Customer type
What a government agency's security questionnaire reaches for
Government questionnaires are built from NIST SP 800-53 families and the Cybersecurity Framework, and ask about personnel screening and supply chain more than most.
Frameworks ticked by default for this customer: ISO/IEC 27001:2022, NIST SP 800-53 Rev 5, NIST Cybersecurity Framework 2.0 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.
Families, with the clauses from this customer's other frameworks
| Family | Anchor clauses in this customer's frameworks |
|---|---|
| Background checks | SP 800-53 PS-3 |
| Multi-factor authentication | SP 800-53 IA-2 · NIST CSF PR.AA-03 |
| Access provisioning and review | SP 800-53 AC-2 · NIST CSF PR.AA-05 |
| Privileged access | NIST CSF PR.AA-05 |
| Encryption at rest | SP 800-53 SC-28 · NIST CSF PR.DS-01 · GDPR Art. 32 |
| Encryption in transit | NIST CSF PR.DS-02 |
| Data retention and secure deletion | GDPR Art. 28 |
| Data location and transfers | GDPR Art. 44 · GDPR Art. 46 |
| Logging and monitoring | SP 800-53 AU-6 · NIST CSF DE.CM-01 |
| Vulnerability and patch management | SP 800-53 RA-5 · NIST CSF ID.RA-01 |
| Incident response plan | SP 800-53 IR-8 · NIST CSF RS.MA-01 |
| Notifying the customer of an incident | GDPR Art. 33 |
| Business continuity plan | SP 800-53 CP-2 · NIST CSF RC.RP-01 |
| Backup and disaster recovery | SP 800-53 CP-9 · NIST CSF PR.DS-11 |
| Subcontractors and subprocessors | GDPR Art. 28 |
| Assessing your own suppliers | SP 800-53 SR-6 · NIST CSF GV.SC-07 |
| Data subject requests | GDPR Art. 15 · GDPR Art. 28 |
| Lawful basis, consent and privacy notice | GDPR Art. 6 |
| Data processing agreement | GDPR Art. 28 |