VSQ-001 · Company & ScopeWhat legal entity provides the service being assessed?Suggested evidence: Contract entity / order form · Typical owner: Legal / Sales
VSQ-002 · Company & ScopeWhat product, service, and deployment model are in scope for this review?Suggested evidence: Architecture overview / product scope · Typical owner: Product / Solutions Engineering
VSQ-003 · Company & ScopeWhich production regions process or store customer data?Suggested evidence: Data residency documentation · Typical owner: Security / Privacy
VSQ-004 · Company & ScopeWhich customer data types are processed by the service?Suggested evidence: Data flow / data classification map · Typical owner: Privacy / Product
VSQ-005 · Company & ScopeDoes the service support single-tenant, multi-tenant, or both deployment models?Suggested evidence: Architecture documentation · Typical owner: Engineering
VSQ-006 · GovernanceIs there an approved information security policy reviewed on a defined cadence?Suggested evidence: Information security policy · Typical owner: Security / GRC
VSQ-007 · GovernanceWho is accountable for the information security program?Suggested evidence: Org chart / security charter · Typical owner: Executive / Security
VSQ-008 · GovernanceHow are security exceptions documented, approved, and reviewed?Suggested evidence: Exception management procedure · Typical owner: Security / GRC
VSQ-009 · GovernanceHow are security risks tracked through remediation?Suggested evidence: Risk register / risk procedure · Typical owner: Security / GRC
VSQ-010 · GovernanceAre employees required to complete security awareness training?Suggested evidence: Training policy / completion record · Typical owner: Security / HR
VSQ-011 · Identity & AccessIs multi-factor authentication required for privileged administrative access?Suggested evidence: IAM standard / access configuration · Typical owner: Security / IT
VSQ-012 · Identity & AccessHow is least privilege enforced for production access?Suggested evidence: Access control policy / role matrix · Typical owner: Security / Engineering
VSQ-013 · Identity & AccessHow frequently are privileged and sensitive-access rights reviewed?Suggested evidence: Access review procedure / review evidence · Typical owner: Security / IT
VSQ-014 · Identity & AccessHow quickly is access revoked after termination or role change?Suggested evidence: Joiner-mover-leaver procedure · Typical owner: IT / HR
VSQ-015 · Identity & AccessAre shared administrative accounts prohibited or tightly controlled?Suggested evidence: Access control standard · Typical owner: Security / IT
VSQ-016 · Data ProtectionIs customer data encrypted in transit?Suggested evidence: Encryption standard / TLS configuration · Typical owner: Security / Engineering
VSQ-017 · Data ProtectionIs customer data encrypted at rest?Suggested evidence: Encryption standard / cloud configuration · Typical owner: Security / Engineering
VSQ-018 · Data ProtectionHow are encryption keys generated, stored, rotated, and access-controlled?Suggested evidence: Key management standard · Typical owner: Security / Platform
VSQ-019 · Data ProtectionHow is sensitive customer data classified and handled?Suggested evidence: Data classification and handling policy · Typical owner: Privacy / Security
VSQ-020 · Data ProtectionWhat controls prevent production customer data from being copied into lower environments without authorization?Suggested evidence: Data handling procedure · Typical owner: Engineering / Security
VSQ-021 · Application SecurityIs security review part of the software development lifecycle?Suggested evidence: Secure SDLC standard · Typical owner: Engineering / AppSec
VSQ-022 · Application SecurityAre code changes peer-reviewed before production release?Suggested evidence: Development workflow / branch protection · Typical owner: Engineering
VSQ-023 · Application SecurityAre dependencies and container images scanned for known vulnerabilities?Suggested evidence: Vulnerability management process · Typical owner: AppSec / Engineering
VSQ-024 · Application SecurityAre internet-facing applications tested for common web vulnerabilities?Suggested evidence: AppSec testing procedure / test report · Typical owner: AppSec
VSQ-025 · Application SecurityHow are secrets prevented from being committed to source repositories?Suggested evidence: Secrets management standard / scanning controls · Typical owner: Engineering / Security
VSQ-026 · Vulnerability ManagementHow are vulnerabilities prioritized and assigned remediation deadlines?Suggested evidence: Vulnerability management policy · Typical owner: Security / Engineering
VSQ-027 · Vulnerability ManagementHow are critical vulnerabilities escalated?Suggested evidence: Vulnerability escalation procedure · Typical owner: Security
VSQ-028 · Vulnerability ManagementAre external attack surfaces or production assets scanned on a recurring basis?Suggested evidence: Scanning schedule / platform evidence · Typical owner: Security
VSQ-029 · Vulnerability ManagementHow are security patches tested and deployed?Suggested evidence: Patch management procedure · Typical owner: IT / Platform
VSQ-030 · Vulnerability ManagementHow are accepted vulnerability risks documented and approved?Suggested evidence: Risk acceptance process · Typical owner: Security / GRC
VSQ-031 · Logging & MonitoringWhich security-relevant events are centrally logged?Suggested evidence: Logging standard / SIEM coverage · Typical owner: Security / Platform
VSQ-032 · Logging & MonitoringHow long are security logs retained?Suggested evidence: Logging and retention policy · Typical owner: Security / Privacy
VSQ-033 · Logging & MonitoringAre alerts configured for suspicious privileged activity?Suggested evidence: Detection rules / monitoring procedure · Typical owner: Security
VSQ-034 · Logging & MonitoringHow is access to security logs restricted?Suggested evidence: IAM roles / logging architecture · Typical owner: Security / Platform
VSQ-035 · Logging & MonitoringIs time synchronization used across production systems to support investigations?Suggested evidence: Infrastructure standard · Typical owner: Platform
VSQ-036 · Incident ResponseIs there a documented security incident response plan?Suggested evidence: Incident response plan · Typical owner: Security
VSQ-037 · Incident ResponseHow often is the incident response process exercised?Suggested evidence: Tabletop report / exercise record · Typical owner: Security / Executive
VSQ-038 · Incident ResponseHow are customers notified when a confirmed incident affects their data or service?Suggested evidence: Incident communication procedure / contract terms · Typical owner: Legal / Security
VSQ-039 · Incident ResponseHow are incident lessons learned converted into remediation actions?Suggested evidence: Post-incident review procedure · Typical owner: Security / Engineering
VSQ-040 · Incident ResponseAre forensic and investigation responsibilities defined?Suggested evidence: Incident response roles / runbook · Typical owner: Security
VSQ-041 · Business ContinuityIs there a documented business continuity and disaster recovery program?Suggested evidence: BCP / DR policy · Typical owner: Operations / Security
VSQ-042 · Business ContinuityAre backups tested for restoration?Suggested evidence: Backup testing record · Typical owner: Platform / Operations
VSQ-043 · Business ContinuityAre recovery objectives defined for critical services?Suggested evidence: BCP / service recovery documentation · Typical owner: Operations / Product
VSQ-044 · Business ContinuityHow are backup copies protected from unauthorized modification or deletion?Suggested evidence: Backup architecture / access controls · Typical owner: Platform / Security
VSQ-045 · Business ContinuityHow often are disaster recovery procedures exercised?Suggested evidence: DR exercise report · Typical owner: Operations / Engineering
VSQ-046 · Third PartiesIs there a process to assess security risk before onboarding critical subprocessors?Suggested evidence: Third-party risk procedure · Typical owner: Security / Procurement
VSQ-047 · Third PartiesIs a current list of subprocessors maintained for the service?Suggested evidence: Subprocessor list · Typical owner: Privacy / Legal
VSQ-048 · Third PartiesHow are material subprocessor changes reviewed and communicated?Suggested evidence: Vendor management procedure / privacy terms · Typical owner: Privacy / Procurement
VSQ-049 · Third PartiesAre contractual security and confidentiality requirements applied to relevant third parties?Suggested evidence: Vendor contract standard · Typical owner: Legal / Procurement
VSQ-050 · Third PartiesHow are critical third-party security issues tracked to closure?Suggested evidence: Vendor risk register · Typical owner: Security / Procurement
VSQ-051 · PrivacyIs there a defined process for handling data subject requests where applicable?Suggested evidence: Privacy procedure · Typical owner: Privacy / Legal
VSQ-052 · PrivacyHow are retention periods defined and enforced for customer data?Suggested evidence: Retention schedule / deletion procedure · Typical owner: Privacy / Engineering
VSQ-053 · PrivacyHow is customer data deleted after termination or an authorized deletion request?Suggested evidence: Deletion procedure / product documentation · Typical owner: Privacy / Engineering
VSQ-054 · PrivacyAre privacy reviews performed for material new uses of personal data?Suggested evidence: Privacy impact assessment procedure · Typical owner: Privacy / Product
VSQ-055 · PrivacyHow is access to personal data limited to authorized personnel?Suggested evidence: Access control / privacy policy · Typical owner: Privacy / Security
VSQ-056 · AI & Model GovernanceDoes the service use AI or machine-learning models in functionality delivered to customers?Suggested evidence: Product architecture / AI inventory · Typical owner: Product / AI
VSQ-057 · AI & Model GovernanceWhich model providers or model families are used in the customer-facing workflow?Suggested evidence: AI architecture / vendor list · Typical owner: Product / AI
VSQ-058 · AI & Model GovernanceIs customer content used to train or fine-tune models shared across customers?Suggested evidence: AI data-use policy / provider terms · Typical owner: Privacy / Product / Legal
VSQ-059 · AI & Model GovernanceWhat customer data is sent to external model providers and for what purpose?Suggested evidence: AI data flow / subprocessor documentation · Typical owner: Product / Privacy
VSQ-060 · AI & Model GovernanceWhat retention rules apply to prompts, outputs, embeddings, and retrieved content?Suggested evidence: AI retention policy / provider configuration · Typical owner: Privacy / Product
VSQ-061 · AI & Model GovernanceWhat human review or escalation controls apply to high-impact AI-assisted outputs?Suggested evidence: AI governance procedure / product controls · Typical owner: Product / Risk
VSQ-062 · AI & Model GovernanceHow are model or prompt changes tested before production release?Suggested evidence: AI change management / evaluation plan · Typical owner: AI / Engineering
VSQ-063 · AI & Model GovernanceHow are prompt injection, unsafe tool use, or untrusted retrieved content addressed?Suggested evidence: AI security design / threat model · Typical owner: AI / Security
VSQ-064 · AI & Model GovernanceAre AI-related incidents and material model failures included in incident processes?Suggested evidence: AI incident procedure · Typical owner: Security / Product
VSQ-065 · AI & Model GovernanceCan customers disable or restrict AI features where contractually supported?Suggested evidence: Product documentation / configuration guide · Typical owner: Product / Legal
VSQ-066 · Compliance & AssuranceWhich independent security certifications or attestations are currently in scope for the service?Suggested evidence: Current certificate / attestation report · Typical owner: GRC / Security
VSQ-067 · Compliance & AssuranceWhat is the scope and validity period of each certification or attestation?Suggested evidence: Certificate / auditor report · Typical owner: GRC
VSQ-068 · Compliance & AssuranceHow are audit findings or exceptions tracked through remediation?Suggested evidence: Audit remediation tracker · Typical owner: GRC / Security
VSQ-069 · Compliance & AssuranceIs a current penetration test or equivalent independent security assessment available under appropriate terms?Suggested evidence: Penetration test executive summary · Typical owner: Security / Legal
VSQ-070 · Compliance & AssuranceHow are customer requests for assurance evidence handled and approved?Suggested evidence: Customer trust procedure / evidence catalog · Typical owner: GRC / Sales Engineering
VSQ-071 · Physical & InfrastructureWhich cloud or hosting providers support the production service?Suggested evidence: Architecture diagram / vendor list · Typical owner: Platform / Security
VSQ-072 · Physical & InfrastructureHow is administrative access to cloud production environments restricted?Suggested evidence: Cloud IAM standard · Typical owner: Platform / Security
VSQ-073 · Physical & InfrastructureAre production networks segmented from development and corporate environments where appropriate?Suggested evidence: Network architecture · Typical owner: Platform / Security
VSQ-074 · Physical & InfrastructureHow are infrastructure changes reviewed and logged?Suggested evidence: Infrastructure-as-code workflow / change policy · Typical owner: Platform
VSQ-075 · Physical & InfrastructureHow is physical security responsibility allocated between the company and hosting providers?Suggested evidence: Shared-responsibility documentation · Typical owner: Security / Operations
VSQ-076 · Customer ControlsDoes the product support customer single sign-on?Suggested evidence: Product documentation · Typical owner: Product / Engineering
VSQ-077 · Customer ControlsDoes the product provide customer-configurable MFA or strong authentication controls?Suggested evidence: Product documentation · Typical owner: Product / Engineering
VSQ-078 · Customer ControlsCan customers manage roles and permissions using role-based or equivalent controls?Suggested evidence: Product access-control documentation · Typical owner: Product / Engineering
VSQ-079 · Customer ControlsAre customer audit logs or security events available through the product or API?Suggested evidence: Audit-log documentation · Typical owner: Product / Engineering
VSQ-080 · Customer ControlsCan customers configure data retention, regional storage, or security settings where supported?Suggested evidence: Product configuration documentation · Typical owner: Product / Privacy