Skip to main content

Top 20 Questions Asked on Questionnaires

Reduce inbound security questionnaire requests — preload your Knowledge Base with these top FAQs.

K
Written by Kristen Howard
Updated over 4 months ago

Every inbound security questionnaire feels different, but the truth is they usually ask for the same answers repeatedly. After analyzing hundreds of questionnaires submitted via Trust Centers, we’ve identified the Top 20 questions that show up most frequently. By preparing your answers in advance and loading them into your Knowledge Base, teams save hours on back-and-forth, streamline reviews, and accelerate the path to closed-won.

Top 20 Inbound Security Questions

1. Is the assessment for the entire company, or a particular functional area or risk control topic?

2. What is the name of the product, service, or system being provided by the vendor, processor, or third party?

3. Provide a brief description of the types of services being performed by the third party?

4. Enter the URL of any web site (s) applications that are in scope for the assessment?

5. What is the URL of the company relevant to the services being scoped for the assessment?

6. Does the company provide personnel or staff augmentation?

7. Does the company or services require direct end-user interaction?

8. Does the company utilize the services of Fourth-Nth parties for the delivery of the product, service or system?

9. Do the products, services, or system require network connectivity between parties?

10. Do the products, services, or systems require remote access between parties?

11. Do the products, services, or systems require system to system integration?

12. Does the products, services, or systems include any classification of personally identifiable information?

13. Are technology or software applications provided?

14. List the applications provided that are in scope.

15. What type of technology or software is being provided? Select all that apply from the list below.

  • Commercial Off-The-Shelf (COTS)

  • Custom Developed

  • Mobile

  • Open Source

  • Artificial Intelligence/Machine Learning

16. Does this assessment include Cloud Hosting Services?

17. What service hosting models are provided as part of this service? Select all that apply from the list below.

  • Data center: single tenancy

  • Co-location: dedicated server

  • Web Hosting

  • File Hosting

  • Continuous

  • Cloud Hosting e.g., AWS, Azure, Google, etc.

18. What type of Cloud Computing Services are being provided? Select all that apply from the list below.

  • Software as a Service (SaaS)

  • Infrastructure as a Service (IaaS)

  • Platform as a Service (PaaS)

19. What type of Cloud Deployment Models are provided? Select all that apply from the list below.

  • Private Cloud

  • Public Cloud

  • Community Cloud

  • Hybrid Cloud

20. Is your company a data processor or a data controller?

Get the Full List (Top 100)

Answer the Top 100 questions using this excel spreadsheet - add context to your answer for better training of AIQA - then upload to your Trust Center.

Did this answer your question?