Security Questionnaire Mapper
Customer type

What a government agency's security questionnaire reaches for

Government questionnaires are built from NIST SP 800-53 families and the Cybersecurity Framework, and ask about personnel screening and supply chain more than most.

Frameworks ticked by default for this customer: ISO/IEC 27001:2022, NIST SP 800-53 Rev 5, NIST Cybersecurity Framework 2.0 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.

Families, with the clauses from this customer's other frameworks

FamilyAnchor clauses in this customer's frameworks
Background checksSP 800-53 PS-3
Multi-factor authenticationSP 800-53 IA-2 · NIST CSF PR.AA-03
Access provisioning and reviewSP 800-53 AC-2 · NIST CSF PR.AA-05
Privileged accessNIST CSF PR.AA-05
Encryption at restSP 800-53 SC-28 · NIST CSF PR.DS-01 · GDPR Art. 32
Encryption in transitNIST CSF PR.DS-02
Data retention and secure deletionGDPR Art. 28
Data location and transfersGDPR Art. 44 · GDPR Art. 46
Logging and monitoringSP 800-53 AU-6 · NIST CSF DE.CM-01
Vulnerability and patch managementSP 800-53 RA-5 · NIST CSF ID.RA-01
Incident response planSP 800-53 IR-8 · NIST CSF RS.MA-01
Notifying the customer of an incidentGDPR Art. 33
Business continuity planSP 800-53 CP-2 · NIST CSF RC.RP-01
Backup and disaster recoverySP 800-53 CP-9 · NIST CSF PR.DS-11
Subcontractors and subprocessorsGDPR Art. 28
Assessing your own suppliersSP 800-53 SR-6 · NIST CSF GV.SC-07
Data subject requestsGDPR Art. 15 · GDPR Art. 28
Lawful basis, consent and privacy noticeGDPR Art. 6
Data processing agreementGDPR Art. 28