Oredra Security Library

Security Questionnaire Answer Library

What did your customer ask you? Find the question, understand what it really means, see what information may support your answer, and avoid claiming more than your company can prove.

No signup required. Your search text is not sent to Oredra marketing analytics.

Browse by topic

Start with the section in front of you.

Identity & access

Do you require multi-factor authentication (MFA)?

The reviewer is usually asking whether access requires more than a password and, just as importantly, where that requirement applies. Do not answer “yes” simply because your software supports MFA. Confirm that your company actually requires it for the users and systems in scope.

Understand this question

Identity & access

How do you provision user access?

Explain how a person receives access, who approves it, and how the access level is chosen. A written procedure is useful, but do not claim a formal approval workflow if access is actually granted informally.

Understand this question

Identity & access

How do you remove access when an employee or contractor leaves?

Describe who triggers access removal, who performs it, which account types are covered, and any timing you can actually support. Avoid promising immediate or same-day removal unless that is a verified company practice.

Understand this question

Identity & access

Do you follow the principle of least privilege?

Least privilege generally means limiting access to what a person needs for their responsibilities. Before answering “yes,” confirm how permissions are actually assigned and whether broad administrator access or shared accounts create exceptions.

Understand this question

Identity & access

Do you conduct periodic user access reviews?

A periodic access review is a deliberate check that existing access is still appropriate. Routine account administration is not automatically a periodic review. Answer based on whether your company actually performs a recurring review and can describe its scope and frequency.

Understand this question

Data protection

Is customer data encrypted in transit?

The question is asking whether information is protected while moving between systems, users, or services. Verify the actual protocols and the scope of the data flows before answering. Do not assume that using a modern cloud platform means every transmission path is covered.

Understand this question

Data protection

Is customer data encrypted at rest?

Encryption at rest concerns stored data. Before answering, identify where customer information is stored and confirm which storage systems, databases, devices, and backups are actually encrypted.

Understand this question

Data protection

How long do you retain customer data, and how is it deleted?

Describe the actual retention and deletion practice for the data in scope. Be especially careful with fixed timelines, backups, legal or contractual retention, and copies held by subprocessors because those details can make a simple answer inaccurate.

Understand this question

Backup & resilience

Do you back up critical data?

First determine what your company considers critical data, where it is stored, and what recovery copies actually exist. High availability, file version history, replication, and backups can overlap, but they are not automatically the same thing.

Understand this question

Backup & resilience

Do you test backup restoration?

A successful backup job does not prove that data can be restored. Answer “yes” to restoration testing only when the company has actually performed a recovery or restore test and can describe what was tested.

Understand this question

Backup & resilience

Do you maintain a business continuity plan?

A business continuity plan describes how essential business operations can continue through a disruption. It is not automatically the same as a disaster recovery plan, an emergency contact list, or a backup process.

Understand this question

Backup & resilience

Do you maintain a disaster recovery plan?

A disaster recovery plan focuses on restoring technology, systems, and data after a serious disruption. A written plan is not proof that recovery has been tested or that recovery objectives have been achieved.

Understand this question

Incidents & vulnerability management

Do you have an incident response plan?

A written incident response plan documents how the company prepares for and handles cybersecurity incidents. Do not treat an informal understanding, a cyber-insurance phone number, or a vendor service as proof that your company maintains a complete plan.

Understand this question

Incidents & vulnerability management

How do you notify customers of a security incident?

Describe the company process for deciding when and how affected customers are notified. Be careful with exact deadlines: notification timing can depend on contracts, laws, the facts of the incident, and the commitments your company has actually made.

Understand this question

Incidents & vulnerability management

Do you perform vulnerability scanning?

Vulnerability scanning generally means using tools or services to identify known weaknesses in systems, software, or configurations. Confirm the actual scope, frequency, and ownership before answering, and do not substitute penetration testing—or vice versa—as if they were the same activity.

Understand this question

Incidents & vulnerability management

Do you perform penetration testing?

Answer “yes” only when your company has actually had the relevant systems or application tested through a penetration-testing engagement. Vulnerability scans, automated security checks, and a written policy are not automatically penetration tests.

Understand this question

Incidents & vulnerability management

How do you manage security patches and software updates?

Describe how security updates are identified, evaluated, and applied to the systems your company manages. Avoid inventing universal patch deadlines: different systems, vendors, and severity levels may follow different processes.

Understand this question

People & endpoints

Do employees receive security awareness training?

Answer based on training your workforce actually receives. A security policy, onboarding conversation, or occasional reminder may be useful, but it should not be described as a recurring formal training program unless that is what your company operates.

Understand this question

People & endpoints

Do you conduct phishing simulations?

A phishing simulation is a controlled exercise that sends simulated phishing messages to evaluate or reinforce employee behavior. General awareness training and real phishing attempts do not automatically count as simulations.

Understand this question

People & endpoints

Do you use endpoint protection or anti-malware?

The reviewer is asking what protects laptops, desktops, servers, or other endpoints from malicious activity. A product license is not proof that every relevant endpoint is enrolled, active, monitored, or configured consistently.

Understand this question

People & endpoints

Do you centrally manage company devices or use MDM?

Mobile device management (MDM) or another endpoint-management platform can enforce settings on enrolled devices, but having the tool is not the same as managing every device. Verify which devices and users are actually in scope.

Understand this question

Governance & assurance

Do you maintain a written information security policy?

Answer “yes” only if a written policy actually exists in a current, approved form. A policy describes expectations and requirements; it does not by itself prove that every stated practice or control is operating.

Understand this question

Governance & assurance

Do you assess the security of vendors and third parties?

Describe how your company evaluates vendors that can affect customer data or important operations. A small business may perform practical due diligence without running a formal enterprise vendor-risk program; the answer should reflect the process that actually exists.

Understand this question

Governance & assurance

Are you SOC 2 compliant, certified, or do you have a SOC 2 report?

SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.

Understand this question

Governance & assurance

Are you ISO 27001 certified?

ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.

Understand this question

Not sure what your company can answer?

Check your questionnaire readiness in about three minutes.

See which common areas are clear, scattered, uncertain, or simply not something your company does today. It is not a compliance score.

Take the free readiness check