Oredra Security Library

Incidents & vulnerability management security questionnaire answers

Incident response, notifications, scanning, penetration testing, and patching.

← All security questionnaire questions

Incidents & vulnerability management

Questions customers commonly ask.

Incidents & vulnerability management

Do you have an incident response plan?

A written incident response plan documents how the company prepares for and handles cybersecurity incidents. Do not treat an informal understanding, a cyber-insurance phone number, or a vendor service as proof that your company maintains a complete plan.

Understand this question

Incidents & vulnerability management

How do you notify customers of a security incident?

Describe the company process for deciding when and how affected customers are notified. Be careful with exact deadlines: notification timing can depend on contracts, laws, the facts of the incident, and the commitments your company has actually made.

Understand this question

Incidents & vulnerability management

Do you perform vulnerability scanning?

Vulnerability scanning generally means using tools or services to identify known weaknesses in systems, software, or configurations. Confirm the actual scope, frequency, and ownership before answering, and do not substitute penetration testing—or vice versa—as if they were the same activity.

Understand this question

Incidents & vulnerability management

Do you perform penetration testing?

Answer “yes” only when your company has actually had the relevant systems or application tested through a penetration-testing engagement. Vulnerability scans, automated security checks, and a written policy are not automatically penetration tests.

Understand this question

Incidents & vulnerability management

How do you manage security patches and software updates?

Describe how security updates are identified, evaluated, and applied to the systems your company manages. Avoid inventing universal patch deadlines: different systems, vendors, and severity levels may follow different processes.

Understand this question

Not sure what your company can answer?

Check your questionnaire readiness in about three minutes.

See which common areas are clear, scattered, uncertain, or simply not something your company does today. It is not a compliance score.

Take the free readiness check