Access control questions in a security questionnaire
Access control is the largest area in the kit, 11 of its 86 questions: MFA, passwords, shared accounts, single sign-on and how often access is reviewed.
What the client wants to know
The client wants to know that only the right people can reach their data, that a stolen password is not enough, and that access can be removed quickly. The same few controls come back in different wording: MFA on all users, MFA on email, MFA on code repositories, MFA for admin and remote access. One honest fact about MFA answers all of them.
The 11 questions as clients phrase them
The kit covers 11 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Is multi-factor authentication (MFA) enforced for all users?
- Is MFA required for remote and administrative access?
- How are passwords managed and stored?
- Do you follow the principle of least privilege?
- How often are user access rights reviewed?
- Are shared or generic accounts used?
- Do you use single sign-on (SSO) for your business applications?
- Is there one central place to disable a user's access?
- Is MFA enforced on your email system?
- Is MFA enforced on your source code repositories?
- Do you have a password policy?
What a good answer contains
- MFA: name the systems it covers, for example email, code hosting, cloud consoles and admin panels, and say authenticator apps or security keys are preferred.
- Passwords: a company password manager, unique passwords per service, nothing shared in chat or documents.
- Shared accounts: personal accounts wherever the service supports them. Where a shared login cannot be avoided, it sits in the password manager with named access.
- Least privilege and reviews: access per role and project, admin rights limited, rights reviewed at least every 6 months and when someone changes role or leaves.
- SSO: if you have one identity provider, say access is granted and removed in one place. If not, say how the leaver checklist covers each application.
Watch out for
If MFA is not on every account yet, do not answer yes. Say which systems have it, say enabling it everywhere is the first priority, and give the date. The free Security Overview builder lists the exact fix for each gap.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Access: Multi-factor authentication is required on email, code hosting, cloud consoles and admin panels. If not yet: Turn on MFA for every account in email, code hosting, cloud consoles and admin panels. Use an authenticator app or security key, not SMS, where possible.
- Access: All staff use a password manager. Passwords are not shared in chat or documents. If not yet: Roll out a password manager for everyone and move shared logins into shared vaults.
- Access: Access rights are reviewed at least every 6 months. If not yet: Put a review in the calendar every 6 months. List who has admin access to each system and remove what is not needed.
- Access: Staff sign in to the main business apps through one identity provider with MFA. If not yet: Connect your main apps to one identity provider (for example Google Workspace or Microsoft Entra ID) so access is granted and removed in one place.
Example: how a prepared answer opens
Question: How are passwords managed and stored?
All staff use a company password manager.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.