Free CAIQ-Lite questionnaire tool
What is CAIQ-Lite?
CAIQ-Lite is the shortened edition of the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire. It keeps the same control domains as the full CAIQ but asks a reduced set of yes/no questions, so a cloud provider can publish a security self-assessment without working through the several hundred questions of the full version.
Who needs to fill out a CAIQ-Lite questionnaire?
Software and cloud vendors fill out CAIQ-Lite when a prospect, customer or procurement team asks for a security self-assessment, when they list in the CSA STAR registry, or when they want a standard answer set to reuse across inbound security reviews. Buyers read the completed questionnaire to compare vendors against the Cloud Controls Matrix.
What does CAIQ-Lite cover?
CAIQ-Lite maps to the Cloud Controls Matrix domains, including audit and assurance, application and interface security, business continuity management, cryptography and key management, and data security and privacy. Every question is answered yes, no, not applicable, partially or planned, with optional notes.
Is this CAIQ-Lite tool free?
Yes. Answering the questionnaire in your browser and exporting your responses as CSV are free, and you do not need an account. Your answers stay in the page and are never sent to Wolfia.
Sections in this questionnaire
- Audit & Assurance: 3 questions
- Application & Interface Security: 4 questions
- Business Continuity Management: 3 questions
- Cryptography & Key Management: 2 questions
- Data Security & Privacy: 1 questions
Questions reproduced from the Cloud Security Alliance CAIQ-Lite v4, © Cloud Security Alliance, used for reference. Download the official questionnaire from CSA.
Audit & Assurance
Independent Assessments
Are independent audit and assurance assessments conducted according to relevant standards at least annually?
Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit?
Application & Interface Security
Application Security Baseline Requirements
Are baseline requirements to secure different applications established, documented, and maintained?
Application Vulnerability Remediation
Are application security vulnerabilities remediated following defined processes?
Business Continuity Management
Business Continuity Planning
Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
Backup and Recovery
Is cloud data periodically backed up?
Cryptography & Key Management
Encryption and Key Management
Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
Data Security & Privacy
Data Protection
Are systems, products, and business practices based on security principles by design and per industry best practices?