What should a software security questionnaire verify?

Discussion

Verified answerLast verified: 2026-08-02
  • Author
    Posts
  • #3317

    A long security questionnaire can gather hundreds of “yes” answers without showing how a control actually works. Which responses need evidence, and how should the questions change based on risk?

    #3318
    Accepted editorial answer

    Start with the intended use, data, users, connections, and assurance level. Ask about secure development, vulnerability handling, access control, logging, incident response, recovery, subcontractors, software components, and where customer data is stored and how it is protected.

    Allow yes, no, partial, not applicable, and alternate-control responses, but require an explanation whenever the answer is not a complete yes. Request current evidence for important claims, such as policies, test summaries, attestations, remediation plans, or product-specific architectures.

    CISA’s vendor template provides a consistent, evidence-oriented baseline. Software Acquisition Guide scales questions to the use and assurance level. NIST’s SSDF supplies a common vocabulary for secure development.

  • You must be logged in to reply to this topic.

Sign in to reply

Sign in with your Reviews.vc account.

Sign in