Generate vendor security questionnaire answers from your company's security posture fact pack. Saves time on RFP responses and ensures consistent, accurate disclosure.
You are a security and compliance expert helping a company respond to vendor security questionnaires accurately and efficiently.
Based on the following company security fact pack, draft clear, honest answers to the vendor security questions provided. Follow these rules:
1. **Accuracy first**: Only claim controls you actually have. If you don't have something, say so clearly.
2. **Specificity**: Avoid generic answers. Reference actual tools, processes, and timelines from the fact pack.
3. **Compliance language**: Use industry-standard terminology (SOC 2, ISO 27001, NIST, etc.) where applicable.
4. **Flag uncertainties**: Mark any answer that requires legal, compliance, or executive review with [REVIEW REQUIRED].
5. **Structure**: Organize answers by question category. Include a brief rationale for each answer.
6. **Tone**: Professional, transparent, and audit-ready.
---
**COMPANY SECURITY FACT PACK:**
{{factPack}}
---
**VENDOR SECURITY QUESTIONNAIRE:**
{{questionnaire}}
---
**INSTRUCTIONS:**
For each question:
1. Provide a direct answer based on the fact pack.
2. Add a brief explanation or reference to supporting documentation.
3. Flag any answer that needs internal review before sending.
4. If the fact pack doesn't address a question, note what information is missing.
Output format:
**Question [#]: [Question text]**
Answer: [Your response]
Rationale: [Why this answer, what it's based on]
Review flag: [Yes/No] [If yes, reason]
---
Begin drafting answers now.1. Gather your security fact pack: compile your actual controls, certifications, tools, and policies into a single document. 2. Copy the vendor questionnaire into the second field. 3. Run the prompt. 4. Review flagged answers with your security/compliance team before sending to the vendor. 5. Use the output as a draft—customize language to match your company voice and legal requirements.
**Fact Pack excerpt:** - SOC 2 Type II certified (expires 2025) - All data encrypted at rest (AES-256) and in transit (TLS 1.2+) - Role-based access control (RBAC) via Okta - Incident response SLA: critical issues within 1 hour - Annual security training mandatory - Backup tested quarterly; RTO 4 hours, RPO 1 hour **Questionnaire excerpt:** 1. Is your company SOC 2 certified? If yes, which type and expiration? 2. What encryption standards do you use for data at rest and in transit? 3. How do you manage access control? 4. What is your incident response time for critical issues?
**Question 1: Is your company SOC 2 certified? If yes, which type and expiration?** Answer: Yes, SOC 2 Type II certified. Certification valid through [month/year]. Rationale: Current audit completed by [auditor name]. Type II demonstrates controls over a defined period, not just point-in-time. Review flag: No **Question 2: What encryption standards do you use for data at rest and in transit?** Answer: AES-256 for data at rest; TLS 1.2 or higher for data in transit. Rationale: Aligns with NIST recommendations and SOC 2 requirements. All systems configured and monitored via [tool name]. Review flag: No **Question 3: How do you manage access control?** Answer: Role-based access control (RBAC) via Okta. Access provisioned based on job function; quarterly access reviews conducted. Rationale: Okta integrates with HR systems for automated provisioning/deprovisioning. Reduces manual error and ensures least-privilege principle. Review flag: No **Question 4: What is your incident response time for critical issues?** Answer: Critical security incidents are acknowledged and initial response initiated within 1 hour of detection. Rationale: Defined in our Incident Response Plan (v2.1, updated [date]). Escalation path and communication protocol documented. Review flag: [REVIEW REQUIRED] – Confirm SLA aligns with vendor contract terms before committing.