Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Vendor Security Assessment

ASecurity

Drafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor responses become binding contractual representations with executive certification. Use during vendor due diligence, third-party risk management, procurement security review, or subprocessor evaluation.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
businessrustgoawstestingdatabasesecurity

Works with

cli

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill vendor-security-assessment --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vendor Security Assessment?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Vendor Security Assessment
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-vendor-security-assessment/badge)](https://www.skillsdirectory.com/skills/lev-os-vendor-security-assessment)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: vendor-security-assessment
description: Drafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor responses become binding contractual representations with executive certification. Use during vendor due diligence, third-party risk management, procurement security review, or subprocessor evaluation.
---

# Vendor Security Assessment Questionnaire

Generates a pre-contract due-diligence questionnaire for evaluating vendor security controls, data practices, and compliance across GDPR, CCPA, HIPAA, SOX, GLBA, FERPA, and industry frameworks.

## Quick Start

Gather before drafting:
1. **Vendor scope** — data types accessed (PII, PHI, PCI, financial, proprietary), processing activities, data flows
2. **Applicable regulations** — GDPR, CCPA, HIPAA, SOX, GLBA, FERPA, or sector-specific
3. **Risk tolerance** — what constitutes acceptable vs. disqualifying vendor risk
4. **Contract alignment** — security provisions to incorporate by reference

## Document Framework

| Element | Requirement |
|---|---|
| Preamble | Completion mandatory pre-contract; responses are binding representations |
| Executive certification | Senior officer (CISO/CTO/CLO) attests accuracy; signature block required |
| Submission deadline | 10–15 business days |
| Change notification | Vendor notifies within 5 business days of material security changes |
| Confidentiality | Questionnaire and responses treated as confidential business information |

## Assessment Domains

Draft numbered questions per domain. Each question includes a response field and evidence-request field where applicable. Tailor scope to data sensitivity — not every vendor needs every domain.

**1. Information Security Governance**
- Dedicated CISO/equivalent; certifications (CISSP, CISM, CISA)
- Framework alignment (NIST CSF, ISO 27001, CIS Controls, COBIT)
- Policy review cadence; security awareness training (all-staff + specialized)
- Board-level security reporting frequency

**2. Data Classification & Lifecycle**
- Classification taxonomy compatibility with client's scheme
- All data storage/processing locations (primary, DR, backup, cloud regions)
- Cross-border transfer mechanisms (SCCs, adequacy decisions, BCRs)
- Retention post-termination; destruction methods; certificates of destruction
- Backup frequency; encrypted backup media; tested RTO/RPO

**3. Access Control & Privileged Access**
- MFA enforcement across all access; supported factors
- RBAC, least-privilege, segregation of duties
- Privileged access: JIT elevation, session recording, auto-deprovisioning
- Access recertification frequency; anomalous-access alerting

**4. Vulnerability Management & Testing**
- Scanning tools, frequency, and patching SLAs:

| Severity | Patch SLA |
|---|---|
| Critical | ≤ 24–72 hrs |
| High | ≤ 7 days |
| Medium | ≤ 30 days |
| Low | ≤ 90 days |

- Annual third-party pentests (external + internal lateral movement)
- AppSec testing (SAST, DAST, SCA) for custom software
- Bug bounty / responsible disclosure program
- Request most recent pentest summary and remediation status

**5. Incident Response & Business Continuity**
- Documented IR plan with roles, escalation, communication protocols
- IR testing frequency (tabletop, simulations) and recent results
- Notification timeline — must allow client to meet most restrictive regulatory deadline (GDPR 72 hrs, HIPAA 60 days, state breach laws)
- Cooperation with client IR team and legal counsel
- Cyber insurance: policy limits, third-party liability, adequacy for data volume
- BCP/DR: tested RTO/RPO, geographic diversity, multi-scenario resilience

**6. Encryption & Key Management**
- At rest: minimum AES-256; scope includes production, dev/test, backups, portable media
- Database encryption approach (TDE, column-level, application-layer)
- In transit: TLS versions, deprecated protocol status, enforced cipher suites
- In use: confidential computing / secure enclave capabilities (if applicable)
- Key management: HSM/KMS storage, rotation frequency, secure destruction

**7. Network Security & Segmentation**
- Customer isolation; production vs. corporate separation
- Zero-trust architecture status
- Perimeter controls: firewalls, IDS/IPS, WAF, DDoS protection
- Remote access: VPN, NAC/device posture, MFA
- Assessment cadence (external scans, internal pentests, wireless)

**8. Subprocessor Risk Management**
- Complete subprocessor inventory: role, data access, location, assessments conducted
- Flow-down of security requirements (contractually at least as stringent as client's)
- Client notification and approval rights before new subprocessor engagement
- Right to terminate non-compliant subprocessors

**9. Certifications & Compliance**
- SOC 2 Type II: report date, principles, opinion status, scope alignment
- ISO 27001: certificate dates, scope, certification body
- PCI DSS, FedRAMP/StateRAMP, HITRUST, TISAX (as applicable)
- Regulatory compliance confirmation for applicable data types
- Commitment to provide updated reports/certifications annually

**10. Physical Security & Environmental Controls**
- Data center access: MFA, visitor logs, surveillance, security personnel
- Background checks for personnel with physical access
- Environmental: fire suppression, UPS, generators, climate, water detection
- Facility certifications (SSAE 18 SOC 1, Uptime Institute tier)

**11. HR Security & Insider Threat**
- Background checks; periodic re-investigation for sensitive roles
- Security training before access; policy acknowledgment
- Offboarding: access revocation timeline, exit procedures
- Insider threat monitoring; DLP for exfiltration prevention

## Risk Assessment Framework

Score vendor responses after receipt:

| Rating | Criteria |
|---|---|
| Low | Controls meet/exceed requirements; evidence provided |
| Moderate | Minor gaps; addressable via contractual provisions |
| High | Significant gaps; requires remediation plan with deadlines |
| Critical | Fundamental deficiencies; disqualifying absent remediation |

Assessment report must include:
- Per-domain and overall risk rating with justification
- Recommended contractual controls (audit rights, insurance minimums, SLAs)
- Evidence gaps requiring follow-up
- Go/no-go recommendation with conditions
- Flagged inconsistencies between responses and publicly available information

## Checks

- State explicitly in preamble: responses are **contractually binding representations**; incomplete/misleading answers constitute grounds for disqualification or material breach
- Align notification timelines with the **most restrictive applicable breach notification law**
- Mark questions as required vs. conditional based on data type (PCI questions only if payment data involved)
- Flag vendors refusing to disclose subprocessors or share certifications as elevated risk
- All legal citations to specific regulatory provisions must be verified against current law [VERIFY]

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →