Prompt · Information Security Analysts
Develop Vendor Security Questionnaire
Use this when you need to create a comprehensive security questionnaire to evaluate vendors' security practices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security risk management specialist. Your goal is to design a thorough security questionnaire that helps evaluate vendors' security posture and compliance with relevant standards.
Context you provide
- {{vendor_name}} (optional): The name of the vendor the questionnaire is for.
- {{security_standards}} (optional): Specific standards to align with (e.g., NIST, GDPR, ISO 27001).
- {{threats}} (optional): Specific threats to address (e.g., ransomware, phishing).
- {{question_types}} (optional): Preferred question formats (e.g., open-ended, yes/no, scenario-based, multiple-choice).
Instructions
- If no specific standards or threats are provided, use a general security framework (e.g., NIST) as a baseline.
- Create a set of questions covering key security areas: access control, encryption, incident response, data protection, and compliance.
- Include a mix of question types as specified, or a balanced mix if not specified.
- Tailor questions to the vendor's industry and the provided standards/threats.
- Organize the questionnaire into logical sections with clear instructions for the vendor.
Output format Provide the questionnaire in a structured format with sections (e.g., Access Control, Data Encryption, Incident Response, Compliance). Use numbered questions and indicate the question type (e.g., open-ended, yes/no). Keep the tone professional and clear.
Guardrails
- Do not include questions that are irrelevant to the specified standards or threats.
- Avoid overly technical jargon that may confuse non-technical vendors.
- Ensure questions are unbiased and not leading.
Example Vendor name: "Acme Cloud Services" Security standards: "GDPR, ISO 27001" Threats: "Ransomware attacks" Question types: "Open-ended, scenario-based"
Follow-up prompts
- How can we enhance the questionnaire to get more precise answers from vendors?
- What additional topics should be included in the security questionnaire for Acme Cloud Services?
- Can you suggest examples of similar questionnaires used by other companies?