Vulnerability management questions in a security questionnaire
Vulnerability questions ask how you find and fix weaknesses: patch times, dependency scanning, penetration tests, a reporting address and a bug bounty. Answer with what you do, not with a claim you cannot back.
What the client wants to know
The client wants to know that known flaws in your software and servers get fixed, and that an outsider who finds a problem has somewhere to report it. A penetration test is a common question, but a small team without one can still answer well by describing the alerts and reviews it does run.
The 5 questions as clients phrase them
The kit covers 5 questions in this area. The wording varies between questionnaires, the control behind it does not.
- How do you manage vulnerabilities in your software and systems?
- Have you had an external penetration test?
- Do you have a way for people to report security issues?
- Do you scan your code and dependencies for vulnerabilities?
- Do you have a bug bounty or responsible disclosure policy?
What a good answer contains
- Patching: dependency and vulnerability alerts switched on, servers and dependencies patched on a schedule. Give fix times, for example critical issues within 7 days and high within 30 days, only if you will meet them.
- Scanning: alerts enabled on all code repositories and handled within the stated fix times.
- Penetration test: if one was done in the last 12 months, say a summary is available under NDA. If not, say so, describe what you rely on instead and offer a scoped test if the engagement requires it.
- Reporting: a contact address and an acknowledgement time, for example 2 working days.
- Bug bounty: it is fine to say you run no paid bounty but accept reports at your security address.
Watch out for
Do not claim a penetration test you did not commission. Pen tests are optional for small firms. Say so, and do not pad the answer.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Monitoring: Dependencies and servers are patched on a schedule, with alerts for known vulnerabilities. If not yet: Switch on dependency alerts (for example Dependabot or Renovate) and set a monthly patch day for servers.
- Assurance: An external penetration test was done in the last 12 months. If not yet: Optional for small firms. If clients ask, budget for a scoped external test of the main application.
Example: how a prepared answer opens
Question: How do you manage vulnerabilities in your software and systems?
Dependency and vulnerability alerts are switched on for our code.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.