ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Supplier Security Questionnaire

Supplier Security Questionnaire

1. Purpose

This questionnaire is used to assess the information-security practices of suppliers and third-party service providers before onboarding and during periodic supplier reviews.

It helps the organization understand:

  • What services the supplier provides
  • What information and systems are involved
  • How information is protected
  • How access is controlled
  • How incidents are managed
  • How vulnerabilities are handled
  • How business continuity is maintained
  • Whether subcontractors or subprocessors are involved
  • What security assurance is available

The questionnaire should be completed based on the supplier’s actual services and environment. Not every question will apply to every supplier.

Core Principle

Understand the Supplier → Assess the Risk → Verify Controls → Identify Gaps → Treat Risk → Monitor


2. Supplier Information

FieldSupplier Response
Supplier Name
Legal Entity Name
Service/Product Name
Service Description
Supplier Contact
Security Contact
Privacy Contact
Business Owner
Contract/SOW Reference
Service Start Date
Service Location
Data Processing Location
Countries of Operation
Number of Employees
Number of Security Personnel
Questionnaire Completion Date
Completed By
Reviewed By

3. Instructions to Supplier

Please answer each question using:

  • Yes
  • No
  • Partially
  • Not Applicable

Where the answer is Yes or Partially, provide supporting information or evidence where appropriate.

Where the answer is No, explain whether an alternative control exists.

Where Not Applicable is selected, provide a brief justification where the question may reasonably appear relevant.

Evidence

Do not provide passwords, API keys, private keys, access tokens, authentication secrets, or other confidential credentials.

Sensitive security evidence should be shared through an approved secure channel.


4. Service and Security Scope

4.1 Service Description

Q1. Please describe the service being provided.

Response:

Q2. What business functions does the service support?

Response:

Q3. Is the service business-critical?

☐ Yes ☐ No ☐ Partially

Q4. What would be the expected impact if the service became unavailable?

Q5. Does the service connect to the customer’s systems?

☐ Yes ☐ No

If yes, describe the integration:


5. Information and Data

Q6. Does the supplier access, process, store, or transmit customer information?

☐ Yes ☐ No

Q7. Does the supplier process personal data?

☐ Yes ☐ No

Q8. Does the supplier process financial or payment information?

☐ Yes ☐ No

Q9. Does the supplier process confidential business information?

☐ Yes ☐ No

Q10. Does the supplier process security-related information?

☐ Yes ☐ No

Q11. Does the supplier store customer information?

☐ Yes ☐ No

Q12. What categories of information are processed?

Q13. What is the information retention period?

Q14. Can customers request deletion or return of information?

☐ Yes ☐ No ☐ Contract-dependent

Details:


6. Data Classification and Protection

Q15. Does the supplier have an information-classification process?

☐ Yes ☐ No

Q16. Are customer information and confidential information handled according to defined security requirements?

☐ Yes ☐ No ☐ Partially

Q17. Are appropriate controls applied based on information sensitivity?

☐ Yes ☐ No ☐ Partially

Q18. Is customer information logically separated from other customers?

☐ Yes ☐ No ☐ N/A

Details:


7. Information Security Governance

Q19. Does the supplier maintain a formal information-security program?

☐ Yes ☐ No

Q20. Is there a person or team responsible for information security?

☐ Yes ☐ No

Q21. Does senior management have oversight of information security?

☐ Yes ☐ No

Q22. Does the supplier maintain information-security policies?

☐ Yes ☐ No

Q23. Are security policies periodically reviewed?

☐ Yes ☐ No

Q24. Does the supplier conduct periodic information-security risk assessments?

☐ Yes ☐ No


8. Security Certifications and Assurance

Q25. Is the organization certified against ISO/IEC 27001?

☐ Yes ☐ No

If yes:

Certificate Number: __________________

Certification Body: __________________

Expiry Date: __________________

Scope:

Q26. Does the supplier have a SOC 2 report?

☐ Yes ☐ No

If yes:

☐ Type I
☐ Type II

Report Period: __________________

Scope:

Q27. Does the supplier have other relevant security certifications or independent assessments?

☐ Yes ☐ No

Details:

Q28. Can relevant security assurance documentation be provided for review?

☐ Yes ☐ No ☐ Subject to NDA/contract


9. Risk Management

Q29. Does the supplier maintain a formal security-risk management process?

☐ Yes ☐ No

Q30. Are information-security risks documented?

☐ Yes ☐ No

Q31. Are risk owners assigned?

☐ Yes ☐ No

Q32. Are identified risks periodically reviewed?

☐ Yes ☐ No

Q33. Are significant security risks reported to management?

☐ Yes ☐ No


10. Identity and Access Management

Q34. Are individual user accounts used instead of shared accounts?

☐ Yes ☐ No ☐ Where practical

Q35. Is access granted based on business need?

☐ Yes ☐ No

Q36. Is least privilege applied?

☐ Yes ☐ No

Q37. Is user access periodically reviewed?

☐ Yes ☐ No

Q38. Are access rights removed when personnel leave or change roles?

☐ Yes ☐ No

Q39. Are privileged accounts separately controlled?

☐ Yes ☐ No ☐ N/A

Q40. Is privileged access periodically reviewed?

☐ Yes ☐ No ☐ N/A


11. Authentication and MFA

Q41. Is MFA implemented for administrative or privileged access?

☐ Yes ☐ No ☐ N/A

Q42. Is MFA implemented for remote access?

☐ Yes ☐ No ☐ N/A

Q43. Is MFA available to customer users?

☐ Yes ☐ No ☐ N/A

Q44. Are passwords protected against common or compromised passwords?

☐ Yes ☐ No ☐ N/A

Q45. Are authentication credentials securely stored?

☐ Yes ☐ No

Q46. Are authentication failures monitored?

☐ Yes ☐ No


12. Privileged Access

Q47. Does the supplier provide privileged access to customer environments?

☐ Yes ☐ No

Q48. Is privileged access restricted to authorized personnel?

☐ Yes ☐ No

Q49. Is privileged access individually attributable?

☐ Yes ☐ No

Q50. Is privileged access logged?

☐ Yes ☐ No

Q51. Is privileged access reviewed periodically?

☐ Yes ☐ No

Q52. Is temporary or just-in-time privileged access used where practical?

☐ Yes ☐ No ☐ N/A


13. Personnel Security

Q53. Are personnel subject to appropriate pre-employment screening where legally permitted and appropriate?

☐ Yes ☐ No ☐ Role-dependent

Q54. Are employees required to sign confidentiality agreements?

☐ Yes ☐ No

Q55. Do employees receive security-awareness training?

☐ Yes ☐ No

Q56. Is security training provided periodically?

☐ Yes ☐ No

Q57. Are personnel security responsibilities defined?

☐ Yes ☐ No

Q58. Is access revoked promptly when personnel leave?

☐ Yes ☐ No


14. Security Awareness

Q59. Does the supplier conduct security-awareness training?

☐ Yes ☐ No

Q60. Does training cover phishing and social engineering?

☐ Yes ☐ No

Q61. Does training cover protection of customer information?

☐ Yes ☐ No

Q62. Does training cover incident reporting?

☐ Yes ☐ No

Q63. Is security awareness tailored to privileged or technical roles?

☐ Yes ☐ No ☐ Partially


15. Physical Security

Q64. Are facilities hosting customer systems or information physically secured?

☐ Yes ☐ No ☐ N/A

Q65. Is physical access controlled?

☐ Yes ☐ No ☐ N/A

Q66. Are visitors controlled and monitored?

☐ Yes ☐ No ☐ N/A

Q67. Are critical facilities protected against environmental threats?

☐ Yes ☐ No ☐ N/A

Q68. Are physical-security controls periodically reviewed?

☐ Yes ☐ No ☐ N/A


16. Endpoint Security

Q69. Are company-managed endpoints protected against malware?

☐ Yes ☐ No ☐ N/A

Q70. Are security patches applied to endpoints?

☐ Yes ☐ No

Q71. Is disk encryption used where appropriate?

☐ Yes ☐ No ☐ N/A

Q72. Are administrative privileges restricted on employee devices?

☐ Yes ☐ No ☐ N/A

Q73. Are lost or stolen devices subject to security controls such as remote lock/wipe where appropriate?

☐ Yes ☐ No ☐ N/A


17. Network Security

Q74. Are network security controls implemented?

☐ Yes ☐ No

Q75. Are network boundaries and trust zones defined?

☐ Yes ☐ No ☐ N/A

Q76. Are firewalls or equivalent controls implemented?

☐ Yes ☐ No ☐ N/A

Q77. Is network traffic monitored where appropriate?

☐ Yes ☐ No

Q78. Are unauthorized network connections restricted?

☐ Yes ☐ No


18. Cloud Security

Complete this section where cloud services are used.

Q79. Does the supplier use public cloud infrastructure?

☐ Yes ☐ No

Q80. Which cloud providers are used?

Q81. Are cloud accounts centrally managed?

☐ Yes ☐ No ☐ N/A

Q82. Is cloud administrative access protected with MFA?

☐ Yes ☐ No ☐ N/A

Q83. Are cloud permissions based on least privilege?

☐ Yes ☐ No ☐ N/A

Q84. Are cloud activities logged?

☐ Yes ☐ No ☐ N/A

Q85. Are cloud configurations periodically reviewed?

☐ Yes ☐ No ☐ N/A

Q86. Are cloud backups implemented where required?

☐ Yes ☐ No ☐ N/A


19. Application Security

Q87. Does the supplier follow a secure software-development lifecycle?

☐ Yes ☐ No ☐ N/A

Q88. Are security requirements defined during application development?

☐ Yes ☐ No ☐ N/A

Q89. Is source code reviewed?

☐ Yes ☐ No ☐ N/A

Q90. Are security vulnerabilities identified during development?

☐ Yes ☐ No ☐ N/A

Q91. Is security testing performed before significant releases?

☐ Yes ☐ No ☐ N/A

Q92. Are security defects tracked and remediated?

☐ Yes ☐ No ☐ N/A


20. Vulnerability Management

Q93. Does the supplier maintain a vulnerability-management process?

☐ Yes ☐ No

Q94. Are systems periodically scanned for vulnerabilities?

☐ Yes ☐ No ☐ N/A

Q95. Are critical vulnerabilities prioritized for remediation?

☐ Yes ☐ No

Q96. Are vulnerabilities tracked until closure?

☐ Yes ☐ No

Q97. Is penetration testing performed where appropriate?

☐ Yes ☐ No ☐ N/A

Q98. Are significant vulnerabilities communicated to customers where contractually or operationally required?

☐ Yes ☐ No ☐ N/A


21. Malware and Endpoint Protection

Q99. Are anti-malware or equivalent endpoint security controls implemented?

☐ Yes ☐ No ☐ N/A

Q100. Are security alerts monitored?

☐ Yes ☐ No

Q101. Are malware incidents investigated?

☐ Yes ☐ No


22. Logging and Monitoring

Q102. Are security-relevant events logged?

☐ Yes ☐ No

Q103. Are administrative activities logged?

☐ Yes ☐ No

Q104. Are authentication events logged?

☐ Yes ☐ No

Q105. Are logs protected against unauthorized modification?

☐ Yes ☐ No

Q106. Are security logs monitored?

☐ Yes ☐ No

Q107. Are logs retained according to defined requirements?

☐ Yes ☐ No


23. Security Incident Management

Q108. Does the supplier maintain a formal incident-response process?

☐ Yes ☐ No

Q109. Is there a defined security incident-response team or responsible function?

☐ Yes ☐ No

Q110. Are security incidents documented?

☐ Yes ☐ No

Q111. Are incidents investigated and contained?

☐ Yes ☐ No

Q112. Is there a process for notifying customers of relevant security incidents?

☐ Yes ☐ No

Q113. Are incident notification timelines defined contractually where appropriate?

☐ Yes ☐ No ☐ Contract-dependent

Q114. Are lessons learned performed after significant incidents?

☐ Yes ☐ No


24. Data Breach Management

Q115. Does the supplier maintain a process for responding to personal-data breaches?

☐ Yes ☐ No ☐ N/A

Q116. Can the supplier identify affected information and customers during an incident?

☐ Yes ☐ No

Q117. Does the supplier support investigation and evidence preservation?

☐ Yes ☐ No

Q118. Does the supplier support applicable customer/regulatory notification requirements?

☐ Yes ☐ No ☐ Contract-dependent


25. Encryption

Q119. Is sensitive information encrypted during transmission?

☐ Yes ☐ No ☐ N/A

Q120. Is sensitive information encrypted at rest?

☐ Yes ☐ No ☐ N/A

Q121. Are cryptographic keys appropriately protected?

☐ Yes ☐ No ☐ N/A

Q122. Is access to encryption keys restricted?

☐ Yes ☐ No ☐ N/A

Q123. Are keys/certificates managed throughout their lifecycle?

☐ Yes ☐ No ☐ N/A


26. Secrets and Credentials

Q124. Are passwords, API keys, tokens, and other secrets stored securely?

☐ Yes ☐ No ☐ N/A

Q125. Are secrets prevented from being stored in source code?

☐ Yes ☐ No ☐ N/A

Q126. Are exposed or compromised credentials promptly revoked or rotated?

☐ Yes ☐ No

Q127. Are service-account credentials managed securely?

☐ Yes ☐ No ☐ N/A


27. Backup and Recovery

Q128. Is customer information backed up where required?

☐ Yes ☐ No ☐ N/A

Q129. Are backups protected from unauthorized access?

☐ Yes ☐ No

Q130. Are backups encrypted where appropriate?

☐ Yes ☐ No ☐ N/A

Q131. Are backup restoration procedures tested?

☐ Yes ☐ No

Q132. Are recovery objectives defined for critical services?

☐ Yes ☐ No ☐ N/A


28. Business Continuity and Disaster Recovery

Q133. Does the supplier maintain a business-continuity plan?

☐ Yes ☐ No

Q134. Does the supplier maintain disaster-recovery procedures?

☐ Yes ☐ No

Q135. Are recovery procedures periodically tested?

☐ Yes ☐ No

Q136. Are critical services supported by appropriate resilience measures?

☐ Yes ☐ No ☐ N/A

Q137. Can the supplier provide relevant continuity assurance?

☐ Yes ☐ No


29. Availability and Service Resilience

Q138. Are service availability requirements defined?

☐ Yes ☐ No

Q139. Are critical components designed for resilience?

☐ Yes ☐ No ☐ N/A

Q140. Is service availability monitored?

☐ Yes ☐ No

Q141. Are major outages investigated?

☐ Yes ☐ No

Q142. Are customers notified of significant service disruptions where appropriate?

☐ Yes ☐ No


30. Change Management

Q143. Does the supplier have a formal change-management process?

☐ Yes ☐ No

Q144. Are security impacts assessed before significant changes?

☐ Yes ☐ No

Q145. Are changes tested before production deployment where appropriate?

☐ Yes ☐ No

Q146. Are emergency changes documented and reviewed?

☐ Yes ☐ No ☐ N/A


31. Information Transfer

Q147. Are customer information transfers controlled?

☐ Yes ☐ No

Q148. Are approved secure communication channels used?

☐ Yes ☐ No

Q149. Is sensitive information protected during transfer?

☐ Yes ☐ No

Q150. Are external recipients verified before sensitive information is shared?

☐ Yes ☐ No ☐ N/A


32. Third-Party and Subprocessor Management

Q151. Does the supplier use subcontractors or subprocessors?

☐ Yes ☐ No

If yes, identify significant subprocessors:

Q152. Does the supplier assess the security of its subprocessors?

☐ Yes ☐ No

Q153. Are security requirements flowed down to relevant subprocessors?

☐ Yes ☐ No

Q154. Are customers informed of material subprocessor changes where required?

☐ Yes ☐ No ☐ Contract-dependent

Q155. Can the supplier identify where subprocessors process customer information?

☐ Yes ☐ No


33. Data Location and International Transfers

Q156. In which countries is customer information stored?

Q157. In which countries is customer information processed?

Q158. Is customer information transferred across borders?

☐ Yes ☐ No

Q159. Are applicable data-transfer requirements assessed?

☐ Yes ☐ No ☐ N/A


34. Privacy and Data Protection

Q160. Does the supplier maintain a privacy/data-protection program?

☐ Yes ☐ No ☐ N/A

Q161. Is there a designated privacy responsibility?

☐ Yes ☐ No ☐ N/A

Q162. Are personal-data processing activities documented?

☐ Yes ☐ No ☐ N/A

Q163. Are data-subject rights supported where applicable?

☐ Yes ☐ No ☐ N/A

Q164. Is personal data retained only for defined purposes and periods?

☐ Yes ☐ No ☐ N/A


35. AI and Generative AI

Complete where the supplier uses AI in providing the service.

Q165. Does the service use generative AI or machine-learning technologies?

☐ Yes ☐ No

Q166. Is customer information used as input to AI systems?

☐ Yes ☐ No

Q167. Is customer information used to train AI models?

☐ Yes ☐ No ☐ Contract-dependent

Q168. Can customers opt out of model training where applicable?

☐ Yes ☐ No ☐ N/A

Q169. Are AI-related security and privacy risks assessed?

☐ Yes ☐ No ☐ N/A

Q170. Are AI service providers/subprocessors disclosed where relevant?

☐ Yes ☐ No ☐ N/A


36. Secure Development and Software Supply Chain

Where applicable:

Q171. Are third-party software dependencies identified?

☐ Yes ☐ No ☐ N/A

Q172. Are software dependencies monitored for vulnerabilities?

☐ Yes ☐ No ☐ N/A

Q173. Is software composition analysis performed?

☐ Yes ☐ No ☐ N/A

Q174. Is source-code access restricted?

☐ Yes ☐ No ☐ N/A

Q175. Is code-signing or equivalent release integrity protection used where appropriate?

☐ Yes ☐ No ☐ N/A


37. Security Testing

Q176. Does the supplier conduct periodic security testing?

☐ Yes ☐ No

Q177. Is penetration testing performed where appropriate?

☐ Yes ☐ No ☐ N/A

Q178. Are critical findings tracked through remediation?

☐ Yes ☐ No

Q179. Is retesting performed after significant remediation?

☐ Yes ☐ No ☐ N/A


38. Supplier Security Monitoring

Q180. Does the supplier monitor security events continuously or according to defined risk-based requirements?

☐ Yes ☐ No

Q181. Are critical security alerts escalated?

☐ Yes ☐ No

Q182. Are supplier security metrics reported to management?

☐ Yes ☐ No


39. Security Incident History

Please disclose relevant significant security incidents affecting the service within the period requested by the customer, subject to legal and contractual restrictions.

Q183. Has the service experienced a significant security incident?

☐ Yes ☐ No

If yes:

Date: __________________

Description:

Impact:

Corrective Actions:

Customer Notification:


40. Regulatory and Legal Requirements

Q184. What laws, regulations, or industry requirements are relevant to the service?

Q185. Does the supplier maintain a process for monitoring applicable regulatory changes?

☐ Yes ☐ No

Q186. Are contractual security requirements reviewed periodically?

☐ Yes ☐ No


41. Contractual Security Requirements

Q187. Does the supplier agree to appropriate confidentiality requirements?

☐ Yes ☐ No

Q188. Does the supplier agree to defined security requirements?

☐ Yes ☐ No

Q189. Are security incident notification obligations defined?

☐ Yes ☐ No

Q190. Are data-return/deletion requirements defined?

☐ Yes ☐ No

Q191. Are subprocessor requirements defined?

☐ Yes ☐ No

Q192. Are termination and access-revocation requirements defined?

☐ Yes ☐ No


42. Audit and Assurance

Q193. Can the supplier provide independent security assurance?

☐ Yes ☐ No

Q194. Can relevant security documentation be reviewed?

☐ Yes ☐ No ☐ Subject to NDA

Q195. Are security assessments or audits performed periodically?

☐ Yes ☐ No

Q196. Are material security findings tracked to closure?

☐ Yes ☐ No


43. Supplier Termination and Data Disposal

Q197. Does the supplier have a documented termination process?

☐ Yes ☐ No

Q198. Can customer information be returned upon termination?

☐ Yes ☐ No ☐ Contract-dependent

Q199. Can customer information be securely deleted upon termination?

☐ Yes ☐ No ☐ Contract-dependent

Q200. Can deletion or return be evidenced where required?

☐ Yes ☐ No

Q201. Is customer access revoked after termination?

☐ Yes ☐ No


44. Security Contacts

ContactNameRoleEmailPhone
Security Contact
Incident Contact
Privacy Contact
Technical Contact
Business Contact

45. Supporting Evidence

Please identify documents that can support questionnaire responses.

EvidenceAvailableReference/Location
ISO 27001 Certificate☐
SOC 2 Report☐
Security Policy☐
Penetration Test☐
Vulnerability Assessment☐
Business Continuity Evidence☐
Incident Response Procedure☐
Privacy Documentation☐
Security Architecture☐
Data Processing Agreement☐
Other☐

46. Supplier Declaration

The supplier confirms that the information provided in this questionnaire is accurate to the best of its knowledge as of the completion date.

The supplier agrees to notify the organization of material changes that may significantly affect the security of the service, where required by contract or applicable arrangements.

Supplier Representative

Name: ______________________________

Title: _______________________________

Organization: ________________________

Signature/Approval: ___________________

Date: ________________________________


47. Internal Review Section

This section should be completed by the organization.

Reviewer

Name: ______________________________

Role: _______________________________

Review Date: _________________________

Questionnaire Assessment

☐ Satisfactory
☐ Additional Information Required
☐ Security Gaps Identified
☐ Additional Risk Assessment Required
☐ Additional Contractual Controls Required
☐ Management Review Required


48. Security Findings

Finding IDQuestionnaire Ref.FindingRiskRequired ActionOwnerDue DateStatus

49. Risk Assessment Summary

The questionnaire should not be treated as the risk assessment itself.

Use the responses as inputs to the organization’s Supplier Risk Assessment.

Key Risk Factors

Risk AreaResult
Information Sensitivity
System Criticality
Supplier Access
Privileged Access
Customer Data
Personal Data
Business Dependency
Security Assurance
Incident History
Subprocessors
Business Continuity
Regulatory Exposure

Overall Supplier Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Rationale


50. Risk Treatment

RiskTreatmentControl/ActionOwnerDue DateStatus

Possible treatments include:

  • Additional security controls
  • Contractual requirements
  • Reduced access
  • Additional monitoring
  • Additional security evidence
  • Security testing
  • Data minimization
  • Compensating controls
  • Risk acceptance
  • Supplier replacement

51. Approval

Business Owner

Name: ______________________________

Decision: ___________________________

Date: ________________________________

Security/ISMS

Name: ______________________________

Decision: ___________________________

Date: ________________________________

Procurement

Name: ______________________________

Decision: ___________________________

Date: ________________________________

Privacy/Legal, Where Required

Name: ______________________________

Decision: ___________________________

Date: ________________________________


52. Periodic Review

The questionnaire should be refreshed when appropriate based on supplier risk.

Review triggers may include:

  • New service
  • New information processed
  • New production access
  • New privileged access
  • Significant security incident
  • Major vulnerability
  • New subprocessor
  • Data-location change
  • Contract change
  • Regulatory change
  • Significant supplier change
  • Periodic supplier review

The review frequency should be defined using the organization’s supplier-risk methodology.


53. Startup-Friendly Questionnaire Approach

A startup does not necessarily need to send all 200 questions to every supplier.

Use a risk-based questionnaire.

Low-Risk Supplier

Focus on:

  • Service
  • Information
  • Access
  • Basic security controls
  • Incident reporting
  • Contractual requirements

Medium-Risk Supplier

Add:

  • Access management
  • MFA
  • Encryption
  • Vulnerability management
  • Backup
  • Business continuity
  • Security assurance

High/Critical Supplier

Add detailed review of:

  • Privileged access
  • Cloud security
  • Application security
  • Security testing
  • Incident response
  • Subprocessors
  • Data location
  • Business continuity
  • Independent assurance
  • Contractual security requirements
  • Exit and data-deletion arrangements

This avoids creating unnecessary administrative work while maintaining risk-based supplier governance.


54. Recommended Evidence Trail

The questionnaire should connect to:

Supplier

→ Questionnaire

→ Security Evidence

→ Supplier Risk Assessment

→ Security Findings

→ Risk Treatment

→ Contractual Requirements

→ Supplier Approval

→ Periodic Review

→ Reassessment

→ Exit


55. Relationship With Other ISMS Documents

DocumentRelationship
Supplier Security Management PolicyDefines supplier-security requirements
Supplier RegisterIdentifies suppliers
Supplier Risk AssessmentEvaluates risks using questionnaire results
Supplier Security AssessmentProvides deeper control assessment
Supplier Review RecordPeriodic supplier review
Third-Party Access ProcedureControls supplier access
Contractor Account ProcedureControls contractor accounts
Access Rights RegisterRecords supplier permissions
Privileged Access RegisterRecords supplier privileged access
SaaS Application RegisterTracks SaaS suppliers
Cloud Asset InventoryTracks cloud dependencies
External Data Sharing ProcedureControls external information sharing
Third-Party Information Sharing AgreementEstablishes information-sharing requirements
Incident ManagementHandles supplier incidents
Risk RegisterRecords significant supplier risks
Business ContinuityAddresses supplier dependency

56. ISO 27001 Connection

The questionnaire supports the organization’s risk-based management of supplier relationships, including areas relating to:

  • Supplier relationships
  • Supplier agreements
  • ICT supply-chain security
  • Monitoring of supplier services
  • Information transfer
  • Access control
  • Incident management
  • Business continuity
  • Information protection
  • Risk management

The questionnaire itself is not an ISO 27001 mandatory form. The organization should determine the questions and evidence required based on its risks, supplier relationships, contractual obligations, and applicable requirements.


57. Quick Internal Review Checklist

☐ Supplier identified
☐ Service understood
☐ Information identified
☐ Information classification identified
☐ Customer data considered
☐ Personal data considered
☐ Supplier access identified
☐ Privileged access assessed
☐ Security governance assessed
☐ Access controls assessed
☐ MFA assessed
☐ Vulnerability management assessed
☐ Incident management assessed
☐ Encryption assessed
☐ Backup/recovery assessed
☐ Business continuity assessed
☐ Subprocessors assessed
☐ Data location assessed
☐ Security assurance reviewed
☐ Contractual requirements assessed
☐ Termination/data deletion assessed
☐ Findings recorded
☐ Supplier risk assessment completed
☐ Risk treatment defined
☐ Approval completed
☐ Review date established


58. Final Audit Trail

For each supplier, the organization should be able to demonstrate:

Supplier identified → Questionnaire completed → Evidence reviewed → Security gaps identified → Supplier risk assessed → Controls/treatment defined → Risk accepted or reduced → Supplier approved → Supplier monitored → Periodically reassessed

Final Principle

Do not use a supplier questionnaire simply to collect “Yes/No” answers. Use it to understand the supplier’s actual security environment, verify important claims with appropriate evidence, identify gaps, assess the resulting risk, and determine what controls or contractual requirements are necessary.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *