Standardised questionnaire by the Cloud Security Alliance for cloud providers.
The CAIQ is a questionnaire developed by the Cloud Security Alliance (CSA) that builds directly on the Cloud Controls Matrix. It translates the CCM's control domains into concrete yes/no questions regarding the implementation of security measures. Providers can submit a completed CAIQ to the public CSA STAR registry, thereby providing clients with a standardised form of evidence. The aim is to replace individual security questionnaires with a uniform, reusable standard.
For cloud and SaaS providers, the CAIQ is both a blessing and a curse: a recognised standard, but with hundreds of questions. Once completed thoroughly, it covers many client inquiries — yet clients still send their own customised questionnaires regardless. The same answers then have to be gathered and adapted time and again. Those who maintain a well-managed response base can complete the CAIQ and client-specific questionnaires using the same knowledge in a fraction of the time.
With Tendry, you complete the CAIQ and all derived client questionnaires from a verified knowledge base. This allows you to answer hundreds of security questions consistently, rather than working through them anew each time.