Security Questionnaire Mapper
Question group

Access and identity

Who can reach the customer's data and how they prove who they are: multi-factor authentication, passwords, access reviews and privileged accounts. The section where the same question is most often asked twice in different words.

The families

4 families
Family and a typical questionISO 27001Evidence expected
Multi-factor authenticationIs multi-factor authentication enforced for all remote access?8.5Configuration evidence showing which systems require a second factor, which users it covers, and the exceptions with their reason.
Password policyDo you have a password policy that sets minimum length and complexity?5.17The password standard (length, complexity, reuse, lockout) and the system settings that enforce it.
Access provisioning and reviewHow often are user access rights reviewed, and by whom?5.18The access request and approval records, the last completed access review with its sign-off, and leaver records showing when access was removed.
Privileged accessHow is privileged or administrator access restricted and monitored?8.2The list of privileged accounts with owners, how privileged sessions are granted and logged, and the last review of that list.