Free resource
One source of truth so every team answers consistently. Canonical answer, evidence reference and owner per question - so the next questionnaire gets faster, not harder.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A single source of truth so sales, engineering and ops answer security questionnaires the same way every time. Every row is a model answer - adapt the [bracketed] parts, link the evidence, name an owner. |
| How to use it | When a questionnaire lands, answer from this library, not from memory. Afterwards, fold any genuinely new question back in - the library gets stronger and the next response gets faster. |
| The #1 mistake | Different teams giving different answers to the same question. One contradiction between sales and engineering is what makes a buyer's security team start digging. |
| A second pair of eyes | If you want someone who has sat on the other side of the audit table to sanity-check your scoring before it counts, that is what we do at kellwick.com. |
Sheet: Answer Library
Every row below has a canonical answer written for you - adapt the [brackets], link the evidence and name the owner. Write each answer once and the next questionnaire gets faster, not harder.
| Domain | Question | Canonical answer (adapt the [brackets]) | Evidence reference | Owner | Last reviewed |
|---|---|---|---|---|---|
| Access control | Do you enforce MFA for all users? | Yes. MFA is enforced for all user and administrator access to production and internal systems via [identity provider]. Any exception is documented, time-bound and approved by [role]. | [MFA policy + IdP config] | - | - |
| Access control | How often do you review access? | User access is reviewed at least [quarterly] and on every role change. Reviews are recorded and any excess access is removed and the removal evidenced. Privileged access is reviewed [monthly]. | [access review records] | - | - |
| Encryption | Is data encrypted in transit and at rest? | Yes. Data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256 for [databases / object storage / backups]. Keys are managed in [KMS] with defined rotation. | [encryption standard] | - | - |
| Backup / recovery | Do you test restores? How often? | Backups run [daily] and are encrypted. We test restores at least [quarterly] and record the outcome, so recovery is proven rather than assumed. Our targets are RTO [X] and RPO [Y]. | [restore test log] | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources