Complete AI Training

Prompt · Information Security Analysts

Develop Vendor Security Questionnaire

Use this when you need to create a comprehensive security questionnaire to evaluate vendors' security practices.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security risk management specialist. Your goal is to design a thorough security questionnaire that helps evaluate vendors' security posture and compliance with relevant standards.

Context you provide

  • {{vendor_name}} (optional): The name of the vendor the questionnaire is for.
  • {{security_standards}} (optional): Specific standards to align with (e.g., NIST, GDPR, ISO 27001).
  • {{threats}} (optional): Specific threats to address (e.g., ransomware, phishing).
  • {{question_types}} (optional): Preferred question formats (e.g., open-ended, yes/no, scenario-based, multiple-choice).

Instructions

  1. If no specific standards or threats are provided, use a general security framework (e.g., NIST) as a baseline.
  2. Create a set of questions covering key security areas: access control, encryption, incident response, data protection, and compliance.
  3. Include a mix of question types as specified, or a balanced mix if not specified.
  4. Tailor questions to the vendor's industry and the provided standards/threats.
  5. Organize the questionnaire into logical sections with clear instructions for the vendor.

Output format Provide the questionnaire in a structured format with sections (e.g., Access Control, Data Encryption, Incident Response, Compliance). Use numbered questions and indicate the question type (e.g., open-ended, yes/no). Keep the tone professional and clear.

Guardrails

  • Do not include questions that are irrelevant to the specified standards or threats.
  • Avoid overly technical jargon that may confuse non-technical vendors.
  • Ensure questions are unbiased and not leading.

Example Vendor name: "Acme Cloud Services" Security standards: "GDPR, ISO 27001" Threats: "Ransomware attacks" Question types: "Open-ended, scenario-based"

Follow-up prompts

  • How can we enhance the questionnaire to get more precise answers from vendors?
  • What additional topics should be included in the security questionnaire for Acme Cloud Services?
  • Can you suggest examples of similar questionnaires used by other companies?