People and HR security questions in a vendor questionnaire
People questions cover training, confidentiality, what happens when someone leaves, background checks and contractors. They are easy to answer well once you write the routines down.
What the client wants to know
The client knows that most incidents involve a person: a phished password, a former employee who kept access, a contractor who never saw the rules. These questions check that your team is trained, bound by confidentiality, and that access ends when the job ends. They also check that contractors follow the same rules as employees.
The 7 questions as clients phrase them
The kit covers 7 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Do employees receive security awareness training?
- Do staff sign confidentiality agreements?
- What happens to access when an employee or contractor leaves?
- Is there an acceptable use policy for company systems?
- Do you perform background checks on staff?
- Do contractors follow the same security rules as employees?
- Do you run phishing awareness exercises?
What a good answer contains
- Training: who completes it, how often (at least once a year), what it covers (phishing, passwords, incident reporting) and that attendance is recorded.
- Confidentiality: everyone on client work is bound by terms in their employment or contractor agreement.
- Leavers: a checklist run on the last working day, with access to email, code hosting, cloud accounts, the password manager and client systems removed within 1 working day.
- Background checks: say what you actually check. References and identity before access to client data is a realistic answer for a small team.
Watch out for
Contractors are the usual gap. Say whether they confirm your security policies in writing. If they only sign confidentiality terms, say that and name the date the written policies will be in place.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- People: Staff complete security awareness training at least once a year. If not yet: Run a 1-hour session once a year on phishing, passwords and reporting incidents, and keep an attendance list.
- Access: Access is removed within 1 working day when someone leaves. If not yet: Write a leaver checklist (email, code hosting, cloud, password manager, client systems) and run it on the last working day.
- People: Written security policies exist and staff have read them. If not yet: Write short policies (information security, access, acceptable use, incidents, backups) and have every person confirm they read them.
- People: References and identity are checked before new staff get access to client data. If not yet: Check references and identity before giving a new person access to client data, and keep a short record.
Example: how a prepared answer opens
Question: What happens to access when an employee or contractor leaves?
A leaver checklist is run on the last working day.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.