PONOPT FIELD NOTES · Закупки и vendor management

A Practical Cybersecurity Questionnaire for Physical-Infrastructure Vendors

A short, framework-mapped questionnaire for vetting physical-infrastructure vendors (CCTV, access control, IoT): what to ask, how to score, and how to verify.

A short questionnaire is your first control, not the final answer. It should test the risks your site inherits from physical systems that are now networked devices: default credentials on cameras and controllers, unpatched firmware, open remote access, unnamed sub-vendors, and thin incident response. Tier vendors by criticality, keep the tool to one scored page, and treat self-reported answers as claims you validate with evidence and contract clauses before relying on them.

Key takeaways

  • Physical-infrastructure products such as cameras, access controllers, and perimeter sensors are networked devices; their security posture is a cyber risk even though the asset looks physical.
  • Tier vendors by how much access they get to your site and data before you pick which questionnaire to send; not every vendor needs the full tool.
  • A short questionnaire concentrates on five blocks: device hygiene, credentials and access, network segmentation, supply chain transparency, and incident response.
  • Self-assessments are claims, not proof; require evidence, run verification checks, and put the agreed posture into the contract and service level.
  • Standards such as NIST SP 800-161 and CISA's Vendor SCRM template give a defensible mapping and common vocabulary for both parties.
  • A vendor questionnaire cannot detect firmware tampering or insider behavior; combine it with on-site sampling, monitoring, and a realistic residual-risk decision.

Why a camera or access controller is a cyber risk

A physical-infrastructure vendor does not merely install hardware; it hands you internet-connected systems that sit on your network and watch your site. Video cameras, door controllers, turnstiles, intercoms, and perimeter sensors run embedded software, hold credentials, and communicate over the network. Once connected, an unpatched device with a default password is a legitimate network presence an attacker can move through, regardless of how strong the door lock is.

Cyber supply chain risk management therefore treats the procurement of such components as an assessment of the supplier and the product together. NIST SP 800-161 frames this as evaluating the full chain from design to integration and deployment, while CISA's Vendor SCRM template groups the questions into governance, information security, physical security, personnel security, and resilience. Your questionnaire is the practical way to bring that framework down to one purchase decision.

Design the tool: tier first, then ask

The most common mistake is sending a 300-question bank to every integrator. That produces delayed, generic answers and trains vendors to say yes to everything. Instead, decide what the vendor actually touches before drafting questions.

A maintenance-only contractor with badge access to a mechanical room poses a different risk than the integrator that configures your video management server, holds admin credentials, and connects your perimeter sensors to the office network. Categorize vendors as high, medium, or low by the data they can reach, the systems they administer, and whether they work on a continuously connected basis. Reserve the full questionnaire for high and medium tiers; let low-tier vendors answer a five-question screening.

The five blocks that carry the risk

Keep the questionnaire to one page by focusing on the controls that most directly affect physical systems. Each block is scored yes, partially, or no, with a short evidence field.

The first block is device and firmware hygiene: how the vendor tracks the software versions of cameras, controllers, and gateways it supplies, how it learns about vulnerabilities, and how quickly it can deliver a tested patch. The second is credentials and access: whether default passwords are changed at commissioning, whether administrative accounts use multi-factor authentication, and who holds the master credentials.

The third block is network behavior: segmentation of video and control traffic from the business network, whether devices can reach the internet, and logging of who connects. The fourth is supply chain transparency: named sub-contractors, the origin of firmware and hardware, and whether a controlled bill of materials exists so that components received or repaired in transit are not silently substituted. The fifth is response and handover: how the vendor detects an incident on the systems it manages, who you call, and what documentation and recovery support it leaves behind.

  • Do default credentials get changed at commissioning, and are they unique per device?
  • Are admin and maintenance accounts protected with multi-factor authentication, with role separation?
  • Are video, access-control, and building-management networks segmented from the office network?
  • How does the vendor learn about firmware vulnerabilities and deliver tested patches, and in what time frame?
  • Can the vendor name its sub-contractors and provide a controlled bill of materials for hardware and firmware?
  • Who holds root credentials, and is access logged and reviewed?
  • What happens on an incident: detection duties, notification window, and retained evidence?

Score the answers and verify the claims

A useful scoring model weights each block by the tier of the vendor and the sensitivity of the asset. For example, firmware patching and credential management typically carry the highest weight for an access-control integrator, while supply-chain transparency matters more for a vendor supplying edge hardware. Set a threshold below which you require a remediation plan, and mark answers that need follow-up rather than accepting them as final.

Verification matters because questionnaire answers describe intent, not reality. Ask for evidence: a patch-management policy, a certificate such as an ISO/IEC 27001-aligned statement of applicability, a network diagram, or audit results. Compare claims with observable signals, for example whether a vendor that promises disciplined patching can show a documented test cycle. For the highest tier, combine the questionnaire with an on-site sampling of one or two devices to check that factory defaults are actually gone and firmware is current.

Lock the posture into the contract

A questionnaire is only as durable as the obligation behind it. State in the procurement agreement that the vendor must maintain the controls it confirmed, define a notification window for security incidents affecting your systems, and specify what evidence it must produce on request and on re-assessment.

In regulated sectors this is not optional. For organizations in the Russian banking system, Bank of Russia standard STO BR IBBS-1.4-2018 sets expectations for managing information-security risk when substantial functions are outsourced, including periodic assessment of the service provider and duties that survive the handover. Even outside banking, the same principle applies: outsourcing work does not transfer your accountability for the security of your site and data.

Limitations you should name openly

A vendor questionnaire cannot detect a compromised build, a malicious insider, or a backdoored component, and it cannot see how a vendor actually behaves on site. It is a screening instrument that reduces, but does not eliminate, risk.

Be equally clear about what the tool is not. It does not replace an on-site audit, penetration testing, or continuous monitoring of the systems once installed. Where uncertainty remains after scoring, record the residual risk and decide deliberately, rather than assuming a clean questionnaire means a safe deployment.

One-page vendor questionnaire with a weighted scoring key

Use this compact tool as your template. Ask only the questions that apply to the vendor's tier, score each block with the indicated weight, and record evidence in the notes column. Treat any block below 50% as a condition for follow-up or a remediation plan.

  1. Tier the engagement: high (full admin + network/recording access), medium (config/service with local access), low (one-off hardware or site visit). [governs tool depth]
  2. Device hygiene (weight 25): Are default credentials changed at commissioning and unique per device, and is firmware patched on a documented, tested cycle with known timelines?
  3. Credentials and access (weight 25): Are admin and maintenance accounts protected by multi-factor authentication, with role separation and logged, reviewed access?
  4. Network behavior (weight 20): Are video, access-control, and building systems segmented from the business network and denied direct internet egress where not required?
  5. Supply chain transparency (weight 15): Can the vendor name sub-contractors and provide a controlled bill of materials for hardware, firmware, and repaired units?
  6. Incident response and handover (weight 15): Does the vendor detect incidents on managed systems, notify you within a defined window, and hand over documentation and recovery support?
  7. Evidence request: Attach patch-management policy, network diagram, or ISO/IEC 27001 statement of applicability for every high-weight 'yes'.
  8. Scoring rule: weighted total under 70% triggers a written remediation plan; under 50% escalates to a site audit or exclusion.
  9. Contract clause: confirm the vendor must maintain confirmed controls, notify you of incidents affecting your systems, and produce evidence on re-assessment.

Questions people ask

Should I send the same questionnaire to every vendor?

No. Sending one long tool to every vendor produces slow, generic answers. Tier vendors by the data they can reach, the systems they administer, and whether they work continuously. High- and medium-tier vendors get the full scored questionnaire; low-tier vendors who only deliver hardware or visit a site once can answer a short screening of five questions. This keeps the burden proportional to actual risk.

How short is a short questionnaire for this kind of vendor?

Aim for roughly fifteen to twenty scored questions grouped into five blocks: device and firmware hygiene, credentials and access, network segmentation, supply-chain transparency, and incident response and handover. If every block is covered by three or four concrete yes-or-no questions with an evidence field, you can keep the tool to one or two pages while still covering the risks that actually matter.

A vendor says it cannot answer detailed cyber questions. What should I do?

That answer is itself a finding. A vendor providing networked physical security systems should be able to state who holds credentials, how firmware is patched, and who its sub-contractors are. If the vendor genuinely cannot answer, document the gap, decide whether the residual risk is acceptable for the tier of access being granted, and consider a lower-scope deployment, added monitoring, or exclusion. Do not accept 'no answer' as a passing result.

Which frameworks should I map the questions to?

The most useful anchors are NIST SP 800-161 for cyber supply chain risk management, CISA's Vendor SCRM template with its seven categories (governance, information security, physical security, personnel security, integrity, and resilience), and ISO/IEC 27001-based management evidence. Mapping to these lets both parties use a common vocabulary and gives you a defensible basis if a risk decision is later questioned.

Is a self-assessment questionnaire enough, or do I need an on-site audit?

A questionnaire is not enough on its own for high-risk vendors. It tells you what the vendor intends, not what is actually configured. Validate key claims with evidence such as patch-management policies and network diagrams, and for the highest tier sample one or two installed devices on site to confirm that factory defaults are gone and firmware is current. Audits and monitoring complement, rather than replace, the questionnaire.

How do I weigh physical-security answers against cyber answers?

Treat them as linked rather than separate. A vendor with excellent perimeter fencing but default passwords on controllers fails overall, because the networked device is the weakest link an attacker can reach remotely. Score the cyber blocks for networked assets and the physical blocks for how people and hardware are protected, then combine them with weights that reflect which systems are most exposed and most critical to your operation.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. Procuring Safe and Secure ICT Products and Services Fact SheetCybersecurity and Infrastructure Security Agency (CISA)
  2. ICT SCRM Task Force Vendor TemplateCybersecurity and Infrastructure Security Agency (CISA)
  3. NIST SP 800-161 Rev. 1: Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsNational Institute of Standards and Technology (NIST)
  4. Vendor Risk Assessment Questionnaire Template: A Comprehensive GuideUpGuard
  5. Стандарт Банка России СТО БР ИББС-1.4-2018: Обеспечение информационной безопасности организаций банковской системы РФ. Управление риском нарушения информационной безопасности при аутсорсингеГАРАНТ / Банк России
  6. Приказ Росстандарта от 08.08.2017 N 822-ст об утверждении ГОСТ Р 57580.1-2017Legalacts.ru (Росстандарт)