Security Questionnaire Mapper
Question group

Governance and policy

The opening section of almost every questionnaire: is there a policy, who owns security, is risk assessed, and has anyone independent looked. These questions draw on the documents a certificate already rests on.

The families

4 families
Family and a typical questionISO 27001Evidence expected
Information security policyDo you maintain an information security policy approved by management?5.1The approved top-level security policy with its approval record and last review date, and the list of topic policies that sit under it.
Security roles and a named security leadWho is responsible for information security in your organisation?5.2An organisation chart or role description naming who owns information security, the reporting line, and the roles below it.
Risk assessmentDo you perform a formal information security risk assessment at least annually?noneThe risk assessment method, the current risk register with owners and treatment decisions, and the date of the last full assessment.
Independent audit and certificationIs your organisation independently audited against a recognised security standard?5.35The current certificate or attestation report with its scope statement and period, and the latest internal audit summary.