Question Bank
528 questions across 201 controls
Does your organisation have a documented AI governance policy or charter?
The policy should be formally approved by an executive sponsor, enumerate prohibited AI use cases, assign accountability for AI risk decisions, and specify a review cadence. Absence of a policy is a foundational gap that downstream controls cannot compensate for.
Which of the following topics does your AI governance policy cover?
A mature policy covers all six areas. Policies limited to high-level principles without accountability assignments or prohibited use lists provide weak governance foundations for enterprise buyers.
Has your organisation documented its AI risk tolerance, the types and levels of AI risk it is willing to accept?
Risk tolerance is the decision rule that determines when AI risks require treatment. Without it, risk management decisions are inconsistent and cannot be audited. Look for explicit statements covering safety, fairness, privacy, reliability, and regulatory compliance.
Are named roles with defined accountability for AI risk management documented and assigned in your organisation?
Diffuse accountability is the most common AI governance failure mode. Look for a RACI or equivalent document that names an executive AI governance sponsor and assigns a system owner to every production AI system.
Which of the following AI governance roles are formally defined and assigned in your organisation?
All five should be present for a mature programme. Missing executive accountability or per-system ownership are the most significant gaps: they indicate AI governance cannot be enforced or audited.
Does your organisation maintain a current inventory of all AI systems in use or under development?
An AI inventory is the prerequisite for proportionate risk treatment. It should cover production, staging, and development systems and be reviewed at least quarterly.
Which of the following fields does your AI system inventory record for each entry?
All six fields should be present. Risk classification and dependency tracking are the most commonly missing fields; without them the inventory cannot drive proportionate risk controls or supply chain oversight.
For AI systems that a regulator classifies, which of the following does your inventory hold?
Options run from the most commonly held to the least. A classification field with no determination behind it is a claim, not a record, and the determination is what an authority asks to see. Systems assessed as exempt are the ones most often missing a registration reference, because the exemption is read as removing the filing rather than pairing with it.
Does your organisation apply a documented risk management process to AI systems throughout their lifecycle?
The process should cover risk identification, analysis, evaluation, treatment, and residual risk acceptance. It should be triggered before deployment and after any substantial modification, not only at initial development.
At which points in the AI system lifecycle is a formal risk assessment conducted?
Assessments conducted only at initial deployment miss risk accumulation from model drift, changed use contexts, and regulatory evolution. A mature process triggers reassessment at all five points.
How are your AI risk tolerance statements expressed?
Enterprise buyers should expect at minimum quantified thresholds for the risk dimensions relevant to your AI use cases. Qualitative-only statements cannot be verified or used to drive consistent risk treatment decisions.
Does your organisation complete a documented impact assessment before deploying an AI system that may affect individuals or groups?
AI impact assessments must go beyond standard risk assessments to address population-scale harms including discrimination, privacy, economic effects, and societal impacts. The assessment should be retained and revisited when system purpose or data inputs change.
Which of the following harm categories does your AI impact assessment explicitly evaluate?
All six categories should be assessed for systems affecting individuals. Missing vulnerable group analysis or societal harm evaluation are common gaps that create regulatory exposure under the EU AI Act and GDPR.
Is a design document approved for each AI system before development begins?
Undocumented intent makes post-deployment evaluation and audit impossible. Look for version-controlled design documents that predate development commencement and are approved by the system owner.
Which of the following are recorded in your AI system design documentation before development proceeds?
All six elements are expected. The socio-technical decisions, fairness, explainability and safety modes, are the ones most often absent from documentation inherited from a general software development template.
Are defined verification and validation procedures executed before any AI system is deployed or after a substantial modification?
AI V&V must cover dimensions conventional software testing misses: distributional robustness, fairness across population subgroups, and safety failure modes. Testing should not be performed solely by the team that built the system.
Which of the following are included in your AI system V&V testing?
All six elements characterise a mature AI V&V process. Fairness evaluation and independent review are the most frequently absent from programmes that inherit generic software testing practices.
Does a documented deployment plan exist for each production AI system, dated before its deployment?
The plan is the artefact, not the intention. An assessor compares the plan date against the deployment record date for a sample of releases; a plan written after go-live does not meet the control.
Which of the following does the deployment plan record for each production AI system?
Options run from the most commonly recorded to the least. Without a worked definition of a substantial modification, teams reach inconsistent judgements about when a change needs the full gate. Retraining on a new data source and a change to an inference threshold are the two cases worth naming.
Does your organisation maintain a model registry that tracks all ML models in development and production?
A model registry is the prerequisite for tracing production models to their training data and evaluation results, essential for incident response, audit, and debugging. Net-new control: not addressed at this operational level by NIST AI RMF, ISO 42001, or the EU AI Act.
Which of the following are recorded in your model registry for each entry?
All six fields should be present. Missing training dataset references or evaluation metrics at registration time are the most common gaps: they prevent traceability between production behaviour and training decisions.
Is a completed model registry entry required before a model can be promoted from staging to production?
A mandatory promotion gate ensures the registry accurately reflects what is running in production. Registries that are populated after deployment rather than as a gate provide much weaker auditability.
Does your organisation have a documented procedure for decommissioning AI systems?
Retired AI systems that remain partially active (orphaned model endpoints, residual data pipelines) create unmonitored risk. Decommissioning should be a controlled, auditable process with system owner sign-off.
Which of the following steps does your AI system decommissioning procedure require?
All five steps should be present. The most commonly missed is verification of downstream pipeline removal. Orphaned integrations calling decommissioned endpoints are a recurring production incident pattern.
Are the data used to train, fine-tune or evaluate AI models subject to documented data management practices?
Training data quality is the single largest determinant of AI system quality. Practices should include documented quality requirements, bias identification steps, and validation before use.
Which of the following training data management practices are applied before model training begins?
All six practices are expected for a mature data governance programme. Missing bias identification or subgroup handling documentation creates exposure to fairness failures that surface after deployment.
Is the provenance of every dataset used to train, fine-tune or evaluate a production model recorded?
Answer for the datasets behind the models currently in production. A record that covers the most recent dataset but not the ones earlier versions were trained on does not meet the control, because the obligation attaches to the model for as long as it is in use.
What does your training data provenance record include for each data source?
All six elements are expected for any source used by a production model. The link to the model registry is the element most often absent and the one that decides whether a disputed source can be traced to the models that consumed it.
Does every training and evaluation dataset carry a recorded special-category screening result?
The screening result records what the dataset was screened for, the outcome and the date, whether or not special category data was found. A dataset that has never been screened does not meet the control even if it holds no such data.
Where a training or evaluation dataset holds special category personal data, which of the following are recorded for it?
Answer for the datasets that screened positive. If no dataset holds special category data, the screening results in Q1 are the evidence and this question does not apply. Absence should be recorded positively rather than assumed.
Does technical documentation exist for each AI system before it is deployed?
Technical documentation is the primary evidence artefact for AI governance audits and regulatory inspections. It must be version-controlled and the current version should correspond to the deployed model version.
Which of the following sections are included in your AI system technical documentation?
All eight sections are expected. Known failure modes and human oversight mechanisms are the two sections most often missing from documentation inherited from a general software template. They are also the two an enterprise buyer reads first.
Does the current version of each system's technical documentation correspond to the version of the system in production?
Compare the documentation version against the model or release version recorded in the registry for a sample of systems. Documentation that describes a version no longer deployed fails this question even where every required section is present.
Are users of your AI systems informed that they are interacting with an AI before or at the point of first interaction?
Undisclosed AI interaction is deceptive and a regulatory obligation in most jurisdictions. Disclosure must be presented before interaction begins and should not be easily dismissed or hidden.
For AI systems that generate synthetic content or converse with users, which of the following disclosure mechanisms are in place?
All four mechanisms apply to generative AI systems producing synthetic media. Organisations using AI only for classification or decision-support (not synthetic media generation) should note which apply and which do not. The persona review item applies to any system with a name, an avatar or a conversational voice: it asks whether someone looked at the interface for human images, statements of feeling and humanoid imagery and recorded a decision on each.
For AI systems that make or inform decisions about people, which of the following are in place?
Options run from the most commonly in place to the least. The population here is wider than the users of the product: a person refused a service never sees the interface, so a disclosure built into the product reaches none of them. An explanation that points the reader at published model documentation does not set out the main elements of their decision.
Is the explainability capability of each AI system that produces decisions or recommendations affecting users documented?
Unexplainable AI outputs prevent operators from identifying errors or challenging decisions. Documentation should specify what explanations are available (feature attribution, confidence scores, decision paths) and, where explanation is not technically feasible, state this limitation explicitly.
Which of the following does your explainability documentation record?
Options run from the most commonly recorded to the least. At least one explanation type applies to any system in scope. Where explanation is not technically feasible the last item is the honest answer. It is a weak position unless the oversight design in AIG-022 carries the weight instead.
Does each production AI system have a documented monitoring plan?
AI system behaviour degrades in ways not visible from infrastructure metrics alone. Monitoring must include AI-specific measures: confidence score distributions, null or refusal rates, output category distributions, in addition to standard latency and error rate metrics.
Which AI-specific metrics are included in your production monitoring for AI systems?
Programmes that monitor only latency and error rates are using generic application performance tooling, which misses the behavioural degradation patterns specific to AI systems. The last item applies only where agents select their own actions; where they do, it is the metric that shows an agent pursuing something other than the task it was given.
Which of the following does the monitoring plan record for each production AI system?
Options run from the most commonly in place to the least. Operational monitoring answers whether the system is healthy now; the field data limb answers whether what was claimed about it at release still holds. The conformity evaluation is the element most often missing, because collecting field data is easier than drawing a conclusion from it.
Are deployed AI models evaluated on a scheduled basis for performance degradation and distribution shift (data drift, concept drift)?
Model drift is an AI-specific failure mode with no equivalent in conventional software. Without scheduled evaluation, degraded models operate undetected. Evaluation should use held-out test data or shadow deployments and trigger a documented escalation path when thresholds are breached.
How frequently are your production AI models evaluated for drift or performance degradation?
Options run from strongest to weakest. Frequency should match the velocity of the underlying domain: a fast-moving domain such as fraud or content moderation needs monthly evaluation or better. Annual evaluation is insufficient wherever the data environment changes.
Do your AI systems record an event log for each inference or decision?
AI event logs are the primary forensic artefact when AI-driven decisions are challenged or incidents require root-cause analysis. Logs must be protected from tampering and retained for the period required by applicable regulations.
What is the log retention period applied to your AI system event logs?
Answer with the retention actually configured on the AI event log store. The control requires retention to meet the period applicable regulation sets and to align with the audit log retention in MON-003; where a deployment is subject to the EU AI Act the deployer floor is six months. Longer retention carries its own data protection cost and should be set deliberately rather than by default.
Which fields are captured in your AI system event logs?
The first seven fields apply to every AI system. The generative fields apply where the system produces free text or media. Full prompt and response content is required only for the last case and has to be protected by access controls restricting it to security and operations roles.
Does a documented process exist for detecting, investigating and responding to AI system incidents?
A generic IT incident process does not meet the control. The AI process has to define AI-specific incident categories and the notification obligations that attach to a serious incident; Q2 captures which parts are present.
Which of the following are covered in your AI incident response process?
The serious incident definition, the reporting deadlines and the bar on altering the system are the three a process inherited from IT incident management will be missing. The deadline runs from the moment the organisation or an operator becomes aware of the incident, not from the moment the investigation concludes. AIG-043 asks about corrective action on a system found not to conform and about what an authority can ask for afterwards.
Do AI systems that produce outputs used in decisions affecting individuals have documented human oversight mechanisms proportionate to their risk level?
Human oversight is the last line of defence against harmful AI outputs. It must be substantively designed, not nominal. Oversight persons must have defined competencies, training, and sufficient time to conduct meaningful review.
Which of the following are true of the human oversight of your AI systems used in decisions affecting individuals?
Every item applies to each system in scope. An override rate at or near zero sustained over a long period is a signal that review is nominal rather than substantive, which is why monitoring the rate against an expected range matters more than the rate itself.
Is there a documented override and safe-state procedure for each production AI system?
AI systems that cannot be safely stopped or overridden are ungovernable. Override, suspension, and deactivation procedures must be documented, accessible to operators, and tested at least annually, not left to vendor support.
Which of the following override and safe-state capabilities have been tested within the defined interval for your production AI systems?
The test record is the evidence, not the documented procedure. The fourth item is the one that decides whether the mechanism works during an incident: a deactivation that requires a supplier support ticket is not available at the moment it is needed.
Does your organisation maintain a documented list of AI use cases that are prohibited?
A prohibited use list translates regulatory red lines (EU AI Act Art. 5) and organisational ethics commitments into concrete guardrails that engineering and product teams can evaluate against during design and launch review.
Which of the following categories are named in your prohibited AI use list?
The ten categories are the minimum the control asks for. The last two were added to the EU AI Act Article 5 prohibitions by Regulation (EU) 2026/1744 and apply from 2 December 2026, so a list written before that date will usually be missing them. Organisational prohibitions beyond the ten are expected and are not scored here.
Do AI systems that score, rank, recommend or classify individuals have documented fairness objectives?
Bias cannot be detected without predefined, measurable fairness criteria. Objectives should specify the fairness metric (e.g. demographic parity, equalised odds) and the pass/fail threshold, relative to the system's purpose and affected population.
How is bias testing conducted for AI systems subject to bias risk in your organisation?
All five practices are expected. Bias testing conducted only at deployment without production monitoring misses in-production bias accumulation from feedback loops and data drift.
Are AI systems evaluated for AI-specific security vulnerabilities?
AI-specific attacks are not detected by conventional SAST/DAST tooling. Evaluation must be explicitly scoped to AI attack classes and conducted separately from standard application security testing.
Which AI-specific attack classes are evaluated in your AI security testing programme?
Coverage of all six attack classes characterises a mature AI security evaluation. The results belong in a report of their own: an application penetration test that mentions the AI endpoint does not evidence this control, because it tests the interface rather than the model.
Which of the following training data extraction controls are applied to your LLM-based systems?
Membership inference testing and extraction probing are the minimum baseline. Mitigations (output length constraints, PII redaction, differential privacy) are required for any LLM that scores above the documented risk threshold in its evaluation. The risk evaluation methodology and results must be retained.
Do AI systems whose outputs are acted upon have a defined acceptable output range or confidence threshold?
Net-new control: confidence-gating is a structural quality control unique to probabilistic AI systems, not addressed by existing frameworks at an operational level. Outputs acted upon without confidence validation create uncontrolled downstream risk.
What action is taken when an AI output falls below the defined confidence threshold?
Options run from strongest to weakest. Mandatory escalation, human review and abstention all meet the control. Passing a low-confidence output through unchanged does not, because nothing downstream can tell it apart from a confident one.
Is a measured hallucination rate recorded for each generative use case whose outputs users may rely on as factual?
The measurement is the control. A use case with grounding mechanisms in place but no measured rate against a documented threshold does not meet the first clause.
Which of the following are in place for your generative use cases that produce statements users may rely on as factual?
Every item applies to each use case in scope. The grounding mechanism may be retrieval with source citation, a post-processing verification step, an uncertainty score carried with the output or another mechanism that does the same job; the control does not require a named technique. A disclaimer on its own is a disclosure, not a grounding mechanism.
Is prompt injection named in the threat model of each system that places user-supplied or externally sourced content into a model prompt?
Answer for the systems in scope, not for the organisation. A threat model that names injection only as a generic input validation risk does not meet the control; the entry should identify the untrusted content sources the system consumes.
Which of the following are in place for your systems that place user-supplied or externally sourced content into a model prompt?
Every item applies to each system in scope. Indirect injection is the path most often untested: content arriving from a retrieved document, a web page or a tool response carries instructions without any hostile user being present. For a system that calls tools, the last four items are the containment that decides how far a successful injection reaches.
Do your AI systems exposed to external users have a mechanism to detect misuse attempts?
Net-new control: public-facing LLM systems face continuous adversarial probing. Misuse detection is an AI-specific operational security control with no equivalent in classical application security and is not addressed operationally by any existing framework.
Which misuse and abuse detection capabilities are active for your public-facing AI systems?
Options run from the most commonly in place to the least. AI-specific rate limits separate from generic API rate limits are often absent: shared limits allow targeted abuse to consume a disproportionate share of capacity before a generic control notices. A ceiling is a different instrument from a rate limit and is the item most often missing: it bounds what one request, job or run may consume and it stops the work, where an alert on a budget is outrun by a fast workload.
For each generative model or modality you place on the market, which of the following are recorded?
Options run from the most commonly recorded to the least. A detection-only posture answers whether misuse is being caught, not whether the outcome was reachable without real effort and whether anything stopped it first. Where the law turns on foreseeability and on the adequacy of safeguards, an undocumented judgement is not a defence.
Does your organisation perform a documented risk assessment before integrating a third-party AI system, model, or AI-enabled service?
Third-party AI systems introduce risks distinct from conventional software vendor risk: model changes without notice, training data leakage, provider-level safety failures. Assessment should cover data practices, change notification policies, and exit options.
Which of the following dimensions does your third-party AI risk assessment cover?
All seven dimensions are expected for foundation model providers such as LLM APIs. Whether inputs are used for model training is often the most commercially sensitive dimension and should be confirmed in contract terms, not assumed from general documentation.
Do your written agreements with third-party AI providers allocate responsibility for compliance with applicable AI regulation?
The same model can shift from non-high-risk to high-risk depending on how it is deployed, so the agreement states who carries which regulatory duty and what documentation, incident and model-change information the provider supplies, with timeframes.
Where your organisation provides an AI system that a customer deploys, do customers receive written instructions for use?
A provider bears upstream responsibility for enabling customers to govern the AI systems they deploy. Incomplete instructions create downstream governance failures and regulatory exposure for both parties under the EU AI Act.
Which of the following are included in the instructions for use you provide to customer deployers?
Options run from the most commonly provided to the least. Impact assessment information packs and deployer obligation checklists are the usual gaps: they shift the compliance burden onto customers who lack the technical context to carry it. For the identification marking, answer against what a customer can see in the product or its documentation, not against what appears on your website footer.
Which of the following are addressed in your agreements with integrators that build on your AI systems?
All six provisions are expected for agreements covering high-risk AI systems. The obligation covering high-risk reclassification by downstream use is the provision most often absent from AI supply chain contracts.
Is there a documented quality management system covering how your AI systems are developed, tested and released?
Answer yes only where a single approved document set exists that names procedures and owners. An AI policy on its own, or a set of procedures with nothing binding them together, is a no here and is covered by AIG-001 and by the lifecycle controls instead.
Which of the following does your AI quality management system cover?
Options are listed in the order the elements appear in a typical manual, not in order of importance. Tick an element only where the system names the procedure that implements it; a heading with no procedure behind it does not count.
How often is the quality management system reviewed with the review recorded?
Options run from the most frequent to the least. Answer on the recorded reviews rather than the interval the manual states: a documented annual cycle with no minutes from the last cycle is the last option.
Has a conformity assessment been completed for every AI system you have determined falls into an assessed category?
The determination itself is recorded against each system in the AI system inventory (AIG-003). Where you have determined that no system falls into an assessed category, answer yes and keep the determination available; the assessor tests the determination, not the absence of assessments.
Which of the following does your conformity assessment record contain?
Options follow the order in which the items are produced. Tick the evidence item only where each requirement has a named artefact against it; a summary statement that the requirements are met does not count.
Who completes and signs off the conformity assessment?
Options run from the most independent to the least. Answer for the route actually used in the last twelve months, not the route the procedure allows for.
Is there a published channel through which someone outside your organisation can report an adverse impact of an AI system?
A general support queue counts only where it is published as a route for adverse-impact reports and reaches people who are not customers. An internal reporting route for staff is HRS-009 and does not answer this question.
Which of the following apply to reports received through the channel?
Options follow the path a report takes from receipt to review. Tick the adjudication item only where the outcome is recorded against the report; closing a ticket without an outcome does not count.
Who adjudicates reports received through the channel?
Options run from the most independent to the least. Answer for the reports actually received in the last twelve months; where none were received, answer for the route the procedure assigns.
Is there a register recording what each AI system you operate is used for?
The AI system inventory (AIG-003) records that a system exists and who owns it. This question is about the use: the purpose it is put to and the uses its instructions permit and exclude. One register can serve both provided both sets of fields are present.
Which of the following are recorded for the AI systems you operate?
Options follow the order the items appear in a use register. Answer for what is recorded today, not for what the process says should be recorded.
How is use outside a system stated intended purpose handled?
Options run from the strongest handling to the weakest. Answer for what happened the last time a use fell outside the instructions, not for what the process states.
Does your customer agreement state whether customer content may be used to train or fine-tune your models?
An agreement that is silent on the question is a no. Answer yes where the agreement addresses it either way, including where it states that customer content is never used for training.
Which of the following apply to your use of customer data in model training?
Options follow the path from the agreement through to the dataset. Tick the pipeline item only where the filter is enforced by the build; a documented instruction to engineers does not count. Where you never use customer content for training, tick the first item and the lineage item if they hold; the assessor then tests the exclusion instead of the permission.
How is the exclusion of a customer data from training enforced?
Options run from the strongest enforcement to the weakest. Answer for the pipeline that produced your most recent training dataset.
Have you recorded, for each market you place an AI system or model on, whether a local representative is required?
This asks for the determination, not the appointment. A recorded conclusion that no representative is required, with the reason, is a yes. An assumption that the obligation does not apply, with nothing written down, is a no.
Where a representative is appointed, which of the following does the written mandate contain?
Answer for the mandates in force today. Where you have determined that no representative is required in any market, select None of the above; the determination is tested under question one.
When is the representative determination revisited?
Options run from the most complete trigger set to the least. A determination made once at launch and never revisited is the last option even where it remains correct.
Does each AI agent that can invoke tools hold a permission set enforced by the system rather than described in its prompt?
A prompt instruction telling an agent which tools to use is not an enforced permission set. Answer yes only where the orchestrator or the tool layer refuses a call outside the set. Where you run no agents that invoke tools, this control does not apply to you.
Which of the following are in place for agent tool permissions?
Options follow the path from grant to invocation and then to delegation. The scope item asks whether a permission to call a tool is bounded, for example to one account, one repository or one spend limit, rather than being a permission to call it for anything. The last three items are about borrowed authority: an agent acting for a user, a shared tool and a sub-agent are the three places an authority quietly widens.
What happens when an agent attempts an action classified as consequential?
Options run from the strongest gate to the weakest. Answer for the behaviour of the system in production, not for the behaviour a configuration flag could produce.
Is there a defined route for handling an AI system found not to conform with the requirements applicable to it?
Answer yes where the route is written down and has an owner, whether or not it has been used. A general product defect or bug process counts only where it names the corrective actions available and the parties outside the organisation who have to be told; Q2 captures which parts are present.
Which of the following does your non-conformity and authority cooperation handling cover?
Options are grouped, the four corrective actions first, then the notification duties, then the authority request route. Tick an option only where the route exists for a named system rather than as a general intention. The two authority request options are the ones an organisation that has never had a request tends to leave untested. They are also the ones with a deadline attached when a request arrives.
Is the pipeline that trains, fine-tunes and evaluates production models secured as a system in its own right?
Answer for the training run and its storage, not for the application build pipeline, which is APP-012. An organisation that trains no model and only calls a provider's model answers no and records that the control does not apply.
Which of the following are in place on the training pipeline?
Options follow the pipeline from configuration to assessment. Detection over the logs is the item most often missing; logging alone is the fifth option only when a rule fires on it.
When are the pipeline security measures assessed?
Options run from the fullest cadence to none. A threat named in an assessment record is what shows the assessment considered anything.
Are reads and writes to the durable memory your AI agents keep between tasks authorised within the user, tenant, agent and session scope of the request?
Durable memory is any state an agent reads or writes across tasks or sessions: saved preferences, conversation summaries, stored history, episodic or semantic memories and agent-managed experience stores. A store that any agent or session can read or write in full is not scoped. Where no agent keeps state between tasks, this control does not apply to you.
Which of the following are in place for agent memory?
Options follow the lifecycle from policy to write, from write to retrieval and from retrieval to recovery. The self-authored output item asks whether an agent can promote its own conclusions into memory it will later trust without a check; that is the loop a poisoned entry reinforces itself through.
What happens when an entry in agent memory is suspected of being poisoned?
Options run from the strongest response to the weakest. Answer for the procedure that has actually been used or tested, not for a capability the store could offer.
Does each point where your systems rely on user-supplied or external audio, image or video as evidence of identity, provenance or a real-world event run a detection step for synthetic or manipulated media before the content is relied on?
Identity verification, onboarding checks, evidence uploads and moderation queues are the usual intake points. A step that runs after the decision has been made, or that only logs a score, is not a detection step in this sense. Where a documented assessment concludes that no system relies on inbound media in this way, answer on that assessment.
Which of the following are in place for inbound media at those points?
Options run from the assessment to the step, from the step to the outcome and from the outcome back to the method. The rates item asks for numbers measured on a set the organisation can name, not a vendor's published figure.
What happens to inbound media that fails the synthetic media detection step?
Options run from the strongest disposition to the weakest. Answer for the behaviour of the system in production at the intake point with the highest-impact decision.
Does your organisation have a documented secure software development lifecycle (SDLC) policy that defines required security activities at each development phase?
The policy must cover all phases: requirements, design, development, testing, deployment, and maintenance. It should have a named owner, effective date, and defined review cadence.
How frequently is the secure SDLC policy reviewed and updated?
Annual review is the minimum. The policy should be updated whenever there is a significant change in development technology, tooling, or regulatory requirements.
Which of the following does your secure development lifecycle documentation record?
Options run from the most commonly documented to the least. Tool configurations are the element most often left out, and they are where a requirement quietly stops being met: a scanner running with its rule classes disabled still satisfies an unqualified requirement to run a scanner. Name capabilities rather than products in the register itself.
Are information security and privacy requirements formally identified, documented, and approved before development begins on new applications or significant features?
Requirements must be documented before the first development sprint, not derived after implementation. Traceability from requirement to implementation and testing is expected.
How are security requirements derived for new development work?
Requirements derived from threat modelling and risk assessments are most robust. Ad hoc approaches without a defined method introduce inconsistency and gaps.
For which development work is a documented threat model produced?
Options run strongest to weakest. Coverage of supplier-built components is the limb most often missing: the threats are the same and the analysis arrives only if the agreement asks for it. A threat model produced after the design is settled tests documentation rather than design.
Has your organisation adopted documented secure coding standards?
Standards must be accessible to and used by all developers, not just security specialists. They should reference an industry taxonomy (e.g. OWASP Top 10, CWE Top 25) and be reviewed at least annually.
Which of the following apply to your secure coding standards?
Options run from the most commonly in place to the least. Automated enforcement in continuous integration is the strongest mechanism. Standards published with no enforcement and no training give weak assurance. Standards naming no taxonomy cannot be tested against anything.
Is security testing integrated into your development and release pipeline?
Security testing must be automated in CI/CD, not performed only before major releases. Blocking gates for critical and high findings are expected.
Which security testing activities are integrated into your development pipeline?
SAST and SCA on every PR are baseline expectations for a mature secure development pipeline. DAST on release candidates and IaC scanning indicate a more comprehensive posture.
Is penetration testing of production applications, APIs and infrastructure conducted at a defined frequency of at least annually?
Testing must be performed by a party independent of the development team, either an external firm or a distinct internal red team. Self-assessed or developer-led testing does not satisfy this control.
How are penetration test findings managed after testing is complete?
Every finding must have a corresponding ticket. Critical findings should be remediated and retested within 30 days. Untracked or unconfirmed remediation significantly weakens the value of the pen test. The strongest option separates out the case that usually leaks: a test a customer commissioned against the production estate produces findings that belong in the same tracker on the same terms, not in a report filed with the account team.
Which of the following best describes the scope and approach of your most recent penetration test?
Options run strongest to weakest. At minimum, production APIs and public-facing applications belong in scope. Count an adversary simulation only where written rules of engagement were agreed before it started; an unscoped exercise is a different activity with a different risk profile. A bug bounty alone does not satisfy this control.
Is a software bill of materials generated for each production build?
Monitoring must be continuous, not just at the time of initial selection. SCA tooling integrated into CI is the expected mechanism, not periodic manual checks.
Which dependency and patch management practices are in place?
Options run from the most commonly in place to the least. Automated composition analysis in the pipeline with a deployment gate is the baseline; manual-only review leaves published vulnerabilities unaddressed for weeks. A binary-only component from an unwarranted source is worse than an unpatched one: nobody can read it, nobody is obliged to fix it, and the scanner reports only what its metadata claims.
Are all secrets held in an approved secrets management system rather than in source code, configuration files, version control or a prompt the model reads?
Answer for the secrets in production use. A prohibition on hardcoding that is stated in a policy but not enforced by scanning in the pipeline does not meet the control; Q2 captures which enforcement is in place. A system prompt counts: whatever the model can see, a user can eventually see.
Which secrets management controls are in place in your development and deployment environment?
A vault combined with CI-based secret scanning provides both preventative and detective coverage. Prompt templates are the surface most often left out of the scan, because they are treated as content rather than as configuration.
Are all changes to production systems, applications, infrastructure and configuration subject to a formal change management process?
Every production change, including infrastructure and configuration changes, must have a traceable record. Emergency changes require an expedited but still documented approval, not zero oversight.
How are production changes authorised and deployed in your organisation?
Every production deployment should be traceable to an approved change record. The ability to audit who approved what change, and when, is a key audit expectation.
Which of the following are part of your change approval and post-change process?
Options run from the most commonly in place to the least. Naming who approves keeps security and privacy from being represented by whoever is nearest. Testing that a change works is not testing that the controls it touched still do: a change that quietly disables logging on a subsystem passes every test written for the change itself.
Are development, test and production environments separated logically or physically?
Separation must be structural (e.g. separate cloud accounts, VPCs, Kubernetes namespaces), not solely procedural. Developers with write access to dev/test must not hold equivalent production write access.
Is production data permitted in development or test environments?
Use of production data in non-production environments without de-identification is a data protection risk and a finding in most audit frameworks. Any approved exceptions must have a de-identification record.
Which of the following apply to the separation between your development, test and production environments?
Options run from the most commonly in place to the least. Separation enforced only by naming convention is not separation. The test is whether an account that can deploy to test can also deploy to production.
Are all externally exposed and internally significant APIs subject to a defined set of security controls?
Authentication and authorisation must be enforced on every endpoint. Unauthenticated routes should be the exception with documented justification, not the default. Sensitive data must not appear in query parameters or error responses.
Which API security controls are implemented in your production environment?
Authentication, object-level authorisation, and rate limiting are the three most impactful controls for preventing the most common API vulnerabilities (OWASP API Top 10).
Are build artefacts cryptographically signed?
Signing and verification must both be in place and automated. Signing without verification provides no meaningful protection. Unsigned artefacts should be rejected by the deployment pipeline.
Which software integrity controls are in place in your build and deployment pipeline?
Options run from the most commonly in place to the least. Signing plus verification at deployment is the baseline; signing without verification protects nothing. For the bound response, count only an action the tooling takes on its own, not a runbook step a responder follows after reading an alert.
Are documented secure architecture and engineering principles formally adopted?
The principles must be documented, accessible to engineers, and demonstrably applied in design decisions, not merely stated in a policy document. Architecture decision records (ADRs) are a typical artefact.
How are security architecture principles applied during the design of new systems or significant changes?
A formal design review with a security stakeholder, producing documented architecture decision records (ADRs), is the expected practice for significant systems.
Does your organisation have a publicly accessible vulnerability disclosure programme (VDP) or responsible disclosure policy that defines how external researchers can report security vulnerabilities?
The VDP must be publicly reachable without authentication, include a defined submission channel, scope statement, response timeline commitment, and a safe-harbour clause protecting good-faith researchers.
How is your vulnerability disclosure programme operated?
A formal VDP page with a defined SLA is the minimum. A managed bug bounty programme with scope, triage, and tracking provides stronger coverage. The absence of any disclosure channel leaves reported vulnerabilities without a clear path to resolution.
Is there a documented processing specification for each service that transforms customer data?
The specification is what an integrity check is tested against. Without one, a completeness check can only confirm that the job ran.
Which processing integrity controls are in place?
Quarantine and correction are the pair that matters: a pipeline that drops bad records silently passes a completeness check on what it kept.
How are processing exceptions handled?
Options run from strongest to weakest. This measures whether an exception reaches a conclusion, not whether it is visible.
Does code from outside your own build pipeline execute only inside a confined environment?
Customer-supplied scripts, third-party plug-ins and code a model writes at run time all count. If any of them executes in the application process, the answer is no.
Which restrictions apply to the environment that runs external code?
The credential question is the one that decides the blast radius: an environment that can reach the cloud instance metadata service holds the privileges of the host regardless of its other limits.
What boundary confines the execution?
Options run from strongest to weakest by how much of the host is reachable after an escape. An interpreter restriction is defeated by any bug in the interpreter.
Does your organisation have a documented business continuity plan?
The BCP should be formally approved by senior management, version-controlled, and updated following any significant incident or organisational change.
When was the Business Continuity Plan last formally reviewed and approved?
Annual review is the minimum requirement. A review triggered by a significant incident or major organisational change within the review period also satisfies this requirement.
Which of the following does your business continuity plan record?
Options run from the most commonly present to the least. Failover regularly costs centralised logging or a break-glass boundary, so the security posture under disruption is worth writing down before it is discovered during one. The handover points between plans are where multi-plan incidents fail.
Does your organisation have a documented disaster recovery plan?
The DRP is distinct from the BCP: it should contain specific technical runbooks for recovering each critical system from backup or failover infrastructure.
What does the Disaster Recovery Plan include?
Options run from the most commonly present to the least. A plan carrying only high-level guidance is not usable under pressure. Transaction recovery is the element most often absent: restoring the last snapshot brings a system back running while leaving in-flight transactions half applied, so the service is available and the data is wrong.
Are recovery time objectives and recovery point objectives defined for each critical service?
RTOs and RPOs must be explicitly defined, not inferred from backup frequency or infrastructure configuration. Each objective should be signed off by a named business owner.
Which of the following apply to your recovery time and recovery point objectives?
Options run from the most commonly in place to the least. The control requires the objectives to be defined and agreed, not any particular number. An objective the recovery team has never seen is a commitment made on their behalf.
Are data and system backups performed at a frequency that satisfies the defined recovery point objective?
Backups should cover application data, system state, and configuration. Encryption using a managed KMS key and IAM-restricted access to backup storage are expected.
Which of the following characteristics apply to your production backup implementation?
All six characteristics are expected for a production backup implementation that satisfies RPO commitments and audit requirements.
Is backup restoration tested at a defined frequency of at least annually?
Restoration tests must use actual production backup data, not synthetic test backups. Test results should document measured recovery time and data integrity outcomes.
What was the outcome of the most recent backup restoration test?
A passing test with documented results is the expected outcome. Any failure should trigger remediation before the next test cycle. An untested backup set should be treated as unverified.
Are business continuity and disaster recovery plans exercised at least annually?
Exercises should include personnel with defined response roles. Lessons learned must be captured and result in updates to the BCP, DRP, or related procedures.
What type of BCM/DR exercise was most recently conducted, and when?
A tabletop exercise is the minimum acceptable exercise type. A full simulation or live failover test provides the strongest evidence of plan effectiveness.
Which of the following follow each continuity or recovery exercise?
Options run from the most commonly in place to the least. An exercise that produces no change to any plan is usually an exercise that tested the plan nobody doubted. Record the scenario as well as the outcome, because the scenario is what decides whether the test was worth running.
Do documented provisions exist for processing critical workloads from an alternate site or cloud region?
Alternate processing provisions must not depend on access to the primary site or primary-site telecommunications. Out-of-band channels (e.g. personal mobile numbers, separate messaging platform) should be verified annually.
Which alternate processing and communication provisions are documented and tested?
Options run from the most commonly documented to the least. Untested provisions and unverified contact lists are the usual gaps. Accessibility is the assumption least often checked: an alternate region picked for latency often shares a power grid, a carrier or a staffing pool with the primary, so the event that takes out one reaches the other.
Does a business impact analysis exist that ranks business processes by recovery priority?
The analysis ranks business processes, not servers. A list of systems by criticality is an asset inventory and answers a different question.
Which of the following does the business impact analysis record for each process?
Impact at more than one duration is what produces a defensible tolerable disruption period. A single worst-case figure ranks everything as critical and tells the recovery team nothing.
When is the business impact analysis reviewed?
Options run from strongest to weakest. The change trigger matters more than the interval: a new product line or a new third party can move a process two priority bands between annual reviews.
Is at least one backup copy written to a store that cannot be altered or deleted before its retention period expires?
The store has to refuse the deletion. Answer no where deletion is prevented by a permission an administrator can grant themselves, or by a policy that says not to.
Which of the following apply to that copy?
The test an assessor runs is to try the deletion with the credentials an attacker would have taken. Answer against what those credentials can do today, not against the intended design.
How much of the recovery scope has an immutable isolated copy?
Options run from strongest to weakest. Recovery scope means the systems the continuity plan commits to restoring, so the answer is measured against that list rather than against the backup estate as a whole.
Is there a list of third-party services whose loss would breach a recovery objective?
This is a shorter list than the vendor inventory: only the services whose unavailability would stop a process from meeting its recovery objective. Model and inference providers count.
Which of the following does each entry record?
A contingency is what the service does, not what the incident team would decide at the time. For model providers the pinned version matters because a withdrawn version is an outage with a date on it. The last item is the one usually taken on trust: a provider that promises a customer continuity through a chain it has not contracted for is promising something it cannot enforce.
How is the contingency for a listed provider exercised?
Options run from strongest to weakest. Blocking the provider in a production-equivalent environment is what finds the retry loop, the missing timeout and the fallback that was never wired up.
Does your organisation maintain a documented data classification scheme?
The policy should define at least three tiers (e.g. Public / Internal / Confidential / Restricted) and specify handling rules for storage, transmission, sharing and disposal at each tier. It must be approved by a named owner and reviewed within the last 12 months.
How are data assets assigned a classification tier?
Automated tooling provides the most reliable coverage at scale. Manual classification by data owners is acceptable for smaller or less dynamic data sets, provided a data inventory confirms consistent application.
For which of the following does the classification scheme define handling controls at each sensitivity level?
A scheme that names sensitivity levels without saying what changes between them gives an asset owner nothing to apply. Answer against the scheme as written, not against what the organisation does in practice.
Are information assets labelled in accordance with the data classification scheme so that recipients can identify the classification at the point of use?
Labels should be visible on documents, data stores, outputs and transmissions. Automated labelling via DLP or sensitivity label tooling (e.g. Microsoft Purview, Google Workspace) is preferred over purely manual labelling.
Which asset types have classification labels actively applied?
A mature labelling programme covers all major asset types. At minimum, documents, emails and data exports should be labelled. Gaps in cloud storage or database labelling should be noted.
Is all sensitive and confidential data encrypted at rest using an approved algorithm (AES-256 or equivalent) across databases, object storage, file systems and backup media?
Encryption must cover all environments holding sensitive or personal data including production databases, object stores (e.g. S3, Cloud Storage), backup snapshots, and attached volumes. Verify the algorithm meets AES-256 or an equivalent approved standard.
At which layer(s) is encryption at rest applied?
A defence-in-depth approach applies encryption at multiple layers. Field-level encryption for highly sensitive fields (e.g. national IDs, payment data) provides the strongest protection against logical access to the database layer.
Is all data transmitted over networks, internal and external, protected by an approved transport encryption protocol?
TLS 1.3 is preferred. TLS 1.0 and 1.1 must be disabled. This applies to all public-facing endpoints and to service-to-service communication within the infrastructure.
What is the minimum TLS version enforced on external-facing endpoints?
TLS 1.2 is the minimum acceptable baseline. TLS 1.3 is strongly preferred. Any answer indicating TLS 1.1 or lower requires a remediation plan.
Which of the following are in place for the certificates and transport encryption configuration of your production endpoints?
Automatic renewal removes the commonest outage behind this control, an expired certificate nobody was watching. Scanning on each deployment is stronger than a scheduled scan; either meets the last item provided it also runs after a change to a load balancer, an API gateway or a certificate.
Does your organisation have a documented cryptographic key management policy that covers the full key lifecycle: generation, storage, rotation, revocation and destruction?
The policy must specify key rotation periods, require keys to be stored separately from the data they protect, restrict and log access to key material, and be approved within the last 24 months.
How are encryption keys managed in your production environment?
Cloud KMS with automatic rotation is the baseline expectation where the environment runs on a cloud provider. Keys managed within the application without separation represent a significant control weakness.
Which of the following does your key management programme record?
The first six items are recorded per key, the last is recorded once for the organisation. Options run from the most commonly held to the least. A programme that records purpose and rotation but no lifecycle state can show that a rotation policy exists without showing that any individual key followed it. The recovery route is the element most often left to the key management platform's defaults, and the approved list is the one most organisations hold somewhere without connecting it to the keys in use.
Does your organisation maintain a current Records of Processing Activities (RoPA) or equivalent data inventory documenting all personal data processing with the fields required by GDPR Article 30?
The RoPA must include: processing purposes, data categories, data subject categories, legal basis, retention periods, third-party recipients, cross-border transfers, and applicable safeguards. It should be reviewed and updated at least annually.
How is the data inventory or RoPA maintained?
Options run from the strongest record to the weakest. A privacy management platform discovers flows and raises the entries nobody has touched; OneTrust, Securiti and TrustArc are examples of the category. A register in a documentation or collaboration system such as Confluence, Notion or SharePoint holds up where the number of processing activities is small and one person owns the review. A spreadsheet is acceptable at that size and fails the same way a register does, by going stale between annual reviews with nobody watching.
Does your organisation have a documented policy or procedure requiring that only the minimum personal data necessary for a specific, documented purpose is collected?
The policy should explicitly prohibit collection of personal data without a documented purpose and require review when product capabilities change. It should be approved by the DPO or equivalent authority.
How does your organisation enforce data minimisation and purpose limitation in practice?
A mandatory review gate in the development process (e.g. a privacy design review ticket) is the most effective control. Selecting multiple overlapping mechanisms indicates a mature programme.
Is a compatibility assessment recorded before personal data is used for a purpose that was not disclosed when it was collected?
The assessment covers the link between the old and new purposes, the context of collection, the nature of the data, the consequences for individuals and the safeguards applied. Answer yes only where the assessment is written down and dated before the new processing started. A decision recorded in a meeting note without those five elements is not one.
Does your organisation maintain documented retention schedules for all data categories?
Retention schedules should be assigned to all personal data categories in the RoPA, with a legal or business justification for each period. Deletion should cover primary storage, backups and replicas.
How is data deletion or anonymisation executed when a retention period expires?
Fully automated deletion across all storage tiers (primary, backup, replica) is the strongest control. Any manual or ad hoc approach must be supported by execution records to demonstrate completeness.
What does the retention schedule state about customer data once a contract ends?
Options run from the most commonly stated to the least. The sequence matters more than the periods: an erasure clocked from termination rather than from the end of the retrieval window deletes data a customer is still entitled to collect, and one with no completion condition deletes it mid-migration. Digital assets are the item most often left out, because they are held by a different team from the one that owns the retention schedule.
Is a current privacy notice published at or before the point of personal data collection, disclosing all information required by GDPR Articles 13 and 14?
The notice must include: controller identity and contact details, DPO contact (if applicable), processing purposes and legal bases, retention periods, third-party recipients, international transfer mechanisms, and all six data subject rights. It should be dated and reviewed within the last 12 months.
What process ensures the privacy notice remains current when processing activities change?
The notice should be updated proactively when new purposes, new third-party recipients, or changes to data subject rights mechanisms are introduced. Annual review alone is insufficient for a product whose processing changes between releases.
Which of the following apply to the way your privacy information is presented?
Options run from the most commonly in place to the least. Form and content fail differently: a notice listing every required element in six thousand words of legal prose is complete and not intelligible. The further-processing notice is owed before the processing starts, not at the next annual refresh of the notice.
Where consent is relied upon as the legal basis for processing, does your organisation use a consent management mechanism that records granular, freely given, specific and withdrawable consent?
Consent must be opt-in by default (no pre-ticked boxes). Withdrawal must be as easy as granting consent. Consent records should include timestamp, version, and categories consented to.
How is individual consent recorded and managed?
Options run from the strongest record to the weakest. A consent management platform and a mechanism built into the product are both acceptable, provided the record holds the individual, the timestamp, the consent version and the purposes agreed to; OneTrust, Cookiebot and Usercentrics are examples of the platform category. The test is whether a question about one person on one date can be answered from the record. Consent captured once at sign-up cannot be withdrawn for one purpose while the others stand.
Where a consent request sits inside a wider declaration such as terms of service, which of the following apply?
Options run from the most commonly in place to the least. Consent buried in terms of service is the commonest reason a recorded consent turns out to be invalid: the individual agreed to a document rather than to the processing. If no consent request is bundled into a wider declaration, answer against the standalone flow.
Is there a documented process for handling data subject rights requests?
Each right should have a documented workflow, identity verification step, and defined internal handoff. A request tracking log must demonstrate requests are actioned within 30 days (or 90 days with documented extension).
Which data subject rights can your organisation fulfil without requiring manual engineering intervention?
Self-service or tooling-assisted fulfilment for access, portability and erasure is the expected standard for a mature product. Rights that require manual engineering effort introduce delay and error risk.
Which of the following does your rights request process do?
Options run from the most commonly in place to the least. A refusal with no reasons and no complaint route leaves the individual with nowhere to go. Demanding identity documents for every request deters more people than it protects, and the burden of showing a request is excessive sits with the organisation rather than the requester.
Does a design review against privacy and security requirements take place before a feature involving personal data is deployed?
A privacy-by-design gate (e.g. design review ticket, DPO sign-off) must be completed before any new feature involving personal data is released to production. Default configurations should expose the minimum necessary data.
How are privacy-by-design requirements enforced in the development lifecycle?
A mandatory deployment gate with documented sign-off is the most effective control. Post-deployment review or best-efforts application indicates a significant control gap.
Do the default configurations in your product expose the minimum personal data necessary for the feature to work?
Answer against the state a new account or a new feature arrives in, before anyone changes a setting. A privacy-protective option that a user has to find and switch on is a setting, not a default.
Does your organisation conduct Data Protection Impact Assessments (DPIAs) before initiating processing activities that are likely to result in high risk to individuals, including AI-driven processing, large-scale profiling, or use of new technologies?
DPIAs must be completed before high-risk processing commences. GDPR Article 35 mandates them for systematic profiling, large-scale processing of special category data, and use of new technologies. AI-driven features frequently meet this threshold.
What triggers a mandatory DPIA in your organisation?
Trigger criteria should align with the ICO or EDPB list of processing operations requiring a DPIA. AI processing, profiling and special category data must be included. Fixed-interval-only DPIAs without activity triggers indicate a control gap.
Where an impact assessment leaves a high residual risk that cannot be mitigated, is the supervisory authority consulted before the processing begins?
Answer yes only where the consultation happens before processing starts and the authority's written advice is recorded against the assessment. The consultation has a statutory clock of its own, so a project that discovers the requirement late loses weeks. A recorded decision not to proceed also satisfies the clause.
Are all cross-border transfers of personal data to countries without an EU adequacy decision governed by an approved transfer mechanism such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)?
The 2021 EC SCCs must be used for transfers under the GDPR. Pre-2021 SCCs invalidated post-Schrems II are not acceptable. A Transfer Impact Assessment should accompany transfers to high-risk jurisdictions.
Which transfer mechanism(s) does your organisation rely upon for international transfers of personal data?
Most providers rely on 2021 SCCs for transfers to the US and other non-adequate countries. Sole reliance on Article 49 derogations for routine processing is not permitted under GDPR.
Is sensitive and personal data masked, pseudonymised or replaced with synthetic data in non-production environments (development, staging, test) and in analytics, support tooling and logs?
Production personal data must not appear unmasked in non-production environments or in internal tooling unless there is a documented and DPO-approved exception with appropriate compensating controls.
What approach is used to protect personal data in non-production environments?
Automated masking or exclusive use of synthetic data are the strongest controls. Manual masking without automated enforcement is unreliable. Using production data in non-production environments with access-only controls is not an acceptable substitute for masking.
Does your organisation have technical controls to detect and prevent unauthorised exfiltration of sensitive and personal data?
DLP controls should monitor all major egress channels (email, cloud storage, API exports, messaging). Network egress should be restricted by default. Alerts should route to a responsible reviewer.
Which data leakage prevention controls are active in your environment?
A layered approach combining application-level DLP, network egress controls and anomaly detection provides the strongest coverage. At minimum, DLP should cover email and bulk export channels for Confidential and Restricted data.
Has your organisation recorded an assessment of whether it is required to designate a data protection officer?
The assessment is the artefact, whatever it concludes. An organisation that has concluded no duty applies meets this question if the conclusion, the criteria tested and the date are written down. Q2 covers the appointment where the duty does apply.
How is the DPO role structured within your organisation?
The DPO must not hold a role that creates a conflict of interest (e.g. CISO, legal counsel for processing decisions, or head of marketing). An external DPO is permitted under GDPR provided independence and access requirements are met.
Does every personal data processing activity in your organisation have a documented lawful basis under GDPR Article 6 (or Article 9 for special categories) recorded in the data inventory or RoPA?
The legal basis must be specific to each processing purpose and disclosed in the privacy notice. Processing without a valid, documented legal basis is unlawful regardless of the technical security measures in place.
Which of the following does your record of lawful bases do?
Options run from the most commonly in place to the least. Every basis in Article 6 is a valid answer, so the question is not which ones are used but whether each one is recorded, disclosed and supported. A basis recorded against a system rather than a purpose cannot be shown to fit the processing it covers.
Does your organisation have a process to keep the personal data it holds accurate?
Users should be able to update their own core personal data fields (name, email, contact details) directly in the product without requiring a formal request. Corrections should propagate to all systems holding the inaccurate record.
How are inaccurate personal data records identified and corrected?
Self-service correction capability alongside a formal rectification request process provides the strongest coverage. Corrections must propagate to all systems (primary database, downstream systems, backups where applicable) to be effective.
Can a customer supply and hold the encryption key that protects its own tenant data?
Answer yes only where the key material sits under the customer's control and the customer can withdraw the service's use of it without the provider acting. A provider-held key that is dedicated to one tenant is not a customer-managed key; that is DAT-005.
Which of the following does the key ownership statement give to customers?
A customer reads the statement before deciding whether to use its own key, so each element is tested against the live key configuration rather than against the sales material. Publishing it in a trust centre or annexing it to the data processing agreement both count.
How is the effect of withdrawing a customer key verified?
Options run from strongest to weakest. The test that matters is whether the service loses access within the period the statement gives, including access through caches and read replicas. A capability that has never been exercised is an assertion, not a control.
Is there a current record of the countries and cloud regions in which customer data is stored, processed and backed up?
The record has to cover processing and backup as well as primary storage, since those are the locations that surprise buyers. A sub-processor list without locations does not answer this question.
Which of the following does the location record cover?
Support tooling and analytics are the usual source of a location the record misses, because data is read from a region it is not stored in. The operating, support and engineering countries are a second set again: they answer where the people and the pipelines are, not where the bytes are. Jurisdiction is a legal answer and can differ from every geographic answer above it. Published means readable without an account, not supplied on request.
How is the permitted set of regions enforced?
Options run from strongest to weakest. Preventive enforcement at the account or organisation level is the difference between a location record that describes the estate and one that constrains it.
Can a customer retrieve the data it holds in the service through a documented interface or API?
A support ticket that produces a manual database dump is not a documented interface. Answer yes where the customer can start and complete the retrieval itself against published documentation.
Which of the following does the export documentation state?
Count only what the published documentation states. The termination window and the deletion point are the two a customer needs before it signs and the two most often missing. A conformance claim counts where it names a specification a second system could be built against, not where it names a file type. The last item is the one an export API cannot answer for itself: insolvency, resolution and discontinuation all remove the interface the other items describe.
In what form is customer data exported?
Options run from strongest to weakest. Commonly used means a format another system can read without bespoke work, such as CSV, JSON or a documented archive of those. A PDF of the same content is not portable.
Is every processing activity screened for special category personal data?
Every activity means human resources, recruitment, support and marketing as well as the product. Answer no if screening has been done for the product only.
Which of the following are recorded against an activity that involves special category or criminal conviction data?
The screening result is recorded whether it is positive or negative, so that an unscreened activity is distinguishable from a clean one. Conviction data is treated separately from the Article 9 categories because a different test applies to it.
When is an activity screened?
Options run from strongest to weakest. The change trigger is what catches the new free-text field or the new data source that turns a screened-clean activity into a flagged one.
Is there a register of decisions taken solely by automated processing that produce a legal or similarly significant effect on an individual?
Solely automated means no meaningful human involvement in the decision itself; a person who rubber-stamps an output does not change the answer. Answer no if such decisions are made but are not listed anywhere.
Which of the following are available to an individual subject to such a decision?
Available means reachable by the individual from the decision, not obtainable by writing to a privacy mailbox and waiting. The explanation is of the logic and its consequences, not of the model architecture.
How is the condition that permits each automated decision recorded?
Options run from strongest to weakest. The condition is explicit consent, necessity for a contract or authorisation in law. A general lawful basis for the product is not the same thing and will not carry the decision.
Is a switching record kept for every customer that leaves the service?
One record per departing customer, whether it moved to another provider, moved to its own infrastructure or asked for erasure. A closed support ticket counts only where it holds the elements the control lists.
What does the switching record capture?
Answer on the records for customers that have actually left. An element the runbook says will be captured but that no record holds does not count.
How is the transition runbook exercised?
Options run from the strongest exercise to the weakest. The first two differ in the scenario, not in the discipline: a scenario the organisation runs while it is still operating cannot test the handover a successor would receive if it were not.
Can a customer on the lowest paid or self-service plan retrieve its data through the same interface as a customer on the highest plan?
The question is about entitlement, not about rate limits applied equally to every plan. An interface reachable only after a support request, a partner agreement or an upgrade is a no.
Which of the following does the organisation supply to a customer moving to another service?
Tick an item only where a customer can obtain it without a negotiation. Documentation of behaviour beyond the data model means defaults, limits, scheduling and what each setting does, not the schema.
What do the documented export formats state about interoperability specifications?
Options run from the most complete statement to the least, with the last reserved for a service type no specification covers yet. Where no specification exists, the last option is the accurate answer rather than the third.
Does your organisation have a documented information security policy that has been approved by senior management?
The policy should carry a named approver (e.g. CISO or CEO), an approval date within the last 12 months, and a defined scope statement.
How frequently is your information security policy formally reviewed and re-approved?
ISO 27001 and SOC 2 expect at minimum an annual review. Look for a review record (meeting minutes or a workflow ticket) dated within the required interval.
Are information security roles and responsibilities formally documented and assigned to named individuals or functions?
Look for a roles-and-responsibilities document or RACI that names a security programme owner and assigns asset ownership for critical information assets.
Which of the following security ownership roles are formally defined and filled in your organisation?
At a minimum, a named security programme owner and asset owners for critical systems should be documented and verifiable against the org chart.
Is your information security programme sponsored by a named executive who is accountable for its direction and resources?
The sponsor should be a C-level executive or equivalent who is named in the security programme documents and receives regular programme status updates.
How frequently does senior management formally review the status of the information security programme?
Management review meetings should produce documented minutes with security agenda items, attendance records, and action items. Annual is the typical minimum.
Does a board or an equivalent body independent of management review the information security programme at a defined interval?
Independence means the body sits outside the management line that runs the programme. Where there is no board, the equivalent body is the group holding the owners' interest, such as an investor committee or an audit committee. Minutes recording what was reviewed and decided are the evidence; an agenda listing the item is not.
Does a documented information security programme plan exist?
The programme plan should be a living document approved by management, listing all security domains in scope and referencing budget or headcount allocation.
How is progress against the information security programme plan reported to management?
A documented status report (quarterly or annually) addressed to or acknowledged by a named executive is the expected evidence.
Which of the following does the information security programme plan define?
Options run from the most commonly defined to the least. Resource allocation is the limb most often absent. A plan with objectives and no resources behind them is a statement of intent.
Does your organisation conduct formal information security risk assessments on a defined schedule?
A risk assessment should document threats, vulnerabilities, likelihood, impact, current controls, and treatment decisions, produced by a named assessor.
How often is a full information security risk assessment conducted?
Most frameworks require annual assessment at minimum, plus ad hoc assessment on significant system or business changes.
Which of the following does your risk register record for each identified risk?
Options run from the most commonly held to the least. A register carrying ratings but no owner cannot be worked. One carrying no review date cannot be shown to reflect the risks as they stand rather than as they stood at the last assessment.
Does your organisation have a formal enterprise risk management programme?
The ERM programme should be governed by an approved policy that states risk appetite, assigns ownership of risks to named roles, and defines the review cadence.
How are risk acceptance decisions documented and authorised in your organisation?
Each accepted risk should have a signed or digitally approved acceptance record that names the approver and states the rationale and review date.
Which of the following does the risk management programme document?
Options run from the most commonly documented to the least. Without a stated tolerance, treatment decisions cannot be tested against anything and two people assessing the same risk reach different answers.
Does your organisation maintain a tracked plan of action for open risk findings and control deficiencies?
This may be a plan of action and milestones (POA&M), a remediation tracker, or equivalent. Findings from risk assessments and audits should appear in it with current status.
How often is remediation progress against open risk findings reported to management?
Regular management-level reporting (monthly or quarterly) with aging, closure rates, and overdue items is the expected practice.
What does each entry in the remediation tracker record?
Options run from the most commonly held to the least. An entry with no target date cannot age. A tracker where nothing ages reports the same picture every period.
Does a documented fraud risk assessment exist?
A fraud risk assessment should document insider threat and access-misuse scenarios with likelihood and impact ratings and link findings to detective and preventive controls.
Which of the following controls has your organisation implemented in direct response to identified fraud risk?
The link between the fraud risk assessment findings and the controls designed in response should be documented.
Which of the following does the fraud risk assessment record?
Options run from the most commonly recorded to the least. Insider scenarios are the ones a fraud assessment written from a financial-controls template tends to miss, because the loss path runs through system access rather than through a payment.
Has your organisation recorded the conflicting role combinations that must not be held by one account?
A segregation of duties (SoD) matrix or conflict register should list role pairs that must not be combined, with compensating controls for any necessary exceptions.
How does your organisation verify that SoD conflicts are not present in the live IAM environment?
An IAM export cross-referenced against the SoD conflict matrix, showing no user holds both sides of a conflict, is the expected evidence.
Where full separation of a conflicting pair is not feasible, is a compensating control documented for it?
Answer yes only where each conflict left in place carries a named compensating control and the person who accepted it. A small organisation will have such pairs; what fails the control is leaving them unrecorded.
Does your organisation maintain an inventory of applicable legal, regulatory and contractual information security obligations?
The inventory should cover obligations across all operating jurisdictions and be reviewed at least annually, with additions made when new contracts or regulations apply.
How frequently is the compliance obligations inventory reviewed and updated?
An annual review that produces a dated record with a named reviewer is the minimum. Updates should be visible whenever new obligations arise mid-year.
What does each entry in the obligations inventory record?
Options run from the most commonly recorded to the least. The date an obligation was added is what makes an obligation that arose mid-cycle visible without waiting for the next review. The last item is the one an inventory built from a jurisdictional analysis never returns, because the duty exists in a signed schedule rather than in a law that binds the organisation directly.
Does your organisation conduct internal audits or compliance checks of information security controls at a defined interval?
An internal audit report should state scope, list findings by severity, include a management response with owners and target dates, and be produced by someone independent of the function audited.
How frequently does your organisation conduct information security internal audits?
Most frameworks expect at least annual internal audit activity. Findings should feed directly into the remediation tracker.
Which of the following does each internal audit or compliance check report carry?
Options run from the most commonly present to the least. A report with findings and no management response records an opinion rather than a commitment. Findings with no register behind them close by being forgotten.
Does your organisation have a documented continuous monitoring strategy?
The strategy should be documented, management-approved, and reference how monitoring outputs feed into risk register updates, not rely solely on annual audits.
Which of the following continuous monitoring activities are currently operational in your organisation?
Evidence should show monitoring outputs (dashboards, scan reports, alert logs) generated at the frequencies defined in the strategy.
Which of the following does the continuous monitoring strategy record?
Options run from the most commonly recorded to the least. Monitoring that produces output nobody is named to read is the common failure. A deviation with no link onward to a risk entry leaves the strategy reporting problems it never resolves.
Does your organisation have a formal process for requesting, approving, and tracking exceptions to information security policies?
The process should require a business justification, named approver, risk acceptance rationale, and a defined maximum exception duration.
How are active policy exceptions tracked and managed?
An exception register should show that no exceptions are past their expiry date without renewal or remediation, and that each carries a named approver.
Which of the following does each determination against an external requirement record?
This covers a regime that permits an alternative measure, not a requirement the organisation has failed to meet: an unmet requirement is a finding, not a determination. The assessment is the item most often thin, because restating the requirement is easier than saying what about this environment makes the named measure unreasonable. A determination that only expires on a date behaves like a policy exception and gets renewed rather than re-assessed.
Does your organisation maintain a documented inventory of information assets and processing systems, with designated owners for each asset?
The inventory should include all production systems and critical data stores, show a named owner per asset, and have a last-reviewed date within the defined interval.
How does your organisation keep the asset inventory current as assets are added, modified, or decommissioned?
An automated discovery cross-reference or change-management trigger is the most reliable control. The inventory should match live cloud infrastructure within 30 days.
Does each asset in your inventory carry a criticality rating derived from the services that depend on it?
Ownership says who decides about an asset; criticality says how much is lost if it fails. Recovery prioritisation, assurance depth and incident triage all need the second and none of them can derive it from an owner name. Answer yes only where every asset carries a rating, not only the ones someone thought to rate.
Does your organisation maintain an inventory of the licensed software in use?
The inventory should show that usage does not exceed entitlement and that no licences are operating past expiry.
Which of the following does the software licence inventory record for each licensed product?
Options run from the most commonly recorded to the least. An inventory holding entitlements but no usage count cannot show that use stays within them, which is the condition the control tests.
Does a documented procedure define how licensing non-compliance is identified and remediated?
The procedure should name the prohibited actions, the route by which a violation is flagged and the remediation expected. An acknowledgement requirement on personnel belongs with it.
Does your organisation have a documented records retention schedule?
The schedule should cover audit logs, contracts, incident records, and training records at minimum, with specific retention periods aligned to legal and regulatory obligations.
How are retention policies enforced for your primary storage and logging systems?
Automated retention configuration (e.g. S3 lifecycle policies, Google Vault rules) aligned to the retention schedule is the strongest evidence. Immutability should be enabled for audit logs.
Which of the following does the retention schedule define for each category of compliance-relevant record?
Options run from the most commonly defined to the least. A period with no obligation behind it cannot be defended when it is challenged. A schedule with no destruction method leaves records alive past the period it sets. The last item is the one that changes the answer most: an obligation running from the date a document last was in effect keeps a long-lived policy for years past the period its number suggests.
Does your organisation have a defined threat intelligence programme that collects, analyses, and disseminates threat intelligence to relevant internal stakeholders?
The programme should produce documented intelligence outputs (reports or briefings) on a defined cadence, referencing at least two sources and showing distribution to security, engineering, or risk stakeholders.
How does your organisation act on threat intelligence findings to update risk posture or controls?
A traceable link between an intelligence finding and a risk register entry or change ticket is the expected evidence, demonstrating closed-loop action.
Which external threat intelligence and special interest group relationships does your organisation actively maintain?
Active membership or subscription, not registration alone, with a named internal owner. Regulatory authority and law enforcement contacts are INC-010.
Does your organisation have a documented process for integrating information security requirements throughout the project lifecycle, including mandatory security reviews before go-live?
The process should define required security activities per project phase and require that findings are resolved or risk-accepted before deployment.
At which stages of a project are security activities formally required?
Pre-launch security sign-off is the minimum. Look for completed review checklists with a named security reviewer and documented disposition of findings.
Does your organisation undergo independent security assessments (internal audit teams independent of the security function, or external third-party assessors) at defined intervals?
The assessor must be independent of the function being assessed. Reports should be dated within the defined interval and addressed to management.
What form does your most recent independent security assessment take?
A SOC 2 Type II report or ISO 27001 audit provides the strongest third-party assurance for enterprise customers. All options above should include a management response to findings.
Does your organisation have a documented audit and assurance policy?
The policy should explicitly state that auditors cannot audit their own function, define the reporting line (e.g. to CISO or Audit Committee), and be approved within the last 12 months.
Which of the following does the audit and assurance policy define?
Options run from the most commonly defined to the least. Independence is the limb that decides what the audit is worth: a policy that lets a function audit itself produces a report nobody outside the organisation can rely on.
Does your organisation have a documented data protection policy approved by management?
The policy should cover lawful basis for processing, data subject rights, breach notification, and applicable regulations (e.g. GDPR, CCPA), and be approved within the last 12 months.
Which of the following does your privacy programme maintain?
Options run from the most commonly held to the least. A policy on its own is not a programme. The records of processing and the breach notification procedure are the two operational artefacts an assessor asks for first.
Is a security metrics report produced at a defined cadence?
Metrics should be compared against defined targets and show trend data. Reports should be addressed to or acknowledged by a named executive or security committee.
Which of the following security metrics does your organisation actively track and report?
A good metrics programme covers at least training completion, vulnerability remediation SLA, and incident rates, with results compared to defined targets each reporting period.
Which of the following does the security metrics report carry?
Options run from the most commonly present to the least. A value with no target is a number. A report with no named recipient has no reader accountable for acting on it.
Are operating procedures documented for the critical information processing activities?
Each procedure should carry a version number, a named owner, and a last-reviewed date within the defined interval (typically 12 months).
Which of the following critical process areas have documented operating procedures that are actively maintained?
Select all that apply and be prepared to provide the procedure documents with version history. Fewer than three covered areas would be considered a material gap.
Which of the following apply to your documented operating procedures?
Options run from the most commonly in place to the least. A procedure nobody can reach at the moment they need it is not available, whatever the document management system says about permissions.
Is a named role accountable for requests from the authorities that supervise the organisation's customers?
Answer for the authority that supervises a customer, not for the organisation's own regulator and not for a law enforcement demand, which is the vendor data request control. A role named in a procedure nobody has routed a request through is still a yes; a request handled ad hoc by whoever received it is a no.
Which of the following does the procedure cover?
Options follow the order a request moves through, from arrival to the record left behind. The last item is the one most often missing: a contract that grants access and an operating practice that makes it impossible are a common pairing, and only a review that reads both together finds it.
What access to premises is committed to an authority supervising a customer?
Options run from the widest commitment to the narrowest. Answer on what the published terms actually commit, not on what would probably be agreed. A commitment that stops at the organisation's own sites is the second option even where every site it operates is covered.
Does your organisation have a documented personnel security policy?
The policy should span the full employment lifecycle, from background screening before hire through to offboarding obligations, and be approved and communicated to all staff.
How do you confirm all personnel have received and acknowledged the personnel security policy?
An acknowledgement export showing all active employees with a recorded acknowledgement date at or before their first day of system access is the expected evidence.
Which of the following does the personnel security policy cover?
Options run from the most commonly covered to the least. A policy covering hiring and nothing else leaves the two points of highest risk, role change and departure, without a stated obligation.
Does your organisation conduct background screening on all candidates before system access is granted, proportional to the sensitivity of the role?
Screening should be completed before access is provisioned. The scope of the check should match the role risk band the screening standard defines, covering identity, employment history and any criminal record check the band requires.
Which of the following personnel categories are subject to pre-employment background screening in your organisation?
ISO 27001 and most enterprise customer requirements expect screening for contractors and third parties with privileged access, not just direct employees.
Which of the following does your screening and identity proofing record hold for each person, dated before their first system access?
Options run from the most commonly held to the least. Every element has to be dated before the individual's first system access, which is the part that most often fails under hiring pressure. Screening and proofing answer different questions: screening asks what is known about this person, proofing asks whether the person in front of you is that person.
Do your employment agreements state explicit information security obligations?
Obligations should be stated in the agreement itself, not just referenced by pointer. Signed copies should be on file and the agreement should be signed before or on the first day of employment.
When security obligations in employment agreements change materially, how does your organisation ensure affected personnel acknowledge the updated terms?
A change notification record and re-acknowledgement log showing all affected employees confirmed updated terms within a defined period is the expected evidence.
Which of the following do your employment agreements contain?
Options run from the most commonly present to the least. An agreement that points at a policy the person has never read transfers no obligation they can be held to.
Do all personnel complete a security awareness training programme at onboarding and at defined intervals thereafter?
Training records from the LMS or awareness platform should show completion rates at or above the defined target (typically 95%+), with new hires completing within 30 days of their start date.
Which of the following topics are included in your annual security awareness training curriculum?
Options run from the most commonly covered to the least. Phishing awareness, acceptable use, incident reporting and privacy obligations are the minimum. Insider threat indicators are behavioural, not technical. The colleagues best placed to notice them are not on the security team, and the reporting route is usually not the one used for a suspicious email, so the topic has to be taught.
Does your organisation evaluate the effectiveness of its security awareness programme (e.g. through phishing simulations, quiz scores, or click rate trends)?
Phishing simulation results showing click rate trends over the year, with curriculum changes triggered by high-risk cohorts, demonstrate programme effectiveness.
Do personnel in elevated-privilege or security-critical roles (e.g. sysadmins, developers, incident responders) receive role-specific security training before gaining production access and at defined intervals thereafter?
Role-based training records should show completion before or within 30 days of production access being granted, with annual renewal records on file.
Which of the following role-specific security training tracks does your organisation deliver?
At least three distinct role tracks covering different privilege tiers are expected. Training is matched to the systems and data each role can reach. The management body track is the one most often absent, because the programme is usually built around who holds production access and the board holds none.
How is the effect of role-based training measured?
Options run from strongest to weakest. A test at the end of a module measures recall of the module, not competence in the role, which is why it sits below an assessment against the standard. Answer on what happened at the last delivery rather than on what the procedure describes.
Does your organisation have a documented disciplinary process covering information security policy violations?
The process should define tiered consequences proportionate to severity, require investigation before sanctions are applied, and include an appeal mechanism.
Which of the following apply to your disciplinary process for security violations?
Options run from the most commonly in place to the least. Answer on the process as written and operated, not on whether evidence of a past case could be produced. A process that has never been invoked can still meet every item here.
Are all logical access rights revoked within a defined timeframe on termination or role change?
Completed offboarding checklists should show access revocation dates and confirm the SLA was met (typically same-day for involuntary terminations).
What is your defined maximum timeframe for revoking all logical access after an involuntary termination?
Same-day revocation for involuntary terminations is the expected standard. IAM export cross-referenced against the HR termination log is the verification evidence.
Which of the following does your offboarding process cover?
Options run from the most commonly covered to the least. Contractor access is the gap that outlives the engagement, because the trigger for offboarding sits with the engaging team rather than with human resources. The last item runs on its own trigger and does not wait for a termination.
Does your organisation have documented security requirements for remote working?
The policy should specify MDM enrolment or equivalent device controls, VPN or zero-trust network access requirements, and a process for reporting lost or stolen devices.
How are remote working security requirements communicated to and acknowledged by remote workers?
All employees with a remote or hybrid arrangement should have a current acknowledgement on file, pre-dating or concurrent with the start of their remote working arrangement.
Which of the following do the remote working requirements cover?
Options run from the most commonly covered to the least. The lost device route is the one people need at the worst moment and the one most often missing from a policy written around network access.
Do all personnel have access to a documented mechanism for reporting observed or suspected security events?
At least two reporting channels should be defined (e.g. email alias, Slack channel, ticketing form) and included in security awareness training. A non-retaliation statement should be present.
How frequently are the security event reporting channels tested to confirm they are operational?
Channel testing (e.g. a test submission verified to have been received and acknowledged) should produce a dated test record. Reports received via the channel should be acknowledged within a defined SLA.
Which of the following apply to your security event reporting channels?
Options run from the most commonly in place to the least. An unacknowledged report teaches the reporter not to send the next one, which is the failure mode the control exists to prevent. The external item asks about a suspicious event rather than a vulnerability report, which is a narrower channel held elsewhere. The last two items are the whistleblower case: a report about the organisation itself rather than about a security event, plus the protection that lets a person make it.
Are information security responsibilities defined for every position?
Job descriptions or role definition documents should include a security responsibilities section covering systems in scope, data access entitlements, and asset accountability for elevated-access roles.
Which of the following does your role definition process do?
Options run from the most commonly in place to the least. A role definition written once at hiring and never revisited describes the job somebody used to do. The last item is what turns the definition into an obligation the person knows they hold.
Are the acceptable use rules acknowledged by each person before access to organisational systems is granted?
The acknowledgement before access is what makes the rules enforceable later. Rules published on an intranet with no record of who has read them do not meet the control; Q2 captures how the acknowledgement is recorded.
How is acknowledgement of the acceptable use policy captured and tracked for all personnel?
A digital acknowledgement export showing 100% (or near-100%) completion for all active staff, with acknowledgement dates, is the standard evidence.
Which of the following does your acceptable use policy address?
The last five items are the ones most often missing from a policy written for a single office and a managed laptop. The external systems item is the one that governs contractor and bring-your-own-device working; the control also asks for a recorded verification of that system's controls or an approved connection or processing agreement for each such use.
Does your organisation have a documented insider threat programme with a named owner?
The procedure is the artefact and the owner is the part most often missing. A collection of detection tooling with no procedure, no escalation path and nobody accountable for the programme does not meet the control; Q2 captures which capabilities are in place.
Which of the following insider threat capabilities are in place?
A detection capability without the escalation path and the investigation procedure produces alerts nobody can act on. The last item is what decides whether the evidence gathered survives a disciplinary or legal process.
Is there a training standard that names the groups of people who operate, build, procure or decide with AI systems?
Answer yes only where the standard distinguishes groups and sets different content for them. A single all-staff AI module, or an AI slide inside general security awareness training, is a no here.
Which of the following does your AI training cover?
The first four items apply to every group; the next two apply only to people assigned oversight of a specific system. Tick an item only where it is in the delivered content, not only in the standard.
Who does the AI training reach?
Options run from the widest reach with the strongest record to the narrowest. Contractors here means anyone operating or using AI systems on your behalf, including agency staff and outsourced operations teams.
Does your organisation have a documented access control policy that defines rules for granting, reviewing, and revoking access?
The policy should be version-controlled, have a named owner, and include explicit least-privilege and need-to-know requirements. An undocumented or informal approach does not satisfy this control.
How frequently is the access control policy reviewed and re-approved?
Annual review is the minimum acceptable cadence. The policy must be re-approved by a named owner after each review.
Is a centralised inventory of all identities, including human users, service accounts, and other non-human identities, maintained?
The inventory should be sourced from the IdP or IAM platform (e.g. Okta, Azure AD, AWS IAM), not maintained only in a spreadsheet. It must include both human and non-human identities.
Are shared or generic accounts in use in any of your production systems?
Shared accounts undermine audit trail integrity. Any active shared accounts must have a documented justification and a named individual accountable for activity on that account.
Where a shared account is permitted, does each user authenticate as themselves before being given access to it?
Answer yes only where the individual authentication is enforced by a broker, a privileged access tool or a jump host rather than being a convention. Without it, the justification records why the shared account exists and the log still cannot say who used it. Answer yes as well if no shared accounts are permitted at all.
Are formal, documented processes in place for provisioning and deprovisioning user accounts, including required approvals before access is granted?
Provisioning should require at minimum one named approver distinct from the requester. Approvals must be recorded in a ticketing or workflow system.
When an employee leaves or changes role, within what timeframe are their accounts disabled or access updated?
Same-day or next-business-day deprovisioning is best practice. Delays beyond 3 days create significant orphaned-access risk. The timeframe should be defined in policy and verifiable from logs.
Which of the following are managed through your central identity provider?
Options run from the most commonly covered to the least. An identity that lives outside the identity provider without being a recorded exception is invisible to joiner and leaver processing. Usage conditions set only in an access request cannot deny a login, which is why the question asks where they are set rather than whether they are agreed.
Are access rights for all users formally reviewed and revalidated on a defined periodic schedule?
Reviews must be documented, include a named reviewer per access entry, and result in revocation of any access no longer required. Ad hoc or informal reviews do not satisfy this control.
How frequently are access reviews (recertification campaigns) conducted?
Annual is the minimum; more frequent reviews are expected for privileged accounts and sensitive systems. Reviews should be triggered in addition to scheduled cycles when users change roles.
Is the principle of least privilege enforced so that users and services are granted only the minimum access needed for their current function?
Enforcement requires that roles are scoped tightly and that access is actively reviewed when responsibilities change, not merely that a policy document states the principle.
How is least-privilege enforcement implemented in your environment?
Multiple mechanisms in combination indicate a mature least-privilege posture. Relying solely on a written policy without technical enforcement is insufficient.
Is an inventory of all privileged accounts maintained?
Every privileged account must map to a named individual with a documented business justification. Shared admin accounts are not acceptable.
Which controls are applied specifically to privileged accounts in your environment?
Options run from the most commonly held to the least. MFA and full action logging are the minimum. A separate account for administration is a different thing from segregating the roles: one person can hold both roles on one account and satisfy segregation on paper. Session recording with a behavioural review answers what the action log cannot, which is whether a legitimate action was part of a pattern that was not. Utility and break-glass tooling is the gap most often missed: a tool that bypasses application logic leaves an application audit trail that looks normal. Product names belong in an implementation note, not here.
Is MFA enforced for all user access to externally-facing systems, administrative interfaces, and systems holding sensitive or regulated data?
MFA must be enforced at the system or IdP level, not left to user discretion. Enforcement means no in-scope access path can be completed with a password alone.
Which of the following are true of the multi-factor authentication enforced on in-scope systems?
The control constrains the properties of the mechanism, not the product. Phishing-resistant methods such as a hardware security key are stronger than a one-time code sent over a message channel. That choice belongs in the implementation note rather than here. The third item is the one that fails in practice: a legacy client or a recovery route that still accepts a password alone.
Which conditions trigger a supplemental authentication challenge on your systems?
Options run from the most commonly configured to the least. The conditions should be written down rather than left to a vendor default, because the default set is what an attacker can look up. Elevation and sensitive-operation triggers are the two most often absent.
Is a documented credential management policy enforced at system level?
The policy must be enforced at the system level, not just documented. Key settings to confirm: minimum length ≥12 characters, reuse prohibition, and approved hashing/storage for secrets.
How are API keys, tokens, and service credentials stored?
A dedicated secrets vault with access control and audit logging is the expected approach. Credentials committed to version control, even encrypted, represent a significant risk. Plaintext storage in version control is a critical finding.
Is there a maintained list of the external authenticators your service accepts, with the assurance level each is accepted at?
External authenticators are the sign-ins your organisation does not issue: a customer or partner identity provider, a social login, a federated enterprise directory. Answer yes only where the list exists, each entry states an assurance level, and an authenticator outside the list is actually refused by the service rather than merely undocumented.
Are service accounts, API keys and other non-human identities recorded in an inventory?
Every non-human identity should have a named team or individual as owner. Unowned or undocumented service accounts are a significant risk. The inventory must be kept current, not just created once.
How frequently are API keys and service account credentials rotated?
Automated rotation is strongly preferred. Long-lived, non-rotating credentials significantly increase the impact of a credential exposure. Rotation should also occur immediately upon any suspected compromise.
What does each non-human identity entry record?
Options run from the most commonly recorded to the least. An unowned service account is the one nobody revokes. A shared one turns every compromise into a compromise of every service that uses it.
Is remote access to internal systems and infrastructure limited to approved, documented access paths (e.g. VPN or zero-trust network access)?
Direct SSH, RDP, or API access from the internet to internal resources without a sanctioned gateway should be blocked. All remote access paths must be reviewed and reauthorised periodically.
What remote access technology is in use for accessing internal systems?
Options run from the strongest path to the weakest. An identity-aware proxy decides each connection on its own terms, so one stolen credential does not open the internal network the way a tunnel credential does; Cloudflare Access, Zscaler Private Access and BeyondCorp are examples of the category. A tunnel with multi-factor authentication is the floor this control expects. An internal system reachable directly from the public internet is a critical finding. Record the capability in use rather than the product name.
Are session management controls enforced at system level?
Controls must be enforced at the system level, not left to the end user to configure. Session identifiers must not appear in URLs and must be invalidated upon logout.
What is the maximum idle session timeout configured for users accessing production systems?
Options run from strongest to weakest. Fifteen to thirty minutes is the expected range for production and administrative systems. A timeout above 60 minutes, or none at all, is a finding wherever the session reaches sensitive data.
Which session management controls are enforced on production systems?
Options run from the most commonly enforced to the least. An idle timeout with no absolute lifetime behind it leaves a session that is kept alive by activity running indefinitely.
Are authentication systems configured to lock out or rate-limit accounts after a defined number of consecutive failed login attempts?
The mechanism must be enforced at the system level. The lockout threshold, duration, and recovery process should be defined in policy and verifiable in system configuration.
What mechanism is used to respond to repeated failed authentication attempts?
At least one technical mechanism should be in place at the system or gateway level. Layering multiple mechanisms (e.g. lockout plus IP rate-limiting plus alerting) provides stronger defence against credential stuffing.
Is access to source code repositories, build pipelines and deployment tooling restricted to authorised personnel?
Access to production branches should be restricted with branch protection rules. Write or admin access must require explicit approval and be regularly reviewed.
Which controls are enforced on your production or main branch in source control?
Disabling direct push and requiring at least one reviewer are baseline expectations. Locking branch protection to prevent admin override is a strong additional control.
Is access to systems and data assigned through defined roles rather than granted directly to individual users?
Role-based assignment must be the default. Direct individual-level grants should be exceptions with documented justification, not the norm.
Which of the following describe your role-based access model?
Direct grants to individual accounts are exceptions, not the norm; each one needs a recorded justification and expiry date. The role catalogue export is the evidence.
Are the systems from which administrative access to production is exercised recorded in an inventory?
Answer against the machines, not the accounts. A list of privileged users is the privileged access control. A convention that administrators use a particular laptop, with nothing recording which laptops those are, is a no.
Which of the following apply to a designated administration system?
Options run from the cheapest to hold to the most demanding. The scope is what makes single-purpose testable: without it, nothing says which software counts as outside the purpose. The last item is the one most often overlooked, because a security administration console tends to be treated as a security tool rather than as an administration system.
How is administrative access attempted from a system outside the designated set handled?
Options run from strongest to weakest. Answer on what the enforcement point actually did the last time it happened, or on the result of a test if it has not happened. A policy that forbids it with nothing enforcing or watching is the third option.
Does your organisation have a documented incident response plan?
The IRP should be approved by the CISO or equivalent senior owner, version-controlled, and updated following significant incidents. A plan that has not been reviewed in over 12 months is considered stale.
Which functions are explicitly covered in your Incident Response Plan?
All six are expected in a mature IRP. Missing legal or regulatory escalation paths are a common gap that creates exposure during actual incidents.
Which of the following does your incident tooling do?
Options run from the most commonly in place to the least. Independence from the estate under investigation decides whether the tooling is available in the incident it was bought for, and it is the item most often taken for granted.
Are processes and technical controls in place to detect potential security incidents?
Detection capability should not rely solely on automated alerting. Internal reporting channels and mechanisms to receive third-party notifications are also required.
Which incident detection sources are covered by your triage process?
Automated alerts alone are insufficient. A robust detection process includes internal reporting channels and the ability to receive and triage external notifications.
Are incidents classified by severity and type using a defined taxonomy?
The classification matrix should explicitly include criteria for identifying a personal data breach (triggering GDPR notification obligations) and should be referenced in all incident triage processes.
How many severity levels are defined in your incident classification taxonomy?
Options run from the most granular taxonomy to the least. The control sets no number of levels. It requires each level to carry distinct criteria with a defined escalation path, a notification requirement and a response service level. The criteria for a personal data breach have to be among them.
Which of the following does the incident classification taxonomy carry?
Internal severity levels are not external thresholds: answer on the regulatory and contractual triggers, not on the priority scale. The population item is the one that decides whether the rest is usable, because a threshold set as a percentage of users is unanswerable until the denominator is defined and can be produced. The last two items look backwards across closed incidents and are the part most programmes have never built.
Do documented containment procedures exist for common incident types?
Containment procedures should be specific and actionable, not generic guidance. At minimum, runbooks should exist for account compromise, malware, and data exfiltration incident types.
Which incident types have documented containment and eradication runbooks?
Options run from the most commonly documented to the least. Account compromise, malware and exfiltration are the minimum. Spillage is handled badly by a generic exfiltration playbook: the data is inside the organisation and in the wrong place, the recipients are colleagues rather than attackers, and alerting through the contaminated channel copies the spill to everyone reading it. AI-specific runbooks are expected where AI systems run in production.
Are internal incident reporting requirements and timelines defined for every severity level?
The breach notification procedure must explicitly state the 72-hour GDPR Art.33 obligation and include GDPR Art.33(3) content requirements as a checklist. The procedure should be approved by the DPO or legal team.
Which elements are included in your breach notification procedure?
Options run from the most commonly present to the least. A missing content checklist and an undefined trigger for notifying individuals are the usual gaps. Supply chain notification is the direction most often missed: organisations notify upwards to regulators and outwards to customers while the supplier whose component was involved hears nothing. The last two items are what make the procedure survive a second regime: one named clock inside an incident response plan is not a register, and a deadline cannot be tested against an awareness time nobody wrote down.
What does your internal breach register capture for each personal data incident?
A complete breach register is required for GDPR accountability. All incidents should be logged regardless of notification threshold. The register must capture the notification decision with documented justification.
Does your organisation have a documented process for notifying affected customers of security incidents?
Customer notification timelines are often defined in enterprise contracts at shorter intervals than regulatory requirements. The procedure should reference contractual obligations and include approved communication templates.
What is the standard customer notification timeline for a confirmed high-severity security incident affecting customer data?
Many enterprise contracts specify 24–72 hour notification timelines. A defined standard timeline shorter than or equal to the contractual obligation is the expected answer.
Which of the following does the customer communication process cover?
Options follow the process from the trigger to the help offered afterwards. Tick an item only where the process states it; a practice followed by the incident team but written down nowhere does not count here. The last two are the ones a customer in a regulated sector asks about first, because its own regulator gives it a clock it cannot meet without facts the provider holds.
Are there documented procedures for identifying, collecting and preserving digital evidence from security incidents?
Evidence collection procedures should specify approved tools, chain of custody requirements, storage location, access controls, and retention period aligned to legal and regulatory requirements.
Which elements are included in your evidence collection and preservation procedure?
Chain of custody and secure storage are the minimum requirements. Cloud-based evidence collection procedures are essential where the service runs on cloud infrastructure.
Is a post-incident review conducted after every significant incident?
Post-incident reviews should be conducted within a defined timeframe after the incident is closed (e.g. within 5 business days for high-severity incidents). Corrective actions must be assigned to named owners with due dates.
What is the defined timeframe for completing a post-incident review following a high-severity security incident?
5 business days is a widely accepted target for high-severity incidents. Reviews conducted more than 30 days after closure risk losing context and reducing the quality of root cause analysis.
Which of the following does the post-incident review process produce?
Options run from the most commonly produced to the least. A review that names a cause and changes nothing is a record of the incident rather than a control, which is what the fifth item separates. The last item is not produced by any one review: it reads the incident register against the review set and is what catches the process lapsing under load.
Do personnel with incident response roles receive training at onboarding and at a defined interval thereafter?
Training completion should be tracked in an LMS or equivalent system. Exercise results should be used to update IRP procedures. A plan that generates no updates after an exercise likely was not tested meaningfully.
How frequently is incident response training conducted for personnel with defined IR roles?
At onboarding plus annual refresher training is the minimum expectation. Six-monthly training is considered a strong practice for teams with active response responsibilities.
Which of the following apply to your incident response exercises and training?
Options run from the most commonly in place to the least. Coordinating the exercise tests the seam rather than the plan: a real incident invokes several plans at once and the handover between them is where they come apart. Spillage training reaches a wider group than the response team, because the people who first see spilled information are usually the ones who received it.
Is a contact list maintained for the external parties the incident response team may need to reach?
The contact list must be accessible without requiring access to primary production systems: it should be stored out-of-band (e.g. printed copy, offline document, or separate communications platform).
Which external contact categories are included in your maintained IR contact list?
Supervisory authority, national CERT, cloud provider security contact, and legal counsel are the minimum required categories. Insurance and DFIR retainer contacts are expected for mature IR programmes.
Are all production systems deployed against a documented hardening baseline?
The baseline should reference a named benchmark (e.g. CIS Level 1/2, DISA STIG) and apply to all production workload types, not just servers.
Which approach is used to enforce the hardening baseline and detect deviations?
Automated enforcement at build time combined with runtime drift detection provides the strongest assurance. Periodic scans are a minimum acceptable approach.
Are previous versions of each hardening baseline retained so a system can be returned to an earlier known-good configuration?
Answer yes only where a defined number of complete prior versions is kept and retention is enforced by the repository rather than left to convention. Drift detection tells you the estate no longer matches the baseline; without the prior version there is nothing to return it to.
Is an accurate, maintained inventory of all production system components kept, capturing component type, owner, environment, and version?
The inventory should cover servers, containers, virtual machines, cloud resources, and network devices. Cloud-native discovery tools or a CMDB are the expected mechanisms.
How frequently is the production asset inventory reconciled against actual deployed resources?
Continuous or weekly automated reconciliation is preferred. Quarterly is the minimum acceptable frequency for a controlled environment.
What happens when a component is found in the environment that is not in the inventory?
Options run from the strongest response to the weakest. A detection with nothing bound to it produces a monthly list that nobody is accountable for closing. Automatic isolation suits environments where an unknown component is never legitimate.
Are production systems isolated from development, test and administrative networks at the network layer?
Isolation should be enforced via VPC boundaries, security groups, network ACLs, or equivalent cloud-native controls, not only by naming convention or access policy.
Which mechanisms are used to enforce network segmentation between environments and between tenants?
Multiple enforcement layers are expected for a strong segmentation posture. At minimum, expect separate network boundaries and explicit deny rules for cross-environment traffic.
Is your production network architecture documented?
Documentation should include current data flow diagrams and a network diagram showing trust zones. Defence controls should include at minimum a firewall or WAF and egress filtering.
Which network defence controls are deployed at production network boundaries?
A WAF and egress filtering are baseline expectations at an internet-facing boundary. IDS/IPS and DDoS protection indicate a more mature defence-in-depth posture.
Is outbound web access from production systems and corporate devices filtered to restrict access to malicious or unauthorised external destinations?
Web filtering should block known malicious categories and command-and-control infrastructure. Egress filtering policies should be documented and applied to both production and corporate traffic.
Is authenticated vulnerability scanning of production systems and applications performed at a defined frequency of at least monthly?
The programme should cover both infrastructure and application layers. Scan credentials should be verified. Unauthenticated scans miss a significant portion of findings.
What is the defined SLA for remediating critical severity vulnerabilities (CVSS 9.0 and above) in production systems?
Industry expectation for critical vulnerabilities is 7–14 days. 30 days is the acceptable outer limit only when compensating controls are documented for the gap period.
Which of the following does your vulnerability management programme cover?
Options run from the most commonly covered to the least. Scanning covers the systems you know about; external discovery covers the ones you do not, which is where a forgotten subdomain, a stale cloud account or a credential in a public repository sits. A model artefact is scanned by neither unless it is named: a serialised model is an executable file that most tooling reads as data.
Are security patches applied to production systems within defined timelines based on severity?
A formal patch management policy should define timelines per severity band (critical, high, medium, low) and include an emergency patching process for zero-day or actively exploited vulnerabilities.
What is the defined patching SLA for high severity patches (CVSS 7.0–8.9) in production systems?
30 days is the widely accepted baseline for high severity patches. 14 days is considered strong practice. Anything beyond 30 days requires documented compensating controls.
Which of the following does your patch management process do?
Options run from the most commonly in place to the least. A compensating control with no expiry becomes the permanent answer to a patch nobody applied.
Are managed endpoints and production workloads protected by anti-malware or endpoint detection and response tooling?
EDR deployment should cover all managed endpoints and, where applicable, production compute workloads. Behavioural detection (EDR) is preferred over signature-only anti-malware.
Which endpoint and workload protection tooling is deployed across production systems and managed endpoints?
Options run from the strongest coverage to the weakest. A modern detection and response agent across all managed endpoints plus host-based firewall enforcement is the minimum for a service provider. Email filtering belongs here because it is the route most malicious code arrives by, and its value collapses fastest without current detection content. Name capabilities rather than products when recording what is deployed.
Is current and projected resource utilisation monitored against defined thresholds?
Monitoring should cover all critical resource types. Alerts should fire with enough lead time to allow scaling decisions before service is impacted.
How frequently is capacity planning reviewed to ensure production infrastructure can meet operational demands?
Auto-scaling removes much of the risk but does not eliminate the need for capacity planning at the service limit level. Quarterly reviews are a minimum for services with defined availability SLAs.
Which of the following are monitored against a defined threshold with an alert configured before exhaustion?
Options run from the most commonly monitored to the least. Log storage is the one that fails quietly: the store fills, the oldest events roll off and the retention the organisation believes it holds is gone before anyone looks.
Is production infrastructure deployed with redundancy for the components whose failure would stop the service?
Where the service runs in a cloud region, multi-zone deployment of compute, database and load balancing is the minimum expected redundancy posture.
What level of infrastructure redundancy is implemented for production services?
Multi-AZ within a single region is the baseline expectation. Multi-region is expected where SLAs commit to recovery times that a single-region failure would breach.
Which of the following apply to your availability architecture?
Options run from the most commonly in place to the least. Redundancy that has never been exercised is a design rather than a capability. The failover most likely to fail is the one that has only ever been drawn.
Do all production systems synchronise their clocks from approved, authoritative time sources?
Cloud-native environments should use the cloud provider's time sync service (e.g. Amazon Time Sync Service, Google Time Servers). Drift monitoring should alert on offsets exceeding a defined threshold.
How is NTP synchronisation and clock drift monitored across production systems?
Automated drift monitoring with alerts is expected for environments where log correlation accuracy is required for compliance or incident response. Cloud provider defaults alone are insufficient.
Is tenant data isolated so that one tenant cannot read another tenant's data?
Answer yes only where a mechanism enforces the boundary. An application convention that every query includes a tenant identifier is not enforcement; a platform that refuses the query without one is.
At which layers is isolation between tenants or between workloads enforced?
Isolation usually fails at a layer nobody drew: a shared cache, a search index, an export path or a vector index built from several tenants' documents. Count a layer only where the enforcement is in the platform rather than in the calling code.
How is cross-tenant access tested?
Options run from strongest to weakest. A design review records an intention; a test that asserts a denial records the current behaviour of the deployed system.
Is there an inventory of every public domain and DNS zone used by the service with a named owner for each?
Marketing sites, regional domains and defensive registrations count. A domain nobody owns is the one that expires.
Which of the following protect your domains and name resolution?
Signing and validation are separate settings and one without the other protects nothing. The check for records pointing at released cloud resources is what closes subdomain takeover. The routing item is answerable by a provider that owns no address space: what is recorded there is whose measure applies and the statement it comes from.
How often are DNS records checked for targets the organisation no longer holds?
Options run from strongest to weakest. The exposure window is the gap between releasing a cloud resource and removing the record that points at it, so the interval is the control.
Is every endpoint used to access organisational or customer data enrolled in centralised device management?
Enrolment is what makes the rest of this control testable from one export. Personal devices used for work count; if they are permitted without enrolment, the answer is no.
Which of the following are enforced on managed endpoints by the management platform?
Count a setting only where the platform enforces it and reports compliance. A rule written in the endpoint standard and left to the user is not enforcement.
How is the endpoint inventory kept accurate?
Options run from strongest to weakest. The failure this measures is the device nobody removed when its user left, which only a reconciliation against the workforce list finds.
Is physical access to each office the organisation occupies restricted to an approved access list?
A serviced or shared office still has an access list; it is held by the building operator and the organisation approves who is on it. Answer for the space the organisation controls.
Which of the following are in place at the premises the organisation occupies?
Answer for the space the organisation occupies, not for the cloud data centre. What the infrastructure operator does is covered by the attestation question. The maintenance record covers the doors, locks, walls, barriers and access hardware that enforce the boundary; a general facilities ticket queue counts only where the security work can be identified inside it.
How are the physical controls of the infrastructure operator evidenced?
Options run from strongest to weakest. The step most often missed is the last one in the strongest option: writing down which of your requirements each inherited control answers, so that a gap is visible when the report changes.
Is there a documented log scope naming the security-relevant events captured across production systems, applications and cloud services?
Log scope should be documented in a formal policy or standard. Gaps in event categories (e.g. no data access logging) are a common audit finding.
Which event categories are captured in your production audit logs?
All seven categories are expected for a complete audit logging posture. Missing data access or configuration change logging are the most common gaps in enterprise environments.
Are audit logs stored in a tamper-resistant or write-once store?
Log storage should be in a separate account, project, or cloud resource from the systems generating logs. Object Lock (Compliance mode) or equivalent immutability should be enforced.
Which mechanisms are used to protect audit log integrity?
Options run from the most commonly held to the least. Storage controls and cryptographic protection answer different attacks: immutable storage stops deletion by someone who reached the store, signing stops undetected alteration before the record arrived, including by whoever runs the store. Covering the tools closes the case where the reader is changed rather than the data.
Are audit logs retained for a documented minimum period?
The minimum expected retention is 12 months online and up to 24 months in cold storage. Retention policies should be automated, not dependent on manual archiving.
What is the current minimum retention period for audit logs in your environment?
12 months online with extended cold storage is the standard expectation. For organisations subject to the EU AI Act or GDPR enforcement, ensure retention aligns to applicable regulatory timelines.
Is the retention period enforced by an automated policy on the log store rather than by a manual archiving process?
Answer yes only where the lifecycle or retention rule is set on the store itself, so a log ages out or is preserved without anyone acting. A calendar reminder to archive is not enforcement.
Is log data from production systems, applications, cloud services and network devices aggregated into a centralised log management platform?
Centralised collection is a prerequisite for effective threat detection. Siloed logs that cannot be correlated across systems leave blind spots in incident investigation.
Which of the following log sources are ingested into your centralised platform?
Options run from the most commonly ingested to the least. The control is about coverage and correlation, not about which platform is in use. A source that is collected but lands somewhere the platform cannot search does not count.
How are logging pipeline failures and log storage capacity issues detected and responded to?
Options run from strongest to weakest. Automated alerting with a defined response SLA and runbook is the working standard. The strongest option adds the part that is almost always missing: a check on the platform that runs somewhere else, because a health dashboard inside the platform goes dark with the outage it exists to report.
Are production systems monitored for anomalous behaviour and indicators of compromise?
Active monitoring requires both configured detection rules and a team responsible for reviewing and responding to alerts. Logs without active review provide no detection capability. Answer yes only where the periodic review of the record sets themselves also happens: alert triage reads what crossed a threshold, which is a different act from reading the audit logs, the access reports and the incident tracking records at a stated interval.
Which threat scenarios are covered by active detection rules in your SIEM or monitoring platform?
The first four categories are the minimum expected coverage. All seven indicate a mature detection programme.
What is the defined SLA for acknowledging and triaging high severity security monitoring alerts?
24/7 coverage with a 1-hour or faster acknowledgement SLA is the expectation for high severity alerts in a production environment.
Is the detection rule set mapped to a threat model or a recognised technique catalogue?
Mapped means each rule points at the behaviour it is there to catch and the coverage of the model can be read off the mapping. A rule set built from vendor defaults with no reference back to a threat model does not meet this.
Which of the following does the detection rule set record for each rule?
The suppression fields are the ones that decay fastest, because a rule silenced during an incident is rarely re-examined. Answer against what the platform holds, not against what the runbook says should be held.
How often are detection rules tuned using the outcomes of the alerts they raised?
Options run from strongest to weakest. Tuning means changing the rule on evidence from the queue. Disabling a noisy rule without a revisit date is suppression, which the previous question covers.
Is read access to production logs restricted to named roles?
Answer no where every engineer inherits log read access from a general production role. The question is about the log platform, not about the systems that produce the logs.
Which of the following apply to your logging pipeline and log store?
Filtering before the record reaches the store is different from masking it in a query or a dashboard, which leaves the value in the store. Answer against the pipeline as it runs, not against the logging standard.
How often are log platform access grants reviewed?
Options run from strongest to weakest. A review that produces findings nobody actions is not a review; the removals are the test.
Does every customer-facing service have a defined availability objective?
An objective is a target with a measurement window, not a phrase in a sales contract. Answer no where availability is watched but no target is written down.
Which of the following are in place for availability monitoring?
Measurement from the customer's side means a probe or a request-level metric from the path a customer uses. Host uptime and container health checks answer a different question and a service can pass both while customers see errors. A qualitative target counts only where a threshold decides the miss. The last item is the one no status page carries: a change of control, a lost certification, a failing subcontractor or a retirement decision all threaten a service level before any event opens.
How are customers told about a degradation in progress?
Options run from strongest to weakest. The defined time is measured from detection, not from the point the cause is understood, because a customer needs to know the service is affected before anyone knows why.
Is a documented risk assessment conducted for each third-party vendor before engagement?
The assessment should be completed before the vendor is engaged and produce a documented risk rating and engagement decision signed off by an appropriate authority (e.g. CISO, DPO). Critical vendors should be reassessed at least annually.
What does the vendor risk assessment and supplier register cover?
A comprehensive pre-engagement assessment should cover at minimum: security posture, privacy compliance, certifications and incident history. Financial and operational resilience assessment is important for critical suppliers.
Is there a named cross-functional group that owns supply chain risk activity, with its members and their responsibilities recorded?
Answer yes only where the membership and the activities the group leads are written down rather than understood informally. A standing meeting with no terms of reference, or a group that exists on a slide and has not met, does not count.
Do contracts with all vendors who access, process, store or transmit organisational data include binding security and privacy obligations?
Contracts should include at minimum: information security obligations, incident notification timelines (72 hours or less), audit rights, data handling and deletion requirements, sub-processor controls, and exit provisions.
Which of the following clauses are included as standard in your vendor contracts?
All eight clauses are expected in contracts with vendors processing personal or sensitive data. Absence of a DPA for any personal data processor is a direct GDPR compliance gap.
Which of the following do your contracts for supplied components and external services require?
Options run from the most commonly required to the least. A receiving organisation cannot secure what it cannot describe: a component whose ports and protocols are undeclared cannot be fitted to a hardening baseline, and a control whose functional properties are unstated cannot be relied on or tested. Priority of service decides whether alternate capacity is there when everyone else is invoking theirs too.
Does your organisation maintain a current register of all sub-processors?
The sub-processor register should be publicly accessible or available to customers on request. Customer notification of sub-processor changes must occur with sufficient notice for the customer to object.
How does your organisation manage changes to the sub-processor list?
Advance notification with a right to object is the standard expected by enterprise customers and is required under GDPR Art.28.2. A published list without proactive notification is a weaker but common approach. The customer should confirm whether this satisfies their contractual requirements.
Are sub-processors bound by data protection obligations equivalent to those you owe the controller?
Answer yes only where the flow-down is in the executed agreement with each sub-processor rather than asserted in your own privacy documentation. A sub-processor engaged on its own standard terms usually is not so bound.
Is there a documented process governing the selection, security assessment, configuration, monitoring and exit of cloud service providers?
The process should include security baseline configuration standards (e.g. CIS Benchmarks), documented shared responsibility boundaries, and contractual data portability and exit provisions. Misconfiguration of cloud services is a leading cause of security incidents.
Which elements of cloud service provider security management are formally documented in your organisation?
A shared responsibility matrix and documented configuration baseline are the minimum expected artefacts. Exit planning is critical to ensure data can be recovered or migrated if the CSP relationship ends.
Are vendor security posture and contractual performance reviewed at defined intervals of at least annually?
Reviews should include: updated security certifications or questionnaire responses, incident history check, SLA performance, and any open findings from the previous review. Material deficiencies should be escalated and tracked to resolution.
What triggers a vendor security review outside of the regular annual cycle?
Event-triggered reviews are critical because vendor risk does not change on a fixed annual schedule. Vendor breaches and significant service changes should always trigger an unscheduled reassessment.
Which of the following does each vendor review record?
Options run from the most commonly recorded to the least. A review that reads the current certificate and nothing else repeats the pre-engagement assessment rather than testing the relationship since.
Is every vendor and third-party access grant formally authorised before access is enabled?
Vendor accounts must enforce MFA, have scoped permissions (no broad administrative access), and be time-bounded. Privileged vendor sessions should be logged and, where possible, recorded.
Which controls are applied specifically to privileged vendor access (e.g. remote support, admin credentials)?
JIT provisioning, MFA, and session recording are the expected standard for privileged vendor access. Standing, unmonitored vendor accounts with broad access are a high-risk exposure.
Does your organisation follow a documented offboarding procedure when a vendor relationship ends?
All vendor access credentials (SSO, API keys, service accounts, VPN) must be revoked on or before the termination date. The vendor must provide written confirmation of data deletion or return. Contractual documents including the DPA must be archived.
What does your vendor offboarding checklist include?
All six elements of a complete offboarding should be present. Absence of written vendor confirmation of data deletion is a common gap that creates ongoing liability.
Are disclosures of personal or sensitive data to third parties recorded in a disclosure register?
Every standing third-party disclosure relationship should appear in the data inventory or a dedicated disclosure register. Recipients must be restricted to the minimum data required for the stated purpose, and disclosures must be consistent with what is stated in the privacy notice.
What controls govern the disclosure of personal or sensitive data to third parties?
All six active controls indicate a mature third-party disclosure programme. Absence of a disclosure register makes it impossible to fulfil data subject requests or demonstrate accountability to a supervisory authority.
Is the shared responsibility matrix published where a prospective customer can read it without an account?
The test is publication, not existence. A matrix supplied on request, behind a customer login or under a non-disclosure agreement does not meet this, because a customer scoping its own controls before it signs cannot reach it.
What does the customer-facing security documentation cover?
Naming the control set is what makes the matrix usable: a customer scoping its own audit needs to know which framework the rows correspond to. Authenticity is the commitment most often absent, because it is the one no encryption setting produces on its own. The last item is a statement about what is in place, not about how a request is handled once it lands.
When is the shared responsibility documentation reviewed?
Options run from strongest to weakest. A new service or a new sub-processor is what makes the matrix wrong, so the trigger matters as much as the cycle.
Is there a documented procedure for handling government and law enforcement requests for customer data?
This is separate from the disclosure controls that govern sharing you choose to do. The question is what happens when a demand arrives that you cannot decline on contract grounds.
What does the procedure require before data is released?
Narrowing is the step most often missed: an overbroad demand answered in full is a disclosure the organisation chose to make. The recognition test is the step before that one and is missed more often still, because a review that satisfies itself the order is valid where it was issued has answered a different question. Notification counts here only where it runs before the response leaves.
How are requests reported to customers?
Options run from strongest to weakest. Reporting counts of requests is possible even where an individual request is under a non-disclosure order.
Is there a register of the customer agreements in force and the terms each is required to carry?
The register is about terms the organisation accepts from a customer, not terms it imposes on a supplier; those are in the vendor contract control. Answer yes only where the register exists and lists the agreements, not merely the regulations.
Which of the following does the customer agreement state?
Count only what the executed agreement or the terms it incorporates say. A commitment made in product documentation, a support article or a trust centre page is not a term of the agreement. Options follow the order a switching schedule is normally drafted in, not an order of importance.
How is the agreement set kept current when the terms a regulation requires change?
Options run strongest to weakest. Answer on what happened the last time a required term changed, not on what the contract management procedure says would happen.
Is there a published procedure stating the audit and inspection rights granted to customers?
Published means a customer or a prospective customer can read it rather than negotiate it. An audit clause in a signed contract with no published procedure behind it is a no, as is a procedure that exists only as an internal playbook.
Which of the following does the procedure state?
Tick an element only where the published procedure states it. A right the organisation would grant on request but has not written down does not count here. The premises option is about physical sites, including sites operated by a subcontractor, not about remote access to systems.
How often may a customer exercise an audit under the published terms?
Options run from the widest right to the narrowest. Answer on the terms as published, not on how often customers have actually asked.
Is a record of the subcontractors underpinning each customer-facing service made available to customers?
This is the ICT supply chain behind the service, whether or not personal data is involved. A sub-processor list covering only parties that process personal data is a no unless it also reaches the rest of the chain.
Which of the following does the subcontractor change process provide?
Answer on what the process does rather than on what a contract template offers. The third and fourth options differ: a change can be held until the notice period closes and still go ahead over an objection raised inside it.
What identifies each subcontractor in the record?
Options run from the most complete entry to the least. Answer on the record as published, not on what the internal supplier register holds.