Security Questionnaire Mapper
Customer type

What a software company's security questionnaire reaches for

Software customers send the CAIQ or a SOC 2 driven list, and ask about subprocessors, data location and secure development in detail.

Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), CSA Cloud Controls Matrix v4.0.1 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.

Families, with the clauses from this customer's other frameworks

FamilyAnchor clauses in this customer's frameworks
Information security policySOC 2 CC5.3
Risk assessmentSOC 2 CC3.2
Independent audit and certificationSOC 2 CC4.1
Background checksCSA CCM HRS-01
Multi-factor authenticationSOC 2 CC6.1 · CSA CCM IAM-14
Password policySOC 2 CC6.1 · CSA CCM IAM-02
Access provisioning and reviewSOC 2 CC6.2
Encryption at restSOC 2 CC6.1 · CSA CCM CEK-03 · GDPR Art. 32
Encryption in transitCSA CCM CEK-03
Data retention and secure deletionCSA CCM DSP-16 · GDPR Art. 28
Data location and transfersCSA CCM DSP-19 · GDPR Art. 44 · GDPR Art. 46
Logging and monitoringSOC 2 CC7.2
Vulnerability and patch managementSOC 2 CC7.1 · CSA CCM TVM-03
Secure development and changeSOC 2 CC8.1
Incident response planSOC 2 CC7.4 · CSA CCM SEF-03
Notifying the customer of an incidentSOC 2 CC7.4 · CSA CCM SEF-07 · GDPR Art. 33
Business continuity planSOC 2 A1.3 · CSA CCM BCR-04 · CSA CCM BCR-06
Backup and disaster recoverySOC 2 A1.2 · CSA CCM BCR-08
Subcontractors and subprocessorsSOC 2 CC9.2 · CSA CCM DSP-13 · GDPR Art. 28
Assessing your own suppliersSOC 2 CC9.2
Data subject requestsCSA CCM DSP-11 · GDPR Art. 15 · GDPR Art. 28
Lawful basis, consent and privacy noticeGDPR Art. 6
Data processing agreementGDPR Art. 28