Oredra Security Library
Security Questionnaire Answer Library
What did your customer ask you? Find the question, understand what it really means, see what information may support your answer, and avoid claiming more than your company can prove.
No signup required. Your search text is not sent to Oredra marketing analytics.
Browse by topic
Start with the section in front of you.
The same themes repeat across customer questionnaires. Learn the underlying question once, then keep the approved answer current.
Identity & access
MFA, user access, least privilege, and periodic access review questions.
Browse topicData protection
Encryption, retention, deletion, and how customer information is protected.
Browse topicBackup & resilience
Backups, restoration testing, business continuity, and disaster recovery.
Browse topicIncidents & vulnerability management
Incident response, notifications, scanning, penetration testing, and patching.
Browse topicPeople & endpoints
Security training, phishing simulations, endpoint protection, and device management.
Browse topicGovernance & assurance
Policies, vendor reviews, SOC 2, ISO/IEC 27001, and what those claims actually mean.
Browse topicIdentity & access
Do you require multi-factor authentication (MFA)?
The reviewer is usually asking whether access requires more than a password and, just as importantly, where that requirement applies. Do not answer “yes” simply because your software supports MFA. Confirm that your company actually requires it for the users and systems in scope.
Understand this questionIdentity & access
How do you provision user access?
Explain how a person receives access, who approves it, and how the access level is chosen. A written procedure is useful, but do not claim a formal approval workflow if access is actually granted informally.
Understand this questionIdentity & access
How do you remove access when an employee or contractor leaves?
Describe who triggers access removal, who performs it, which account types are covered, and any timing you can actually support. Avoid promising immediate or same-day removal unless that is a verified company practice.
Understand this questionIdentity & access
Do you follow the principle of least privilege?
Least privilege generally means limiting access to what a person needs for their responsibilities. Before answering “yes,” confirm how permissions are actually assigned and whether broad administrator access or shared accounts create exceptions.
Understand this questionIdentity & access
Do you conduct periodic user access reviews?
A periodic access review is a deliberate check that existing access is still appropriate. Routine account administration is not automatically a periodic review. Answer based on whether your company actually performs a recurring review and can describe its scope and frequency.
Understand this questionData protection
Is customer data encrypted in transit?
The question is asking whether information is protected while moving between systems, users, or services. Verify the actual protocols and the scope of the data flows before answering. Do not assume that using a modern cloud platform means every transmission path is covered.
Understand this questionData protection
Is customer data encrypted at rest?
Encryption at rest concerns stored data. Before answering, identify where customer information is stored and confirm which storage systems, databases, devices, and backups are actually encrypted.
Understand this questionData protection
How long do you retain customer data, and how is it deleted?
Describe the actual retention and deletion practice for the data in scope. Be especially careful with fixed timelines, backups, legal or contractual retention, and copies held by subprocessors because those details can make a simple answer inaccurate.
Understand this questionBackup & resilience
Do you back up critical data?
First determine what your company considers critical data, where it is stored, and what recovery copies actually exist. High availability, file version history, replication, and backups can overlap, but they are not automatically the same thing.
Understand this questionBackup & resilience
Do you test backup restoration?
A successful backup job does not prove that data can be restored. Answer “yes” to restoration testing only when the company has actually performed a recovery or restore test and can describe what was tested.
Understand this questionBackup & resilience
Do you maintain a business continuity plan?
A business continuity plan describes how essential business operations can continue through a disruption. It is not automatically the same as a disaster recovery plan, an emergency contact list, or a backup process.
Understand this questionBackup & resilience
Do you maintain a disaster recovery plan?
A disaster recovery plan focuses on restoring technology, systems, and data after a serious disruption. A written plan is not proof that recovery has been tested or that recovery objectives have been achieved.
Understand this questionIncidents & vulnerability management
Do you have an incident response plan?
A written incident response plan documents how the company prepares for and handles cybersecurity incidents. Do not treat an informal understanding, a cyber-insurance phone number, or a vendor service as proof that your company maintains a complete plan.
Understand this questionIncidents & vulnerability management
How do you notify customers of a security incident?
Describe the company process for deciding when and how affected customers are notified. Be careful with exact deadlines: notification timing can depend on contracts, laws, the facts of the incident, and the commitments your company has actually made.
Understand this questionIncidents & vulnerability management
Do you perform vulnerability scanning?
Vulnerability scanning generally means using tools or services to identify known weaknesses in systems, software, or configurations. Confirm the actual scope, frequency, and ownership before answering, and do not substitute penetration testing—or vice versa—as if they were the same activity.
Understand this questionIncidents & vulnerability management
Do you perform penetration testing?
Answer “yes” only when your company has actually had the relevant systems or application tested through a penetration-testing engagement. Vulnerability scans, automated security checks, and a written policy are not automatically penetration tests.
Understand this questionIncidents & vulnerability management
How do you manage security patches and software updates?
Describe how security updates are identified, evaluated, and applied to the systems your company manages. Avoid inventing universal patch deadlines: different systems, vendors, and severity levels may follow different processes.
Understand this questionPeople & endpoints
Do employees receive security awareness training?
Answer based on training your workforce actually receives. A security policy, onboarding conversation, or occasional reminder may be useful, but it should not be described as a recurring formal training program unless that is what your company operates.
Understand this questionPeople & endpoints
Do you conduct phishing simulations?
A phishing simulation is a controlled exercise that sends simulated phishing messages to evaluate or reinforce employee behavior. General awareness training and real phishing attempts do not automatically count as simulations.
Understand this questionPeople & endpoints
Do you use endpoint protection or anti-malware?
The reviewer is asking what protects laptops, desktops, servers, or other endpoints from malicious activity. A product license is not proof that every relevant endpoint is enrolled, active, monitored, or configured consistently.
Understand this questionPeople & endpoints
Do you centrally manage company devices or use MDM?
Mobile device management (MDM) or another endpoint-management platform can enforce settings on enrolled devices, but having the tool is not the same as managing every device. Verify which devices and users are actually in scope.
Understand this questionGovernance & assurance
Do you maintain a written information security policy?
Answer “yes” only if a written policy actually exists in a current, approved form. A policy describes expectations and requirements; it does not by itself prove that every stated practice or control is operating.
Understand this questionGovernance & assurance
Do you assess the security of vendors and third parties?
Describe how your company evaluates vendors that can affect customer data or important operations. A small business may perform practical due diligence without running a formal enterprise vendor-risk program; the answer should reflect the process that actually exists.
Understand this questionGovernance & assurance
Are you SOC 2 compliant, certified, or do you have a SOC 2 report?
SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.
Understand this questionGovernance & assurance
Are you ISO 27001 certified?
ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.
Understand this questionNot sure what your company can answer?
Check your questionnaire readiness in about three minutes.
See which common areas are clear, scattered, uncertain, or simply not something your company does today. It is not a compliance score.
Take the free readiness check