Encryption questions in a vendor security questionnaire
Encryption questions come in five usual forms: in transit, at rest, key management, encrypted backups and TLS versions. For a small team on a major cloud provider, most answers rest on the provider's default settings.
What the client wants to know
The client wants to know that data cannot be read on the wire or on a stolen disk, and who holds the keys. They do not expect you to run your own key infrastructure. They expect you to know what your providers do and to have checked that it is switched on.
The 5 questions as clients phrase them
The kit covers 5 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Is data encrypted in transit?
- Is data encrypted at rest?
- How are encryption keys managed?
- Are backups encrypted?
- Which TLS versions do your services support?
What a good answer contains
- In transit: all services use HTTPS or TLS, and plain HTTP is redirected or disabled.
- At rest: stored client data is encrypted using the encryption of your hosting providers. Name the providers.
- Keys: managed by the providers' key management services. Staff do not handle raw keys. Application secrets live in a secret store or the password manager, not in code.
- Backups: encryption at rest covers backups held with the same providers.
- TLS versions: TLS 1.2 or higher through your providers. Check that older versions are switched off on every service you run before you say so.
Watch out for
Provider default encryption counts, but only if you confirmed it is on for every database and file store. If one store is not covered, say it is being switched on.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Encryption: All services use encryption in transit (HTTPS or TLS). If not yet: Force HTTPS on every site and API and turn off plain HTTP and old TLS versions.
- Encryption: Stored client data is encrypted at rest. If not yet: Check that disks, databases and storage buckets use encryption at rest. Most cloud providers can switch this on in settings.
Example: how a prepared answer opens
Question: How are encryption keys managed?
Keys are managed by our hosting providers' key management services ([your hosting providers]).
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.