Security Questionnaire
Pronunciation: sih-KYOOR-ih-tee kwehs-chuh-NEHR
Definition
Security Questionnaire is an assurance or evaluation activity that collects structured information about an organization’s controls, practices, systems, incidents, and risk management for assessment purposes. Security Questionnaire provides bounded assurance rather than a permanent guarantee; conclusions apply only to the reviewed scope, criteria, configuration, evidence, and time period. Security Questionnaire must define its objective, scope, criteria, system or control population, evidence period, test method, assessor independence, exceptions, and required remediation or reporting.
Overview
Security questionnaires support vendor due diligence, customer assurance, audits, procurement, and internal reviews. Questions may cover governance, access, encryption, development, infrastructure, privacy, resilience, incidents, certifications, and subcontractors.
Self-reported answers can be outdated, misunderstood, overly broad, or unsupported. Long generic questionnaires consume effort without distinguishing material risks, while certifications and yes-or-no responses may hide scope limitations and exceptions.
Assessors should tailor questions to the service and data flows, request proportionate evidence, clarify scope, validate critical claims, and track remediation. Reusable responses should be versioned, owned, and updated after material changes, incidents, or expiration of supporting assurance. Question libraries should remove items that never change decisions or reveal meaningful exposure.
Security Questionnaire is an assurance or evaluation activity that collects structured information about an organization’s controls, practices, systems, incidents, and risk management for assessment purposes. Security Questionnaire must define its objective, scope, criteria, system or control population, evidence period, test method, assessor independence, exceptions, and required remediation or reporting. A security questionnaire is an evidence-gathering tool, not independent assurance, and should be scoped, validated, maintained, and risk-focused.
A production treatment of Security Questionnaire should test an assurance or evaluation activity that collects structured information about an organization’s controls, practices, systems, incidents, and risk management for assessment purposes within the relevant asset, decision, or service state. The Security Questionnaire context record for assurance, practices, and systems should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Security Questionnaire should determine whether safeguards addressing assurance, practices, and systems changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
A security questionnaire is an evidence-gathering tool, not independent assurance, and should be scoped, validated, maintained, and risk-focused.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)