Outgoing Questionnaires

Overview

Outgoing questionnaires are security assessments that your organization sends to vendors, partners, or service providers to evaluate their security posture and compliance status. This process, often called vendor due diligence, is a critical component of third-party risk management. The AskInfosec Security Questionnaire Automation platform streamlines the creation, distribution, and analysis of these questionnaires.

Prerequisites

Before creating an outgoing questionnaire, you need to:

  1. Set up vendor profiles - Ensure the vendor is added to your vendor management system

  2. Determine assessment scope - Identify the appropriate level of scrutiny based on the vendor's access to your data and systems

  3. Prepare questionnaire template - Select or create a template appropriate for the vendor's service type

Workflow

The typical workflow for outgoing questionnaires consists of the following steps:

  1. Create - Set up a new questionnaire and select the appropriate template

  2. Customize - Modify the questionnaire to address specific vendor risks

  3. Assign - Designate internal reviewers for the vendor's responses

  4. Send - Distribute the questionnaire to the vendor

  5. Monitor - Track the vendor's progress in completing the questionnaire

  6. Review - Evaluate the vendor's responses and supporting evidence

  7. Analyze - Assess the vendor's security posture based on their responses

Creating an Outgoing Questionnaire

Setting Up the Questionnaire

  1. Navigate to the Questionnaires section in the main navigation

  2. Click the Add Questionnaire button

  3. Select Outgoing as the questionnaire type

  4. Fill in the basic information:

    • Questionnaire Name - Provide a descriptive name (e.g., "Vendor X Security Assessment 2023")

    • Due Date - Set a deadline for the vendor to complete the questionnaire

    • Scope - Select "Outgoing" from the scope dropdown

    • Vendor - Select the vendor from your vendor directory

    • Internal Reviewers - Add team members who will review the vendor's responses

  5. Click Next to proceed to the template selection

Selecting a Template

The platform offers several standard questionnaire templates:

  • Basic Security Assessment - A lightweight questionnaire for low-risk vendors

  • Comprehensive Security Assessment - A detailed questionnaire for high-risk vendors

  • Industry-Specific Templates - Specialized questionnaires for healthcare, finance, etc.

  • Custom Templates - Your organization's custom questionnaire templates

To select a template:

  1. Browse the available templates

  2. Select the most appropriate template for your vendor assessment

  3. Preview the template to ensure it covers all necessary security domains

  4. Click Next to proceed to customization

Customizing the Questionnaire

Tailor the questionnaire to address specific risks associated with the vendor:

  1. Review the questions included in the template

  2. Add additional questions relevant to the vendor's service

  3. Remove questions that don't apply to the vendor's service

  4. Adjust question priorities based on your risk assessment

  5. Click Next to proceed to the final review

Final Review

Review the questionnaire details before sending:

  1. Verify the questionnaire name and due date

  2. Confirm the vendor information is correct

  3. Check the list of internal reviewers

  4. Review the selected questions

  5. Click Create to finalize the questionnaire

Sending the Questionnaire to Vendors

Vendor Invitation

Before sending a questionnaire, you need to invite the vendor to the platform:

  1. From the questionnaire details page, click Send to Vendor

  2. Verify the vendor's contact information

  3. Customize the invitation message

  4. Click Send Invitation

The vendor will receive an email with instructions to access the questionnaire.

Tracking Invitation Status

Monitor the status of your vendor invitations:

  1. Navigate to the Vendors section

  2. Check the Invitation Status column

  3. Statuses include:

    • Pending - Invitation sent but not yet accepted

    • Accepted - Vendor has registered and accessed the platform

    • Expired - Invitation link has expired

  4. Resend invitations as needed by clicking the Resend button

Monitoring Vendor Progress

Questionnaire Status Dashboard

Track the completion status of all outgoing questionnaires:

  1. Navigate to the Questionnaires section

  2. Filter by Outgoing type

  3. View the status of each questionnaire:

    • Not Started - Vendor has not begun the questionnaire

    • In Progress - Vendor is actively working on responses

    • Submitted - Vendor has completed and submitted responses

    • Under Review - Your team is reviewing the responses

    • Completed - Review is finished and assessment is complete

Detailed Progress View

For a specific questionnaire, you can view detailed progress:

  1. Click on the questionnaire name to open the details page

  2. View the Progress tab to see:

    • Percentage of questions answered

    • Questions grouped by status

    • Last activity timestamp

  3. Send reminders to vendors if progress is slow

Reviewing Vendor Responses

Response Review Process

Once a vendor submits their responses, your team can begin the review process:

  1. Navigate to the submitted questionnaire

  2. Click the Review button to enter review mode

  3. For each question:

    • Read the vendor's response

    • Review attached evidence

    • Mark the response as Accepted, Needs Clarification, or Insufficient

    • Add comments explaining your assessment

  4. Request additional information from the vendor if needed

Requesting Clarification

If a vendor's response is unclear or incomplete:

  1. Select the question requiring clarification

  2. Click the Request Clarification button

  3. Enter specific questions or requests for additional information

  4. Click Send to notify the vendor

The vendor will receive a notification and can provide additional information.

Accepting Vendor Responses

To accept a vendor's response:

  1. Review the response and supporting evidence

  2. If satisfied, click the Accept button

  3. Add optional notes about your acceptance decision

  4. The response status will update to Accepted

Risk Assessment

Scoring Vendor Responses

The platform automatically calculates risk scores based on vendor responses:

  1. Each question is assigned a risk weight

  2. Responses are evaluated against expected answers

  3. The system calculates domain-specific and overall risk scores

  4. Scores are displayed on the Risk Assessment tab

Risk Dashboard

The Risk Dashboard provides a visual representation of vendor risk:

  1. Navigate to the Risk Assessment tab

  2. View risk scores across different security domains:

    • Access Control

    • Data Protection

    • Incident Response

    • Business Continuity

    • And more

  3. Identify high-risk areas requiring remediation

Comparative Analysis

Compare a vendor's security posture against:

  1. Industry benchmarks

  2. Your organization's requirements

  3. Previous assessments of the same vendor

  4. Other vendors providing similar services

Remediation Management

Identifying Gaps

Identify security gaps in the vendor's controls:

  1. Navigate to the Gaps tab

  2. Review the list of identified security gaps

  3. Prioritize gaps based on risk level

  4. Create remediation plans for high-priority gaps

Creating Remediation Plans

For each identified gap:

  1. Click Create Remediation Plan

  2. Specify the required remediation actions

  3. Set deadlines for completion

  4. Assign responsibility (vendor or internal team)

  5. Click Save to create the plan

Tracking Remediation Progress

Monitor the vendor's progress in addressing security gaps:

  1. Navigate to the Remediation tab

  2. View the status of each remediation item

  3. Send reminders for approaching deadlines

  4. Request evidence of completed remediation actions

Reporting

Generating Vendor Assessment Reports

Create comprehensive reports on vendor security assessments:

  1. From the questionnaire details page, click Generate Report

  2. Select the report type:

    • Executive Summary - High-level overview for leadership

    • Detailed Assessment - Comprehensive analysis for security teams

    • Compliance Report - Focused on regulatory compliance

  3. Choose report format (PDF, Excel, Word)

  4. Click Generate to create the report

Scheduled Reports

Set up recurring reports for ongoing vendor monitoring:

  1. Navigate to the Reports section

  2. Click Schedule Report

  3. Select the report type and format

  4. Set the frequency (weekly, monthly, quarterly)

  5. Specify recipients

  6. Click Save to schedule the report

Best Practices

Questionnaire Design

  • Tailor questionnaires to the vendor's service type and risk level

  • Focus on controls relevant to your data and systems

  • Include both yes/no questions and requests for detailed explanations

  • Request specific evidence for critical security controls

Vendor Communication

  • Provide clear instructions and expectations

  • Set realistic deadlines based on questionnaire complexity

  • Offer assistance for technical questions

  • Maintain professional communication throughout the process

Review Process

  • Involve subject matter experts in reviewing responses

  • Verify evidence thoroughly for critical controls

  • Document your assessment rationale

  • Maintain consistency in evaluation criteria across vendors

Risk Management

  • Establish clear risk thresholds for vendor acceptance

  • Develop standard remediation requirements for common gaps

  • Implement continuous monitoring for high-risk vendors

  • Regularly reassess vendors based on changing risk profiles

Troubleshooting

Vendor Access Issues

  • Invitation Not Received: Verify email address and check spam folders

  • Access Errors: Ensure the vendor is using the correct login credentials

  • Expired Links: Generate new invitation links as needed

Response Collection Problems

  • Incomplete Submissions: Send reminders for unanswered questions

  • Evidence Upload Failures: Check file size and format restrictions

  • Deadline Extensions: Adjust due dates if vendors need more time

Conclusion

The Outgoing Questionnaires module of the Security Questionnaire Automation platform transforms vendor security assessments from a manual, time-consuming process into an efficient, structured workflow. By leveraging standardized templates, automated scoring, and collaborative review tools, your organization can effectively evaluate vendor security postures and manage third-party risk.

Remember that vendor security assessments are not just a compliance exercise but a critical component of your overall security program. Use the insights gained from these assessments to make informed decisions about vendor relationships and to drive security improvements across your supply chain.

Last updated