Security Answer Kit

Security questionnaire guides for small software companies

A client sent you a vendor security questionnaire. These guides explain what each group of questions is asking and how to answer honestly.

Start here

The questions, area by area

Each guide lists the questions clients ask in one area, what they want to know, and what a good answer contains. The kit prepares 86 answers across these 16 areas.

  1. Governance questions in a security questionnaire: owner, policy, certifications (6 questions)
  2. People and HR security questions: training, leavers, background checks (7 questions)
  3. Access control questions: MFA, passwords, SSO and least privilege (11 questions)
  4. Device security questions: laptop encryption, updates, MDM, lost devices (8 questions)
  5. Data protection questions: location, separation, deletion and AI training (8 questions)
  6. Encryption questions: in transit, at rest, keys, backups and TLS versions (5 questions)
  7. Backup and continuity questions: restore tests, RTO, RPO, key person risk (6 questions)
  8. Logging and monitoring questions: audit logs, alerts, retention (4 questions)
  9. Vulnerability management questions: patching, pen tests, disclosure (5 questions)
  10. Secure development questions: code review, environments, secrets (4 questions)
  11. Incident response questions: plan, 72-hour notice, breach history, contacts (5 questions)
  12. Vendor and subprocessor questions: lists, assessments, notice of changes (3 questions)
  13. Privacy and GDPR questions: DPA, transfers outside the EU, DPO, data subject requests (5 questions)
  14. Physical security questions for remote and small teams (3 questions)
  15. Change management questions: tracked changes, rollback, emergency fixes (3 questions)
  16. AI tool questions in a security questionnaire: policy, client data, subprocessors (3 questions)

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.