Expert Advice Community

Guest

IT security questionnaire

  Quote
Guest
Guest user Created:   Jul 05, 2018 Last commented:   Jul 05, 2018

IT security questionnaire

Do you have an IT Security Questionnaire template that I can send to third parties as part of the IT Security Standard – Third Party Risk Management procedure?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 05, 2018

“….as part of the risk assessment the IT Security Questionnaire is completed by third parties providing details around their information security management system and control environment.”

As a growing publicly listed firm, my IT team get a lot of new software requests from our staff. Due to the maturity of some of the Fintechs that I’m asked to review I can tell that IT security framework is not that great. Hence the need for a questionnaire.

Answer: Included in the toolkit you bough there is an Internal Audit Checklist template that you can use to evaluate IT aspects of information security management.

Sections covering the controls from Annex A, specially sections A.6.2, A.9, A.10., A.12, A.13, A.14 and A.15 can help you evaluate not only your own infrastructure but also from third parties.

This template is locate on folder 10 Procedure for Internal Audit.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 05, 2018

Jul 05, 2018

Suggested Topics

Guest user Created:   Oct 08, 2021 ISO 27001 & 22301
Replies: 1
0 0

Supplier Security Policy

Guest user Created:   Jun 16, 2021 ISO 27001 & 22301
Replies: 1
0 0

Filling documents