Security Answer Kit

All guides

Encryption questions in a vendor security questionnaire

Encryption questions come in five usual forms: in transit, at rest, key management, encrypted backups and TLS versions. For a small team on a major cloud provider, most answers rest on the provider's default settings.

What the client wants to know

The client wants to know that data cannot be read on the wire or on a stolen disk, and who holds the keys. They do not expect you to run your own key infrastructure. They expect you to know what your providers do and to have checked that it is switched on.

The 5 questions as clients phrase them

The kit covers 5 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Is data encrypted in transit?
  2. Is data encrypted at rest?
  3. How are encryption keys managed?
  4. Are backups encrypted?
  5. Which TLS versions do your services support?

What a good answer contains

Watch out for

Provider default encryption counts, but only if you confirmed it is on for every database and file store. If one store is not covered, say it is being switched on.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: How are encryption keys managed?

Keys are managed by our hosting providers' key management services ([your hosting providers]).

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Data protection Backups and continuity

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.