Oredra Security Library
Governance & assurance security questionnaire answers
Policies, vendor reviews, SOC 2, ISO/IEC 27001, and what those claims actually mean.
Governance & assurance
Questions customers commonly ask.
Governance & assurance
Do you maintain a written information security policy?
Answer “yes” only if a written policy actually exists in a current, approved form. A policy describes expectations and requirements; it does not by itself prove that every stated practice or control is operating.
Understand this questionGovernance & assurance
Do you assess the security of vendors and third parties?
Describe how your company evaluates vendors that can affect customer data or important operations. A small business may perform practical due diligence without running a formal enterprise vendor-risk program; the answer should reflect the process that actually exists.
Understand this questionGovernance & assurance
Are you SOC 2 compliant, certified, or do you have a SOC 2 report?
SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.
Understand this questionGovernance & assurance
Are you ISO 27001 certified?
ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.
Understand this questionNot sure what your company can answer?
Check your questionnaire readiness in about three minutes.
See which common areas are clear, scattered, uncertain, or simply not something your company does today. It is not a compliance score.
Take the free readiness check