25 security questionnaire questions, and how to answer them with evidence.
For each question: what the reader is really looking for, the document that proves the answer, and the mistake that lowers a score. No answers to copy: a generic answer is spotted immediately and costs you trust.
How to use this page
Take your last questionnaire, find the equivalent questions here, and check just one thing: do you have the document listed alongside? If not, the task is not to write a better answer but to write that document.
Version 1, 25 entries. Continuously expanded.
25 questions shown
Do you have an information security policy approved by management?
What the reader is looking for
The reader is checking that a formal framework exists and is backed by executive management, not the literary quality of the document.
The document that proves it
The policy itself, with its approval page: name of the signatory, job title, approval date, date of the next review.
The classic mistake
Answering “yes” without attaching the approval page. An undated, unsigned policy is treated as non-existent.
Who is responsible for information security in your organisation?
What the reader is looking for
An identified contact and a reporting line: the reader wants to know whether the function really exists or is diluted.
The document that proves it
Job description or organisation chart showing the role, its reporting line and its scope.
The classic mistake
Giving a name without a job title or reporting line, or naming an external provider as responsible without specifying internal oversight.
How often do you review your security policies?
What the reader is looking for
A written review frequency and evidence that it is kept, not an intention.
The document that proves it
The policy’s review clause, and the minutes of the last review carried out.
The classic mistake
Answering “regularly” or “at least once a year” without producing the latest minutes. A frequency without evidence of execution does not count.
Do you run security awareness activities for your staff?
What the reader is looking for
A recurring, measured programme, with a coverage rate.
The document that proves it
Awareness programme, schedule, and participation rate for the last financial year.
The classic mistake
Mentioning induction training only. The reader is looking for recurrence and measurement.
Are you ISO/IEC 27001 certified, or equivalent?
What the reader is looking for
The exact scope of the certification, not just the fact that it exists.
The document that proves it
The current certificate, with its expiry date and its scope annex.
The classic mistake
Answering “yes” when only one site or subsidiary is covered. A scope narrower than the service sold is a discrepancy discovered at clarification.
Do you carry out internal security audits?
What the reader is looking for
An audit programme, its independence, and the follow-up of the findings.
The document that proves it
Audit plan, latest report, and corrective action tracker with closure dates.
The classic mistake
Providing the report without the follow-up of findings. An open finding is more visible than one that has been addressed.
How do you manage access and access rights?
What the reader is looking for
The principle applied, least privilege, segregation of duties, and evidence of access reviews.
The document that proves it
Access management procedure and minutes of the latest access rights review.
The classic mistake
Describing the tool without mentioning the periodic review. It is the review, not the tool, that proves control.
Is multi-factor authentication in place?
What the reader is looking for
The exact scope: administrator access, remote access, business applications, service accounts.
The document that proves it
Authentication policy and a configuration screenshot or technical attestation for each scope.
The classic mistake
Answering a blanket “yes” when service accounts or a legacy tool are excluded. State the scope and the date by which it will be brought into compliance.
How do you manage security patches?
What the reader is looking for
Committed timeframes by criticality level, and evidence that they are met.
The document that proves it
Patch management procedure with timeframes by criticality, and the compliance indicator for the last quarter.
The classic mistake
Writing “as soon as possible”. A timeframe with no figure is read as the absence of a process.
Do you carry out penetration tests?
What the reader is looking for
The frequency, the scope, the independence of the provider and how the vulnerabilities found are handled.
The document that proves it
The provider’s attestation letter and a summary of the remediation plan, without disclosing the detailed technical report.
The classic mistake
Sending the full report: it contains your vulnerabilities. An attestation and a summary are enough, and are what is expected.
Is your data encrypted?
What the reader is looking for
Encryption in transit and at rest, algorithms, and above all key management.
The document that proves it
Technical architecture documentation specifying the mechanisms and key management.
The classic mistake
Answering “yes, bank-grade encryption”. Without a mechanism or key management, the phrase is empty.
How are your environments separated?
What the reader is looking for
Strict separation between production, acceptance testing and development, and no real data outside production.
The document that proves it
Architecture diagram and anonymisation procedure for test datasets.
The classic mistake
Leaving out the question of production data copied into acceptance testing: that is the point the auditor checks first.
Do you log access and sensitive actions?
What the reader is looking for
What is logged, for how long, and who uses those logs.
The document that proves it
Logging policy with retention period, and a description of the monitoring.
The classic mistake
Confusing logging with monitoring. Logs that nobody reads detect nothing.
Do you have security monitoring and incident detection?
What the reader is looking for
A real detection capability, with coverage hours and a response time.
The document that proves it
Description of the set-up, coverage hours, and committed response time.
The classic mistake
Announcing round-the-clock coverage when it relies on an informal on-call arrangement. The commitment must be sustainable.
Where would the data we entrust to you be hosted?
What the reader is looking for
The exact country, the entity operating the hosting, and the applicable law.
The document that proves it
Hosting documentation, contractual region, and the relevant clause of the data processing agreement.
The classic mistake
Answering “in Europe”. The reader wants the country and the entity, and will check whether processing follows storage.
Is any data transferred outside the European Economic Area?
What the reader is looking for
Whether transfers take place, including through a support subcontractor, and the safeguards governing those transfers.
The document that proves it
Register of transfers, standard contractual clauses, and impact assessment if one exists.
The classic mistake
Answering “no” while forgetting support access from another country. Remote access is a transfer.
What is your data retention period?
What the reader is looking for
Retention periods by data category, and an effective deletion mechanism.
The document that proves it
Retention policy by category and evidence that purges are carried out.
The classic mistake
Giving a single retention period for all data. A credible policy distinguishes between categories.
How do you handle a data subject rights request?
What the reader is looking for
A tool-supported process, a timeframe, and an identified point of contact.
The document that proves it
Request handling procedure, with committed timeframe and a register of requests handled.
The classic mistake
Pointing to a contact address without describing the internal process or the timeframe.
Have you appointed a data protection officer?
What the reader is looking for
The existence of the role, its independence and its published contact details.
The document that proves it
Formal appointment and contact details, as published and declared.
The classic mistake
Appointing someone without formalising the role or ensuring independence from the processing they oversee.
Is your data used to train artificial intelligence models?
What the reader is looking for
A clear, contractually binding answer on secondary use of the client’s data.
The document that proves it
Contractual clause prohibiting secondary use, and isolation architecture documentation.
The classic mistake
Answering with an intention. On this point, only an enforceable contractual clause is taken seriously.
How do you assess the security of your own subcontractors?
What the reader is looking for
An assessment process before contracting, and periodic reassessment.
The document that proves it
Third-party assessment procedure, list of critical subcontractors and the date of their last assessment.
The classic mistake
Providing the list without the assessment dates. A list alone proves no control. This is the reverse of the questionnaire: see Optivalue Reach.
Do you have a business continuity and disaster recovery plan?
What the reader is looking for
Quantified recovery time and data loss objectives, and evidence of a recent test.
The document that proves it
Continuity plan with quantified objectives, and the report of the last test exercise.
The classic mistake
Producing a plan without a test report. A plan that has never been tested commits no one.
How often do you test backup restores?
What the reader is looking for
A test frequency and evidence of the last successful test, not just the existence of backups.
The document that proves it
Backup policy with test frequency, and the report of the last restore test.
The classic mistake
Answering “backups are tested regularly”. Give the frequency and the date of the last test.
What is your security incident management process?
What the reader is looking for
The steps, the roles, and the committed client notification timeframe.
The document that proves it
Incident management procedure and the contractual notification clause.
The classic mistake
Describing the process without stating the notification timeframe. That is precisely what will be written into the contract.
Have you suffered a data breach in the last twenty-four months?
What the reader is looking for
An honest answer and a demonstration that the incident was handled and led to improvements.
The document that proves it
Post-incident report, notification made, and action plan with its closed actions.
The classic mistake
Denying on principle. A declared, well-handled incident is more reassuring than an unverifiable absence of incidents.
Can’t find your question? It most likely belongs to one of these twenty-five families, worded differently. That is exactly the work the platform does: recognising that a new question is a variant of one already handled. See the security questionnaires page.
These twenty-five questions, on your documents, in one hour.
You will see which ones your current documentation already proves, and which ones call for a document you do not have yet.