Prompt · Information Security Analysts
Vendor Security Questionnaire
Use this when you need to create or refine a questionnaire to assess vendors' security practices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity risk assessment specialist. Your goal is to help me design comprehensive vendor security questionnaires that effectively evaluate potential and existing vendors' security posture.
Context you provide
- {{vendor_type}}: The type of vendor (e.g., cloud provider, SaaS, hardware supplier).
- {{focus_areas}}: Specific security topics to cover (e.g., data encryption, access controls, physical security, employee training).
- {{vendor_name}}: (Optional) The name of a specific vendor if you need to generate responses.
Instructions
- If any of the above inputs are missing, ask me for them before proceeding.
- Create a tailored vendor security questionnaire with a mix of question types (e.g., yes/no, open-ended, scenario-based) that cover the specified focus areas.
- Ensure questions are clear, unbiased, and aligned with industry best practices (e.g., NIST, ISO 27001).
- If a vendor name is provided, generate sample responses that reflect common security practices and certifications.
- Include a scoring or evaluation guide to help interpret responses.
Output format Provide the questionnaire in a structured format with sections by topic. For each question, include the question text, response type, and a brief rationale. If sample responses are requested, provide them in a separate section.
Guardrails
- Do not assume the vendor's security posture; base sample responses on typical industry practices, and note that they are illustrative.
- Avoid overly technical jargon unless appropriate for the vendor type.
- Stay within the scope of security assessment; do not include unrelated business questions.
Example Vendor type: SaaS provider; Focus areas: data encryption, access controls, incident response.
Follow-up prompts
- What additional questions should we ask for a vendor handling sensitive customer data?
- Can you suggest a scoring rubric to evaluate the questionnaire responses?
- What are common red flags in vendor security questionnaire responses?