DEV Community

Cover image for How to answer a security questionnaire without guessing
Enoch Chan
Enoch Chan

Posted on

How to answer a security questionnaire without guessing

How to answer a security questionnaire without guessing

A customer security questionnaire is easy to treat as a spreadsheet exercise. That is where the risk starts. A row is not just a box to fill: it is a claim that someone may rely on when deciding whether to buy, renew or approve a supplier.

Use a four-part record for every meaningful question:

  1. Scope — What service, environment, data set or process does the question actually cover?
  2. Claim — What precise statement are you making? Avoid turning a narrow fact into a broad promise.
  3. Evidence — Which current policy, configuration record, test result, report or operating record supports the claim?
  4. Owner — Who is authorised to approve the wording and confirm that the evidence still applies?

This is consistent with the evidence-led shape of supplier due diligence. NIST describes due diligence as researching pertinent supplier information so an organisation can make an informed decision. UK guidance also points toward proportionate, staged evidence rather than asking every supplier for every possible document at the start.

A reusable answer library can reduce re-entry, but reuse is not the same as copy-and-paste. Preserve the source, scope, review date and owner with the answer. When a buyer changes the question or the service changes, send the row back through review.

A useful final check is simple: could another reviewer open the answer, understand exactly what it claims, find the supporting evidence and see who approved it? If not, the row is not ready to leave the team.

This workflow does not guarantee procurement approval. It makes the answer easier to review, easier to update and harder to overstate.

Top comments (0)