Security questionnaire, evidence, or a spreadsheet of assertions
A security questionnaire is a structured set of control questions sent to a vendor to establish how it protects the data and systems it will handle. Standardised formats such as SIG, CAIQ and the Vendor Security Alliance questionnaire exist so that vendors can answer once rather than answering every customer differently. Also called Vendor security assessment questionnaire, VSAQ.
The standard formats
SIG, from Shared Assessments, is the broadest — a large question library issued in scoped subsets, common in financial services. CAIQ, from the Cloud Security Alliance, maps to the Cloud Controls Matrix and is the usual format for cloud providers, many of whom publish a completed copy rather than answering individually. The VSA questionnaire is shorter and popular with smaller technology suppliers.
Alongside them sit bespoke internal questionnaires, which is where most of the pain in the ecosystem originates: a vendor selling to forty customers answers forty differently-worded versions of the same forty questions. Accepting a standard format, or a recent completed one, costs you very little and buys goodwill and speed.
What a questionnaire is and is not
A questionnaire is a set of assertions by the party with the least interest in disclosing a weakness. That is not a reason to abandon it — much of what matters is invisible from outside and only the vendor can tell you — but it is a reason to treat the returned document as the beginning of the assessment rather than the end of it.
Three things convert assertions into evidence: documents that corroborate them (SOC 2, ISO 27001 with its statement of applicability, test summaries), outside-in observation that can contradict them, and validation of the answers against both. Answers that conflict with the vendor's own documents are the highest-value finding in the whole exercise, and they are also the finding least likely to be spotted by a human reading their nineteenth questionnaire of the month.
Common questions
What is the difference between SIG and CAIQ?
How long should a vendor security questionnaire be?
Can questionnaire answers be trusted?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.