CAIQ (Consensus Assessments Initiative Questionnaire)
Definition
A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix (CCM) and addresses cloud-specific concerns including data residency, virtualisation security, and the shared responsibility model.
- Publisher
- Cloud Security Alliance (CSA)
- Maps to
- CSA Cloud Controls Matrix (CCM)
- Audience
- Cloud service providers specifically
- Covers
- Data residency, virtualisation security, shared responsibility
Common questions
How is the CAIQ different from a generic vendor security questionnaire?+
Generic questionnaires are often written for on-premises IT vendors and miss cloud-specific concerns. CAIQ questions are built around the CCM and specifically probe issues unique to cloud delivery, such as multi-tenant isolation, data residency across regions, and where the shared responsibility boundary sits between provider and customer.
How does an assessor typically use CAIQ responses in a due-diligence review?+
Responses are cross-checked against the vendor's actual certifications, such as SOC 2 or ISO 27001 reports, rather than accepted at face value, since CAIQ is a self-assessment questionnaire that the vendor completes about its own controls.
Related terms
- Audit Rights Clause
- A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
- Fourth-Party Risk
- The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
- Inherent Risk
- The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
- SIG (Standardised Information Gathering)
- A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business...
- SOC 2 Type II Report
- An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...