CAIQ-Lite 4.0.3

0 / 8

Free CAIQ-Lite questionnaire tool

What is CAIQ-Lite?

CAIQ-Lite is the shortened edition of the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire. It keeps the same control domains as the full CAIQ but asks a reduced set of yes/no questions, so a cloud provider can publish a security self-assessment without working through the several hundred questions of the full version.

Who needs to fill out a CAIQ-Lite questionnaire?

Software and cloud vendors fill out CAIQ-Lite when a prospect, customer or procurement team asks for a security self-assessment, when they list in the CSA STAR registry, or when they want a standard answer set to reuse across inbound security reviews. Buyers read the completed questionnaire to compare vendors against the Cloud Controls Matrix.

What does CAIQ-Lite cover?

CAIQ-Lite maps to the Cloud Controls Matrix domains, including audit and assurance, application and interface security, business continuity management, cryptography and key management, and data security and privacy. Every question is answered yes, no, not applicable, partially or planned, with optional notes.

Is this CAIQ-Lite tool free?

Yes. Answering the questionnaire in your browser and exporting your responses as CSV are free, and you do not need an account. Your answers stay in the page and are never sent to Wolfia.

Sections in this questionnaire

  • Audit & Assurance: 3 questions
  • Application & Interface Security: 4 questions
  • Business Continuity Management: 3 questions
  • Cryptography & Key Management: 2 questions
  • Data Security & Privacy: 1 questions

Questions reproduced from the Cloud Security Alliance CAIQ-Lite v4, © Cloud Security Alliance, used for reference. Download the official questionnaire from CSA.

Audit & Assurance

Independent Assessments

A&A-02.1

Are independent audit and assurance assessments conducted according to relevant standards at least annually?

A&A-02.2

Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit?

Application & Interface Security

Application Security Baseline Requirements

AIS-02.1

Are baseline requirements to secure different applications established, documented, and maintained?

Application Vulnerability Remediation

AIS-07.1

Are application security vulnerabilities remediated following defined processes?

Business Continuity Management

Business Continuity Planning

BCR-01.1

Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?

Backup and Recovery

BCR-08.1

Is cloud data periodically backed up?

Cryptography & Key Management

Encryption and Key Management

CEK-01.1

Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?

Data Security & Privacy

Data Protection

DSP-07.1

Are systems, products, and business practices based on security principles by design and per industry best practices?