section should be completed by the organization.
Reviewer
Name: ______________________________
Role: _______________________________
Review Date: _________________________
Questionnaire Assessment
☐ Satisfactory
☐ Additional Information Required
☐ Security Gaps Identified
☐ Additional Risk Assessment Required
☐ Additional Contractual Controls Required
☐ Management Review Required
48. Security Findings
| Finding ID | Questionnaire Ref. | Finding | Risk | Required Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
49. Risk Assessment Summary
The questionnaire should not be treated as the risk assessment itself.
Use the responses as inputs to the organization’s Supplier Risk Assessment.
Key Risk Factors
| Risk Area | Result |
|---|---|
| Information Sensitivity | |
| System Criticality | |
| Supplier Access | |
| Privileged Access | |
| Customer Data | |
| Personal Data | |
| Business Dependency | |
| Security Assurance | |
| Incident History | |
| Subprocessors | |
| Business Continuity | |
| Regulatory Exposure |
Overall Supplier Risk
☐ Low
☐ Medium
☐ High
☐ Critical
Rationale
50. Risk Treatment
| Risk | Treatment | Control/Action | Owner | Due Date | Status |
|---|---|---|---|---|---|
Possible treatments include:
- Additional security controls
- Contractual requirements
- Reduced access
- Additional monitoring
- Additional security evidence
- Security testing
- Data minimization
- Compensating controls
- Risk acceptance
- Supplier replacement
51. Approval
Business Owner
Name: ______________________________
Decision: ___________________________
Date: ________________________________
Security/ISMS
Name: ______________________________
Decision: ___________________________
Date: ________________________________
Procurement
Name: ______________________________
Decision: ___________________________
Date: ________________________________
Privacy/Legal, Where Required
Name: ______________________________
Decision: ___________________________
Date: ________________________________
52. Periodic Review
The questionnaire should be refreshed when appropriate based on supplier risk.
Review triggers may include:
- New service
- New information processed
- New production access
- New privileged access
- Significant security incident
- Major vulnerability
- New subprocessor
- Data-location change
- Contract change
- Regulatory change
- Significant supplier change
- Periodic supplier review
The review frequency should be defined using the organization’s supplier-risk methodology.
53. Startup-Friendly Questionnaire Approach
A startup does not necessarily need to send all 200 questions to every supplier.
Use a risk-based questionnaire.
Low-Risk Supplier
Focus on:
- Service
- Information
- Access
- Basic security controls
- Incident reporting
- Contractual requirements
Medium-Risk Supplier
Add:
- Access management
- MFA
- Encryption
- Vulnerability management
- Backup
- Business continuity
- Security assurance
High/Critical Supplier
Add detailed review of:
- Privileged access
- Cloud security
- Application security
- Security testing
- Incident response
- Subprocessors
- Data location
- Business continuity
- Independent assurance
- Contractual security requirements
- Exit and data-deletion arrangements
This avoids creating unnecessary administrative work while maintaining risk-based supplier governance.
54. Recommended Evidence Trail
The questionnaire should connect to:
Supplier
→ Questionnaire
→ Security Evidence
→ Supplier Risk Assessment
→ Security Findings
→ Risk Treatment
→ Contractual Requirements
→ Supplier Approval
→ Periodic Review
→ Reassessment
→ Exit
55. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Supplier Security Management Policy | Defines supplier-security requirements |
| Supplier Register | Identifies suppliers |
| Supplier Risk Assessment | Evaluates risks using questionnaire results |
| Supplier Security Assessment | Provides deeper control assessment |
| Supplier Review Record | Periodic supplier review |
| Third-Party Access Procedure | Controls supplier access |
| Contractor Account Procedure | Controls contractor accounts |
| Access Rights Register | Records supplier permissions |
| Privileged Access Register | Records supplier privileged access |
| SaaS Application Register | Tracks SaaS suppliers |
| Cloud Asset Inventory | Tracks cloud dependencies |
| External Data Sharing Procedure | Controls external information sharing |
| Third-Party Information Sharing Agreement | Establishes information-sharing requirements |
| Incident Management | Handles supplier incidents |
| Risk Register | Records significant supplier risks |
| Business Continuity | Addresses supplier dependency |
56. ISO 27001 Connection
The questionnaire supports the organization’s risk-based management of supplier relationships, including areas relating to:
- Supplier relationships
- Supplier agreements
- ICT supply-chain security
- Monitoring of supplier services
- Information transfer
- Access control
- Incident management
- Business continuity
- Information protection
- Risk management
The questionnaire itself is not an ISO 27001 mandatory form. The organization should determine the questions and evidence required based on its risks, supplier relationships, contractual obligations, and applicable requirements.
57. Quick Internal Review Checklist
☐ Supplier identified
☐ Service understood
☐ Information identified
☐ Information classification identified
☐ Customer data considered
☐ Personal data considered
☐ Supplier access identified
☐ Privileged access assessed
☐ Security governance assessed
☐ Access controls assessed
☐ MFA assessed
☐ Vulnerability management assessed
☐ Incident management assessed
☐ Encryption assessed
☐ Backup/recovery assessed
☐ Business continuity assessed
☐ Subprocessors assessed
☐ Data location assessed
☐ Security assurance reviewed
☐ Contractual requirements assessed
☐ Termination/data deletion assessed
☐ Findings recorded
☐ Supplier risk assessment completed
☐ Risk treatment defined
☐ Approval completed
☐ Review date established
58. Final Audit Trail
For each supplier, the organization should be able to demonstrate:
Supplier identified → Questionnaire completed → Evidence reviewed → Security gaps identified → Supplier risk assessed → Controls/treatment defined → Risk accepted or reduced → Supplier approved → Supplier monitored → Periodically reassessed
Final Principle
Do not use a supplier questionnaire simply to collect “Yes/No” answers. Use it to understand the supplier’s actual security environment, verify important claims with appropriate evidence, identify gaps, assess the resulting risk, and determine what controls or contractual requirements are necessary.
