Help us understand how you protect our information.

This questionnaire assists Ambrose Construct Group (ACG) in identifying and evaluating information security risks that may be associated with our external providers.

ACG is committed to maintaining the security of our information and managing risks in conformance with ISO 27001. The aim is to understand the information security risk profile of our vendors, improve ACG’s posture, and increase trust in how our information is handled.

Answer each item on behalf of your organisation. Where a question asks you to describe a control, a short factual answer is enough.

Section 01

Organisation information

Item 01

Organisation name

Item 02

Services provided to ACG

Summary of services provided by the vendor to ACG.

Item 03

Information security contact

The person ACG should speak to about this questionnaire and about security of ACG information.

Item 04

Storing ACG information

Will the vendor be storing information on behalf of ACG? If so, describe the type of information, where it is stored (geographic region), and whether that storage is cloud or on-premises.

Will you store ACG information?

Section 02

Information security management

Item 05

Compliance with standards

Does the vendor conform to any recognised information security standards, such as ISO 27001, PCI DSS, CSA Star, or the ASD Essential Eight? Has the vendor been formally certified against the standard?

Formal certification

Item 06

Information security policy

Does the vendor have an Information Security Policy?

Policy in place

Item 07

Asset management

Does the vendor have an Asset Management Policy? Briefly describe your approach to identifying, managing, and decommissioning hardware and software assets.

Item 08

Access control

Does the vendor have an Access Control Policy in place? Briefly describe your approach to providing, managing, reviewing, changing, and revoking access to systems that may store ACG information.

Item 09

Incident response

Does the vendor have a formal Incident Response Plan? Is the response plan regularly tested and improved? Does the response plan require the vendor to contact affected parties in the event of a security incident?

Formal incident response plan
Regularly tested and improved
Requires contact with affected parties

Section 03

Technical controls

Item 10

Patching

Describe how you ensure that applications and operating systems receive security patches in a timely manner.

Item 11

Antimalware

Describe the application control and/or antimalware controls that you have in place, and how you ensure that they remain current and effective.

Item 12

Access to ACG information

Describe how you can ensure that only authorised personnel can access ACG’s information.

Item 13

Multi-factor authentication

Is all remote Internet-accessible access into the applications and networks that store ACG’s information protected by multi-factor authentication?

MFA on remote access

Item 14

Encryption

Describe the forms of encryption used to protect client data and authentication credentials both in transit and at rest.

Item 15

Hardening

Describe how applications and systems used to access or manage ACG’s information are hardened against security vulnerabilities.

Item 16

Backups and continuity

Describe your approach to ensuring that the availability of ACG’s information, and your ability to continue to provide services, is assured. Are your business continuity and disaster recovery procedures tested and improved on a regular basis?

Business continuity and disaster recovery tested regularly

Section 04

Security validation

Item 17

Penetration testing

Are regular, independent penetration tests conducted against the vendor’s systems and networks, both external and internal? Are the results of penetration tests available to ACG for review?

Regular independent tests, external and internal
Results available to ACG for review

Item 18

Information security audits

Has the organisation undertaken independent audits of its approach to managing information security? Briefly describe the nature of such audits.

Independent audits undertaken

Section 05

Declaration

Item 19

Person completing this questionnaire

Item 20

Supporting documents

Optional. These files are stored in Supplier Questionnaire Supporting Docs, in a folder named after your organisation. PDF, Word, Excel, PowerPoint, text, and image files. 20 MB in total.

No documents selected.

Submit sends your answers to Ambrose Construct Group. Any documents are filed under your organisation name.