Skip to main content

Which Questions Appear in the Small Framework?

Written by ish

Summary

The Controls Framework has two sizes: Small and Full.

This article lists every question that is included in the Small Framework, grouped by domain, so you can quickly see the scope of what a supplier on the Small Framework will be asked.


Security Governance (7 questions)

Control

Question

A3

Does your organisation have a documented Cybersecurity Policy or Information Security Policy?

A10

Does your organisation have a Password Policy that is technically enforced throughout its IT estate?

A11

Does your organisation have a documented Backup Policy?

A13

Does your organisation prevent the use of removable media, and is this enforced technically?

A14

(Only if No to A13) If the use of removable media is not prohibited and enforced technically, is its use subject to other compensatory controls?

A19

Does your organisation restrict employee access to business information based upon the principle of least privilege?

A26

Does your organisation use threat intelligence to inform decisions about information security?

Security Certifications (8 questions)

Control

Question

B1

Is your organisation Cyber Essentials certified? (plus expiry date sub-question)

B2

(Only if Yes to B1) Is your organisation Cyber Essentials Plus certified? (plus expiry date sub-question)

B3

Is your organisation ISO 27001 certified? (plus expiry date sub-question)

B4

Is your organisation aligned with the NIST Cybersecurity Framework?

B5

Does your organisation store, process, transmit or otherwise have the ability to impact the security of cardholder data (CHD) or sensitive authentication data (SAD)?

B6

(Only if Yes to B5) Has your organisation performed validation of compliance to PCI DSS v4 or above?

B7

(Only if Yes to B5) Does your organisation have a defined process for managing and monitoring Third-Party Service Providers (TPSP) for PCI DSS compliance?

B8

Does your organisation have any other certifications or audit reports that cover information security (such as a SOC 2 report)?

HR Security (2 questions)

Control

Question

C1

Does your organisation perform background checks on staff and contractors?

C3

Do employees and contractors receive an information security and data protection training programme?

IT Operations (16 questions)

Control

Question

D4

Does your organisation have a process for editing or removing employee access to systems and information when they change role or leave?

D6

Does your organisation enforce multi-factor authentication on all remotely accessible services?

D12

Do all of your organisation's systems automatically lock after a short period of inactivity?

D14

Does your organisation use/provision a password manager?

D17

Do all systems have their default credentials changed on installation or provision?

D19

Does your organisation use anti-malware controls, such as EDR, to protect all endpoints and internal IT infrastructure?

D20

Does your organisation have procedures to control the installation of software on IT production systems?

D21

Does your organisation have procedures to control the installation of software on user endpoint systems?

D22

Does your organisation enforce full-disk encryption on all organisation-provisioned endpoint devices?

D24

Does your organisation allow staff to access company data or services from employee-owned devices?

D26

(Only if yes to D24) Can your organisation perform a remote wipe of organisation data on all BYOD endpoint devices?

D27

Does your organisation encrypt client data on its IT systems using appropriate cryptographic standards?

D29

Does your organisation ensure that all IT systems are regularly patched with security patches?

D30

Does your organisation use any applications, operating systems or hardware no longer supported by the vendor?

D31

Does your organisation ensure used digital media is disposed of securely with certificates of destruction?

D32

Does your organisation take regular immutable backups of its digital production data?

D38

Does your organisation use email security controls to detect, filter or quarantine malicious inbound email?

Software Development (4 questions)

Control

Question

Scoping Question

Does your organisation develop any software or apps?

E2

Does your organisation have a documented and approved SDLC process that includes security input?

E7

Does your organisation conduct appropriate security testing as part of your development lifecycle?

E10

Does your organisation ensure that all apps it builds are maintained with regular security patches?

Network & Cloud Security (3 questions)

Control

Question

Scoping Question

Does your organisation run any of its own servers, networks or cloud systems?

F1

Are all ingress and egress points for traffic through your network or cloud environment protected by firewalls?

F9

Does your organisation have any controls to protect against Denial of Service (DoS/DDoS) attacks?

Business Resilience (1 question)

Control

Question

H1

Does your organisation have a documented Incident Response Plan?

Supply Chain Management (1 question)

Control

Question

I5

Does your organisation conduct security due diligence against suppliers before entering into a contract?

Data Protection (4 questions)

Ref

Question

Scoping

Does your organisation collect, process, or store personal data, other than that of your own employees?

J1

(Multi-select) Which countries do you store personal data in, or transfer personal data to?

J5

Does your organisation have an up-to-date Data Protection Policy?

J13

Has your organisation suffered a security incident that led to a Personal Data breach in the last 6 months?

Artificial Intelligence (3 questions)

Ref

Question

K2

Does your organisation use Machine Learning or Generative AI models for internal use-cases?

K8

Does your organisation embed Machine Learning or Generative AI capabilities within any service(s) you provide to clients?

K17

Is client data otherwise exposed to Machine Learning or Generative AI models outside of the direct AI-enabled service(s) your client has purchased?


💡 If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.

Did this answer your question?