Security Questionnaire Mapper
Customer type

What a bank's security questionnaire reaches for

Banks send the SIG or their own spreadsheet built on it, map it to the NIST Cybersecurity Framework, ask for a SOC 2 report by name, and ask card questions wherever a payment touches the service.

Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), SIG (Shared Assessments), NIST Cybersecurity Framework 2.0, PCI DSS v4.0.1 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.

Families, with the clauses from this customer's other frameworks

FamilyAnchor clauses in this customer's frameworks
Information security policySOC 2 CC5.3 · SIG domain B
Risk assessmentSOC 2 CC3.2 · SIG domain A
Independent audit and certificationSOC 2 CC4.1
Background checksSIG domain E
Security awareness trainingSIG domain E
Confidentiality terms and leaversSIG domain E
Multi-factor authenticationSOC 2 CC6.1 · SIG domain H · NIST CSF PR.AA-03 · PCI DSS 8.4.2
Password policySOC 2 CC6.1 · SIG domain H
Access provisioning and reviewSOC 2 CC6.2 · SIG domain H · NIST CSF PR.AA-05 · PCI DSS 7.2.4
Privileged accessSIG domain H · NIST CSF PR.AA-05
Encryption at restSOC 2 CC6.1 · SIG domain D · NIST CSF PR.DS-01 · PCI DSS 3.5.1 · GDPR Art. 32
Encryption in transitNIST CSF PR.DS-02 · PCI DSS 4.2.1
Data retention and secure deletionSIG domain D · PCI DSS 3.2.1 · GDPR Art. 28
Data location and transfersGDPR Art. 44 · GDPR Art. 46
Cardholder data and PCI DSSno ISO 27001 clause: beyond an ISO 27001 certificatePCI DSS 3.2.1 · PCI DSS 12.5.2
Logging and monitoringSOC 2 CC7.2 · SIG domain G · NIST CSF DE.CM-01 · PCI DSS 10.4.1
Vulnerability and patch managementSOC 2 CC7.1 · SIG domain P · NIST CSF ID.RA-01 · PCI DSS 6.3.3 · PCI DSS 11.3.1
Penetration testingSIG domain P · PCI DSS 11.4.3
Secure development and changeSOC 2 CC8.1 · SIG domain I
Incident response planSOC 2 CC7.4 · SIG domain J · NIST CSF RS.MA-01 · PCI DSS 12.10.1
Notifying the customer of an incidentSOC 2 CC7.4 · SIG domain J · GDPR Art. 33
Business continuity planSOC 2 A1.3 · SIG domain K · NIST CSF RC.RP-01
Backup and disaster recoverySOC 2 A1.2 · SIG domain K · NIST CSF PR.DS-11
Subcontractors and subprocessorsSOC 2 CC9.2 · SIG domain T · PCI DSS 12.8.1 · GDPR Art. 28
Assessing your own suppliersSOC 2 CC9.2 · SIG domain T · NIST CSF GV.SC-07
Data subject requestsSIG domain O · GDPR Art. 15 · GDPR Art. 28
Lawful basis, consent and privacy noticeSIG domain O · GDPR Art. 6
Data processing agreementSIG domain O · GDPR Art. 28