Vendor Security Assessment Questionnaire
Purpose
Use this questionnaire before engaging an important vendor or when periodically reviewing an existing vendor.
The questionnaire should be proportionate to risk. A vendor hosting critical customer information may require a detailed assessment, while a low-risk supplier with no access to company systems may not.
Vendor Information
Vendor name: ____________________
Service provided: ____________________
Internal owner: ____________________
Assessment date: ____________________
Reviewer: ____________________
Contract renewal date: ____________________
Service Criticality
Would loss of this vendor seriously disrupt the business?
- Yes / No
If yes, describe:
Data Access
Does the vendor:
- Store company data?
- Store customer data?
- Store employee data?
- Process financial information?
- Process credentials or authentication information?
- Access confidential business information?
- Transfer company information to subcontractors?
Describe the information involved:
Where is the information stored?
System Access
Does the vendor have:
- Remote access?
- VPN access?
- Administrator access?
- Cloud administrator access?
- SaaS administrator access?
- API access?
- Access to production systems?
- Access to backups?
- Access to security tools?
Describe:
Identity and Access Security
Does the vendor:
- Use named user accounts?
- Require MFA?
- Restrict privileged access?
- Review user access periodically?
- Remove former employee access promptly?
- Control service accounts and API credentials?
- Log important administrative activity?
Comments:
Device and System Security
Does the vendor:
- Maintain supported operating systems?
- Apply security patches?
- Use endpoint protection?
- Use secure configuration standards?
- Perform vulnerability scanning?
- Protect administrative devices appropriately?
Comments:
Data Protection
Does the vendor:
- Encrypt sensitive data in transit?
- Encrypt sensitive data at rest where appropriate?
- Restrict employee access to customer data?
- Control external sharing?
- Have data retention procedures?
- Have secure data deletion procedures?
Comments:
Backup and Recovery
Does the vendor:
- Back up important customer data?
- Protect backups from deletion or ransomware?
- Test restoration?
- Maintain business continuity arrangements?
- Define expected recovery times?
Recovery information:
Logging and Monitoring
Does the vendor:
- Maintain security logs?
- Monitor suspicious activity?
- Monitor privileged activity?
- Retain logs for an appropriate period?
- Have a process for security alert escalation?
Comments:
Incident Response
Does the vendor have:
- An incident response plan?
- A security incident contact?
- A process for notifying customers of relevant incidents?
- Defined escalation procedures?
- A process for preserving evidence?
Vendor security contact:
Incident notification method:
Subcontractors
Does the vendor use subcontractors or sub-processors?
- Yes / No
If yes:
What services do they provide?
Can they access company data?
- Yes / No / Unknown
How are they assessed?
Security Assurance
Does the vendor have any relevant independent assurance?
Examples:
- ISO 27001
- SOC 2
- PCI DSS
- Cyber Essentials
- Penetration testing
- Independent security assessment
- Other: ____________________
Evidence reviewed:
Certifications should support the assessment, not replace it.
Previous Incidents
Has the vendor disclosed significant cybersecurity incidents relevant to the service?
- Yes / No / Unknown
If yes:
Contractual Controls
Does the contract address:
- Confidentiality?
- Data protection?
- Security requirements?
- Incident notification?
- Subcontractors?
- Data return or deletion?
- Termination?
- Business continuity?
- Access removal?
Assessment Result
Risk level:
- Low / Medium / High / Critical
Decision:
- Approve
- Approve with conditions
- Further review required
- Reject
Required Improvements
Action: ____________________
Owner: ____________________
Due date: ____________________
Evidence required: ____________________
Next Review
Next review date: ____________________
Approved by: ____________________
Practical Rule
Ask deeper questions when the vendor has deeper access to the company.