Security Questionnaire Mapper
Question group

Operations, logging and vulnerability

Logging, patching, penetration testing, endpoint protection, secure development, network segmentation and physical security: the running of the service, and the section with the most requests for reports.

The families

7 families
Family and a typical questionISO 27001Evidence expected
Logging and monitoringDo you centrally log and monitor security events?8.15, 8.16The logging standard naming what is logged and for how long, the monitoring and alerting set-up, and a sample of the review record.
Vulnerability and patch managementHow quickly are critical security patches applied to production systems?8.8The vulnerability management procedure with remediation windows by severity, the latest scan summary, and patch compliance figures for production.
Penetration testingDo you commission an independent penetration test of the service at least once a year?8.8The latest penetration test summary (tester, date, scope, findings by severity) and the remediation status of each finding.
Malware protection and endpointsIs anti-malware software installed on all laptops and servers?8.7The endpoint protection standard, coverage figures across laptops and servers, and the device management baseline.
Secure development and changeDo you follow a secure software development lifecycle, including code review before release?8.25The secure development standard, a sample of recent changes with review and approval records, and the security testing run in the pipeline.
Network security and segmentationAre production networks segmented and protected by firewalls?8.20The network diagram for the service, the segmentation between environments, and the last firewall rule review.
Physical securityDescribe the physical security controls at the data centres that host our data.7.1The physical security standard for offices and hosting sites, and for hosted services the provider's attestation covering its data centres.