Security Answer Kit

All guides

Vulnerability management questions in a security questionnaire

Vulnerability questions ask how you find and fix weaknesses: patch times, dependency scanning, penetration tests, a reporting address and a bug bounty. Answer with what you do, not with a claim you cannot back.

What the client wants to know

The client wants to know that known flaws in your software and servers get fixed, and that an outsider who finds a problem has somewhere to report it. A penetration test is a common question, but a small team without one can still answer well by describing the alerts and reviews it does run.

The 5 questions as clients phrase them

The kit covers 5 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. How do you manage vulnerabilities in your software and systems?
  2. Have you had an external penetration test?
  3. Do you have a way for people to report security issues?
  4. Do you scan your code and dependencies for vulnerabilities?
  5. Do you have a bug bounty or responsible disclosure policy?

What a good answer contains

Watch out for

Do not claim a penetration test you did not commission. Pen tests are optional for small firms. Say so, and do not pad the answer.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: How do you manage vulnerabilities in your software and systems?

Dependency and vulnerability alerts are switched on for our code.

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Secure development Logging and monitoring

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.