Vendor Security Questionnaire
Answer Yes/No and provide supporting evidence.
- Is data encrypted at rest? Evidence: audit summary or config doc.
- Is data encrypted in transit? Evidence: TLS configuration.
- Do you test your business continuity plan annually? Evidence: test report.
- Is MFA required for privileged users? Evidence: policy or screenshot.
- Do you conduct code reviews and vulnerability scans? Evidence: CI/CD logs.
- Are critical vulnerabilities remediated within SLA? Evidence: metrics.
- Do you conduct annual penetration testing? Evidence: report summary.
- Are access privileges reviewed quarterly? Evidence: review log.
- Are logs retained for at least 90 days? Evidence: log retention policy.
- Are you SOC 2 or ISO 27001 certified? Evidence: certificate or audit report.