Summary
The Controls Framework has two sizes: Small and Full.
This article lists every question that is included in the Small Framework, grouped by domain, so you can quickly see the scope of what a supplier on the Small Framework will be asked.
Security Governance (7 questions)
Control | Question |
A3 | Does your organisation have a documented Cybersecurity Policy or Information Security Policy? |
A10 | Does your organisation have a Password Policy that is technically enforced throughout its IT estate? |
A11 | Does your organisation have a documented Backup Policy? |
A13 | Does your organisation prevent the use of removable media, and is this enforced technically? |
A14 | (Only if No to A13) If the use of removable media is not prohibited and enforced technically, is its use subject to other compensatory controls? |
A19 | Does your organisation restrict employee access to business information based upon the principle of least privilege? |
A26 | Does your organisation use threat intelligence to inform decisions about information security?
|
Security Certifications (8 questions)
Control | Question |
B1 | Is your organisation Cyber Essentials certified? (plus expiry date sub-question) |
B2 | (Only if Yes to B1) Is your organisation Cyber Essentials Plus certified? (plus expiry date sub-question) |
B3 | Is your organisation ISO 27001 certified? (plus expiry date sub-question) |
B4 | Is your organisation aligned with the NIST Cybersecurity Framework? |
B5 | Does your organisation store, process, transmit or otherwise have the ability to impact the security of cardholder data (CHD) or sensitive authentication data (SAD)? |
B6 | (Only if Yes to B5) Has your organisation performed validation of compliance to PCI DSS v4 or above? |
B7 | (Only if Yes to B5) Does your organisation have a defined process for managing and monitoring Third-Party Service Providers (TPSP) for PCI DSS compliance? |
B8 | Does your organisation have any other certifications or audit reports that cover information security (such as a SOC 2 report)? |
HR Security (2 questions)
Control | Question |
C1 | Does your organisation perform background checks on staff and contractors? |
C3 | Do employees and contractors receive an information security and data protection training programme? |
IT Operations (16 questions)
Control | Question |
D4 | Does your organisation have a process for editing or removing employee access to systems and information when they change role or leave? |
D6 | Does your organisation enforce multi-factor authentication on all remotely accessible services? |
D12 | Do all of your organisation's systems automatically lock after a short period of inactivity? |
D14 | Does your organisation use/provision a password manager? |
D17 | Do all systems have their default credentials changed on installation or provision? |
D19 | Does your organisation use anti-malware controls, such as EDR, to protect all endpoints and internal IT infrastructure? |
D20 | Does your organisation have procedures to control the installation of software on IT production systems? |
D21 | Does your organisation have procedures to control the installation of software on user endpoint systems? |
D22 | Does your organisation enforce full-disk encryption on all organisation-provisioned endpoint devices? |
D24 | Does your organisation allow staff to access company data or services from employee-owned devices? |
D26 | (Only if yes to D24) Can your organisation perform a remote wipe of organisation data on all BYOD endpoint devices? |
D27 | Does your organisation encrypt client data on its IT systems using appropriate cryptographic standards? |
D29 | Does your organisation ensure that all IT systems are regularly patched with security patches? |
D30 | Does your organisation use any applications, operating systems or hardware no longer supported by the vendor? |
D31 | Does your organisation ensure used digital media is disposed of securely with certificates of destruction? |
D32 | Does your organisation take regular immutable backups of its digital production data? |
D38 | Does your organisation use email security controls to detect, filter or quarantine malicious inbound email? |
Software Development (4 questions)
Control | Question |
Scoping Question | Does your organisation develop any software or apps? |
E2 | Does your organisation have a documented and approved SDLC process that includes security input? |
E7 | Does your organisation conduct appropriate security testing as part of your development lifecycle? |
E10 | Does your organisation ensure that all apps it builds are maintained with regular security patches? |
Network & Cloud Security (3 questions)
Control | Question |
Scoping Question | Does your organisation run any of its own servers, networks or cloud systems? |
F1 | Are all ingress and egress points for traffic through your network or cloud environment protected by firewalls? |
F9 | Does your organisation have any controls to protect against Denial of Service (DoS/DDoS) attacks? |
Business Resilience (1 question)
Control | Question |
H1 | Does your organisation have a documented Incident Response Plan? |
Supply Chain Management (1 question)
Control | Question |
I5 | Does your organisation conduct security due diligence against suppliers before entering into a contract? |
Data Protection (4 questions)
Ref | Question |
Scoping | Does your organisation collect, process, or store personal data, other than that of your own employees? |
J1 | (Multi-select) Which countries do you store personal data in, or transfer personal data to? |
J5 | Does your organisation have an up-to-date Data Protection Policy? |
J13 | Has your organisation suffered a security incident that led to a Personal Data breach in the last 6 months? |
Artificial Intelligence (3 questions)
Ref | Question |
K2 | Does your organisation use Machine Learning or Generative AI models for internal use-cases? |
K8 | Does your organisation embed Machine Learning or Generative AI capabilities within any service(s) you provide to clients? |
K17 | Is client data otherwise exposed to Machine Learning or Generative AI models outside of the direct AI-enabled service(s) your client has purchased? |
đĄ If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.
