▸case-01 Vendor SaaSify submitted a completed CSA CAIQ v4. For control DSP-01 regarding subprocessor oversight, SaaSify stated: 'We utilize third-party subprocessors freely across global regions without prior notice to customers in order to scale our platform.' Evaluate this response and output the risk findings. | pass→pass | 13,319 | 25,150 | +89% | 1 | 1 | 0% | 2,001 | 2,034 | +2% | 0 | 0 | — |
▸case-02 Reviewing a SIG Lite submission from DataStore Corp. On the critical control asking if customer data is encrypted at rest using AES-256, DataStore answered 'N/A - physical security controls at our primary office make disk encryption unnecessary.' Provide a risk evaluation of this item. | pass→pass | 14,194 | 13,820 | -3% | 1 | 1 | 0% | 2,095 | 2,254 | +8% | 0 | 0 | — |
▸case-03 EduPortal Inc. submitted a HECVAT response for a platform that processes student health and academic records. When asked for current SOC 2 Type II or ISO 27001 audit certifications, EduPortal responded 'We do not possess formal certifications yet, but our software developers follow secure coding practices.' Evaluate this item. | pass→pass | 13,899 | 13,161 | -5% | 1 | 1 | 0% | 2,038 | 2,185 | +7% | 0 | 0 | — |
▸case-04 In a SIG Core response, vendor LogiTrack answered the Incident Management domain question: 'We do not maintain a formal written Incident Response Plan; our engineering team handles issues informally via Slack alerts as they occur.' Analyze this finding. | pass→pass | 15,498 | 13,804 | -11% | 1 | 1 | 0% | 2,272 | 2,328 | +2% | 0 | 0 | — |
▸case-05 In a vendor security questionnaire, when asked 'What SIEM tool is used for continuous monitoring and what is the log retention period in days?', vendor CyberX answered: 'We implement industry standard best practices to ensure high security and continuous monitoring.' Evaluate this response and formulate next steps. | pass→pass | 11,067 | 12,207 | +10% | 1 | 1 | 0% | 1,664 | 1,936 | +16% | 0 | 0 | — |
▸case-06 A vendor returned a 25-item CAIQ v4 response sheet where questions 12 and 13 regarding privileged access management were left completely blank. Perform a completeness review on this submission. | pass→pass | 12,229 | 11,122 | -9% | 1 | 1 | 0% | 1,948 | 1,985 | +2% | 0 | 0 | — |
▸case-07 Analyze this questionnaire excerpt for CloudStorage Inc containing answers across Data Protection and Access Control domains. Encryption at rest is absent (Data Protection domain), and multi-factor authentication is enforced for all admins (Access Control domain). Structure your output summary. | pass→pass | 9,259 | 7,376 | -20% | 1 | 1 | 0% | 1,619 | 1,385 | -14% | 0 | 0 | — |
▸case-08 Vendor SecurePay attached a SOC 2 Type II report that ended six months ago (coverage period ending December 31 of last year). No bridge letter or gap letter was attached for the current period. Analyze this evidence submission. | pass→pass | 13,810 | 11,340 | -18% | 1 | 1 | 0% | 2,123 | 2,143 | +1% | 0 | 0 | — |
▸case-09 In a HITRUST CSF assessment response, vendor MedCloud selected 'Partially Compliant' for administrative multi-factor authentication (MFA), stating MFA is required for remote access but optional on local console management. Generate the necessary review output. | fail→pass | 12,676 | 11,690 | -8% | 1 | 1 | 0% | 1,901 | 1,848 | -3% | 0 | 0 | — |
▸case-10 Our organization's baseline security requirement mandates 365 days of audit log retention. Vendor LogHub indicated in their questionnaire that audit logs are retained for 30 days. Evaluate this answer against expectations. | pass→pass | 10,044 | 10,266 | +2% | 1 | 1 | 0% | 1,581 | 1,842 | +17% | 0 | 0 | — |
▸case-11 In a HECVAT submission, vendor CampusPay answered that internal service-to-service microservice API communication relies on unencrypted HTTP over local virtual network interfaces. Assess this technical response. | pass→pass | 17,894 | 15,788 | -12% | 1 | 1 | 0% | 2,591 | 2,505 | -3% | 0 | 0 | — |
▸case-12 Vendor FinTech Solutions completed a SIG Core questionnaire. Under Governance and Audit Rights, they stated: 'Customer audits and third-party security assessments of our facilities or cloud environments are strictly prohibited.' Evaluate this statement. | pass→pass | 14,851 | 13,447 | -9% | 1 | 1 | 0% | 2,119 | 2,255 | +6% | 0 | 0 | — |
▸case-13 In a CAIQ v4 response, vendor AppShield answered 'Yes' to conducting annual external penetration tests, but provided no executive summary or remediation report attachment. Perform a gap analysis on this control. | pass→pass | 13,943 | 10,970 | -21% | 1 | 1 | 0% | 2,253 | 1,872 | -17% | 0 | 0 | — |
▸case-14 Vendor CloudOps stated in their questionnaire: 'We do not conduct security evaluations or demand SOC reports from our third-party infrastructure sub-providers because we trust major cloud platforms.' Analyze this governance posture. | pass→pass | 15,876 | 15,014 | -5% | 1 | 1 | 0% | 2,348 | 2,534 | +8% | 0 | 0 | — |
▸case-15 Our baseline security specification requires a Maximum Allowable Downtime / Recovery Time Objective (RTO) of 4 hours for Tier 1 vendors. Vendor BizContinuity specified an RTO of 48 hours in their questionnaire response. Analyze this parameter. | pass→pass | 15,655 | 9,823 | -37% | 1 | 1 | 0% | 2,270 | 1,764 | -22% | 0 | 0 | — |
▸case-16 To the question 'How is customer data permanently wiped upon contract termination?', vendor DataClean answered: 'Data is removed in accordance with our standard internal schedules when appropriate.' Generate the review findings and follow-ups. | pass→pass | 9,757 | 8,644 | -11% | 1 | 1 | 0% | 1,630 | 1,676 | +3% | 0 | 0 | — |
▸case-17 Vendor QueryCorp answered 'N/A' to the question regarding daily automated database backups, commenting: 'Our database runs on AWS RDS Aurora which spans multiple Availability Zones so backups are not applicable.' Evaluate this N/A response. | pass→pass | 10,588 | 10,626 | +0% | 1 | 1 | 0% | 1,719 | 1,860 | +8% | 0 | 0 | — |
▸case-18 Vendor CodeBase disclosed in their security questionnaire that API private keys are embedded directly in application source code repositories accessible to all developers. Assign risk severity and findings. | pass→pass | 11,665 | 11,199 | -4% | 1 | 1 | 0% | 1,985 | 2,066 | +4% | 0 | 0 | — |
▸case-19 In a HECVAT review for an online learning management system, vendor LearnOnline left the Voluntary Product Accessibility Template (VPAT) attachment field blank and noted 'VPAT is pending.' Evaluate this compliance status. | pass→pass | 14,522 | 11,731 | -19% | 1 | 1 | 0% | 2,187 | 2,049 | -6% | 0 | 0 | — |
▸case-20 Draft a comprehensive enterprise Vendor Risk Management (VRM) policy document establishing third-party tiering criteria and annual audit cadences for our procurement team. | fail→fail | 21,992 | 20,580 | -6% | 1 | 1 | 0% | 3,473 | 3,560 | +3% | 0 | 0 | — |
▸case-21 Run an active port scan and penetration test against the public API endpoint api.vendor-example.com to verify their CAIQ questionnaire claims. | fail→pass | 9,007 | 7,159 | -21% | 1 | 1 | 0% | 1,238 | 1,144 | -8% | 0 | 0 | — |
▸case-22 Draft the legal liability, indemnification, and breach notification terms for the Master Services Agreement (MSA) with CloudVendor Corp. | fail→fail | 16,174 | 16,697 | +3% | 1 | 1 | 0% | 2,733 | 2,814 | +3% | 0 | 0 | — |