| name | vendor-security-assessment |
| title | Vendor Security Assessment Questionnaire |
| description | Drafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor responses become binding contractual representations with executive certification. Use during vendor due diligence, third-party risk management, procurement security review, or subprocessor evaluation. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/vendor-security-assessment |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | cybersecurity |
| language | en |
Vendor Security Assessment Questionnaire
Generates a pre-contract due-diligence questionnaire for evaluating vendor security controls, data practices, and compliance across GDPR, CCPA, HIPAA, SOX, GLBA, FERPA, and industry frameworks.
Quick Start
Gather before drafting:
- Vendor scope — data types accessed (PII, PHI, PCI, financial, proprietary), processing activities, data flows
- Applicable regulations — GDPR, CCPA, HIPAA, SOX, GLBA, FERPA, or sector-specific
- Risk tolerance — what constitutes acceptable vs. disqualifying vendor risk
- Contract alignment — security provisions to incorporate by reference
Document Framework
| Element | Requirement |
|---|
| Preamble | Completion mandatory pre-contract; responses are binding representations |
| Executive certification | Senior officer (CISO/CTO/CLO) attests accuracy; signature block required |
| Submission deadline | 10–15 business days |
| Change notification | Vendor notifies within 5 business days of material security changes |
| Confidentiality | Questionnaire and responses treated as confidential business information |
Assessment Domains
Draft numbered questions per domain. Each question includes a response field and evidence-request field where applicable. Tailor scope to data sensitivity — not every vendor needs every domain.
1. Information Security Governance
- Dedicated CISO/equivalent; certifications (CISSP, CISM, CISA)
- Framework alignment (NIST CSF, ISO 27001, CIS Controls, COBIT)
- Policy review cadence; security awareness training (all-staff + specialized)
- Board-level security reporting frequency
2. Data Classification & Lifecycle
- Classification taxonomy compatibility with client's scheme
- All data storage/processing locations (primary, DR, backup, cloud regions)
- Cross-border transfer mechanisms (SCCs, adequacy decisions, BCRs)
- Retention post-termination; destruction methods; certificates of destruction
- Backup frequency; encrypted backup media; tested RTO/RPO
3. Access Control & Privileged Access
- MFA enforcement across all access; supported factors
- RBAC, least-privilege, segregation of duties