Discussion
- AuthorPosts
- 2nd August 2026 at 12:06 pm #3317
A long security questionnaire can gather hundreds of “yes” answers without showing how a control actually works. Which responses need evidence, and how should the questions change based on risk?
2nd August 2026 at 12:33 pm #3318Accepted editorial answerStart with the intended use, data, users, connections, and assurance level. Ask about secure development, vulnerability handling, access control, logging, incident response, recovery, subcontractors, software components, and where customer data is stored and how it is protected.
Allow yes, no, partial, not applicable, and alternate-control responses, but require an explanation whenever the answer is not a complete yes. Request current evidence for important claims, such as policies, test summaries, attestations, remediation plans, or product-specific architectures.
CISA’s vendor template provides a consistent, evidence-oriented baseline. Software Acquisition Guide scales questions to the use and assurance level. NIST’s SSDF supplies a common vocabulary for secure development.
- AuthorPosts
- You must be logged in to reply to this topic.