Vendor Security Assessment Questionnaire

Purpose

Use this questionnaire before engaging an important vendor or when periodically reviewing an existing vendor.

The questionnaire should be proportionate to risk. A vendor hosting critical customer information may require a detailed assessment, while a low-risk supplier with no access to company systems may not.

Vendor Information

Vendor name: ____________________

Service provided: ____________________

Internal owner: ____________________

Assessment date: ____________________

Reviewer: ____________________

Contract renewal date: ____________________

Service Criticality

Would loss of this vendor seriously disrupt the business?

  • Yes / No

If yes, describe:


Data Access

Does the vendor:

  • Store company data?
  • Store customer data?
  • Store employee data?
  • Process financial information?
  • Process credentials or authentication information?
  • Access confidential business information?
  • Transfer company information to subcontractors?

Describe the information involved:


Where is the information stored?


System Access

Does the vendor have:

  • Remote access?
  • VPN access?
  • Administrator access?
  • Cloud administrator access?
  • SaaS administrator access?
  • API access?
  • Access to production systems?
  • Access to backups?
  • Access to security tools?

Describe:


Identity and Access Security

Does the vendor:

  • Use named user accounts?
  • Require MFA?
  • Restrict privileged access?
  • Review user access periodically?
  • Remove former employee access promptly?
  • Control service accounts and API credentials?
  • Log important administrative activity?

Comments:


Device and System Security

Does the vendor:

  • Maintain supported operating systems?
  • Apply security patches?
  • Use endpoint protection?
  • Use secure configuration standards?
  • Perform vulnerability scanning?
  • Protect administrative devices appropriately?

Comments:


Data Protection

Does the vendor:

  • Encrypt sensitive data in transit?
  • Encrypt sensitive data at rest where appropriate?
  • Restrict employee access to customer data?
  • Control external sharing?
  • Have data retention procedures?
  • Have secure data deletion procedures?

Comments:


Backup and Recovery

Does the vendor:

  • Back up important customer data?
  • Protect backups from deletion or ransomware?
  • Test restoration?
  • Maintain business continuity arrangements?
  • Define expected recovery times?

Recovery information:


Logging and Monitoring

Does the vendor:

  • Maintain security logs?
  • Monitor suspicious activity?
  • Monitor privileged activity?
  • Retain logs for an appropriate period?
  • Have a process for security alert escalation?

Comments:


Incident Response

Does the vendor have:

  • An incident response plan?
  • A security incident contact?
  • A process for notifying customers of relevant incidents?
  • Defined escalation procedures?
  • A process for preserving evidence?

Vendor security contact:


Incident notification method:


Subcontractors

Does the vendor use subcontractors or sub-processors?

  • Yes / No

If yes:

What services do they provide?


Can they access company data?

  • Yes / No / Unknown

How are they assessed?


Security Assurance

Does the vendor have any relevant independent assurance?

Examples:

  • ISO 27001
  • SOC 2
  • PCI DSS
  • Cyber Essentials
  • Penetration testing
  • Independent security assessment
  • Other: ____________________

Evidence reviewed:


Certifications should support the assessment, not replace it.

Previous Incidents

Has the vendor disclosed significant cybersecurity incidents relevant to the service?

  • Yes / No / Unknown

If yes:


Contractual Controls

Does the contract address:

  • Confidentiality?
  • Data protection?
  • Security requirements?
  • Incident notification?
  • Subcontractors?
  • Data return or deletion?
  • Termination?
  • Business continuity?
  • Access removal?

Assessment Result

Risk level:

  • Low / Medium / High / Critical

Decision:

  • Approve
  • Approve with conditions
  • Further review required
  • Reject

Required Improvements

Action: ____________________

Owner: ____________________

Due date: ____________________

Evidence required: ____________________

Next Review

Next review date: ____________________

Approved by: ____________________

Practical Rule

Ask deeper questions when the vendor has deeper access to the company.