Customer type
What a other customer's security questionnaire reaches for
An ordinary corporate customer's questionnaire mixes the SIG, the CAIQ and its own questions; the register shows every framework that usually appears.
Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), SIG (Shared Assessments), CSA Cloud Controls Matrix v4.0.1, NIST Cybersecurity Framework 2.0 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.
Families, with the clauses from this customer's other frameworks
| Family | Anchor clauses in this customer's frameworks |
|---|---|
| Information security policy | SOC 2 CC5.3 · SIG domain B |
| Risk assessment | SOC 2 CC3.2 · SIG domain A |
| Independent audit and certification | SOC 2 CC4.1 |
| Background checks | SIG domain E · CSA CCM HRS-01 |
| Security awareness training | SIG domain E |
| Confidentiality terms and leavers | SIG domain E |
| Multi-factor authentication | SOC 2 CC6.1 · SIG domain H · CSA CCM IAM-14 · NIST CSF PR.AA-03 |
| Password policy | SOC 2 CC6.1 · SIG domain H · CSA CCM IAM-02 |
| Access provisioning and review | SOC 2 CC6.2 · SIG domain H · NIST CSF PR.AA-05 |
| Privileged access | SIG domain H · NIST CSF PR.AA-05 |
| Encryption at rest | SOC 2 CC6.1 · SIG domain D · CSA CCM CEK-03 · NIST CSF PR.DS-01 · GDPR Art. 32 |
| Encryption in transit | CSA CCM CEK-03 · NIST CSF PR.DS-02 |
| Data retention and secure deletion | SIG domain D · CSA CCM DSP-16 · GDPR Art. 28 |
| Data location and transfers | CSA CCM DSP-19 · GDPR Art. 44 · GDPR Art. 46 |
| Logging and monitoring | SOC 2 CC7.2 · SIG domain G · NIST CSF DE.CM-01 |
| Vulnerability and patch management | SOC 2 CC7.1 · SIG domain P · CSA CCM TVM-03 · NIST CSF ID.RA-01 |
| Penetration testing | SIG domain P |
| Secure development and change | SOC 2 CC8.1 · SIG domain I |
| Incident response plan | SOC 2 CC7.4 · SIG domain J · CSA CCM SEF-03 · NIST CSF RS.MA-01 |
| Notifying the customer of an incident | SOC 2 CC7.4 · SIG domain J · CSA CCM SEF-07 · GDPR Art. 33 |
| Business continuity plan | SOC 2 A1.3 · SIG domain K · CSA CCM BCR-04 · CSA CCM BCR-06 · NIST CSF RC.RP-01 |
| Backup and disaster recovery | SOC 2 A1.2 · SIG domain K · CSA CCM BCR-08 · NIST CSF PR.DS-11 |
| Subcontractors and subprocessors | SOC 2 CC9.2 · SIG domain T · CSA CCM DSP-13 · GDPR Art. 28 |
| Assessing your own suppliers | SOC 2 CC9.2 · SIG domain T · NIST CSF GV.SC-07 |
| Data subject requests | SIG domain O · CSA CCM DSP-11 · GDPR Art. 15 · GDPR Art. 28 |
| Lawful basis, consent and privacy notice | SIG domain O · GDPR Art. 6 |
| Data processing agreement | SIG domain O · GDPR Art. 28 |