Security Questionnaire Mapper
Customer type

What a other customer's security questionnaire reaches for

An ordinary corporate customer's questionnaire mixes the SIG, the CAIQ and its own questions; the register shows every framework that usually appears.

Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), SIG (Shared Assessments), CSA Cloud Controls Matrix v4.0.1, NIST Cybersecurity Framework 2.0 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.

Families, with the clauses from this customer's other frameworks

FamilyAnchor clauses in this customer's frameworks
Information security policySOC 2 CC5.3 · SIG domain B
Risk assessmentSOC 2 CC3.2 · SIG domain A
Independent audit and certificationSOC 2 CC4.1
Background checksSIG domain E · CSA CCM HRS-01
Security awareness trainingSIG domain E
Confidentiality terms and leaversSIG domain E
Multi-factor authenticationSOC 2 CC6.1 · SIG domain H · CSA CCM IAM-14 · NIST CSF PR.AA-03
Password policySOC 2 CC6.1 · SIG domain H · CSA CCM IAM-02
Access provisioning and reviewSOC 2 CC6.2 · SIG domain H · NIST CSF PR.AA-05
Privileged accessSIG domain H · NIST CSF PR.AA-05
Encryption at restSOC 2 CC6.1 · SIG domain D · CSA CCM CEK-03 · NIST CSF PR.DS-01 · GDPR Art. 32
Encryption in transitCSA CCM CEK-03 · NIST CSF PR.DS-02
Data retention and secure deletionSIG domain D · CSA CCM DSP-16 · GDPR Art. 28
Data location and transfersCSA CCM DSP-19 · GDPR Art. 44 · GDPR Art. 46
Logging and monitoringSOC 2 CC7.2 · SIG domain G · NIST CSF DE.CM-01
Vulnerability and patch managementSOC 2 CC7.1 · SIG domain P · CSA CCM TVM-03 · NIST CSF ID.RA-01
Penetration testingSIG domain P
Secure development and changeSOC 2 CC8.1 · SIG domain I
Incident response planSOC 2 CC7.4 · SIG domain J · CSA CCM SEF-03 · NIST CSF RS.MA-01
Notifying the customer of an incidentSOC 2 CC7.4 · SIG domain J · CSA CCM SEF-07 · GDPR Art. 33
Business continuity planSOC 2 A1.3 · SIG domain K · CSA CCM BCR-04 · CSA CCM BCR-06 · NIST CSF RC.RP-01
Backup and disaster recoverySOC 2 A1.2 · SIG domain K · CSA CCM BCR-08 · NIST CSF PR.DS-11
Subcontractors and subprocessorsSOC 2 CC9.2 · SIG domain T · CSA CCM DSP-13 · GDPR Art. 28
Assessing your own suppliersSOC 2 CC9.2 · SIG domain T · NIST CSF GV.SC-07
Data subject requestsSIG domain O · CSA CCM DSP-11 · GDPR Art. 15 · GDPR Art. 28
Lawful basis, consent and privacy noticeSIG domain O · GDPR Art. 6
Data processing agreementSIG domain O · GDPR Art. 28