In this article:
We have sunsetted Atlas. Use the Questionnaires tool for all your questionnaire management operations.
Go to Questionnaires
In the platform, select Questionnaires from the Core Tools drop-down menu.
Note: On July 5, 2023, we renamed the Assessments tool as Questionnnaires.
Start a review
- In Questionnaires, click the Sent tab to see all the questionnaires your organization has sent to vendors.
- Scan the table for a questionnaire that you want to review, and see if it has a Ready for review status. Then click Begin review.
Tip: To find a reviewable questionnaire faster, sort on the Status column to see all questionnaires that are ready for review listed together.
- In the first page of the questionnaire, click Begin review.
Review a question
Check the response for a question and then do any of the following actions:
- Click Done to accept the answer.
- Click Flag to call the vendor's attention to the question if you are not satisfied with the answer or have a concern.
- To send a message to the vendor about their answer to the question, click More...
...then type your message and click Send. - To assign the question or the entire category of questions to another reviewer in your organization, click Assign question and then select the reviewer.
- To see who answered the question, click Answer history.
Tip: See if there are any security issues related to the question. These can help you assess whether the answer is accurate or get deeper context about the how the vendor is handling a particular control or security practice. Issues are grouped by factor.
- If the vendor attached any documents, click them to review their contents for additional context.
Go to another question
After reviewing a question response, go to another question in one of the following ways:
- Click Next to see the next question in sequence.
- Use the right scroll bar to scroll between questions.
- Use the left navigation panel to select a specific question or category to review.
Accept the questionnaire or send it back
After completing the questionnaire review:
- Click Send back for completion if you are not satisfied with any answers.
- Click Accept/Close if you are satisfied with the all of the vendor's answers.
If you choose to send back the questionnaire, select reasons and provide a message for additional context, to help the vendor address your concerns. Then, click Send.
The vendor receives a notification email about your review.
Use validation scores to prioritize questionnaires for review
Customized questionnaire include a validation score that reflects good security security controls as defined in the questionnaire template. As a best practice, prioritize reviewing questionnaires with higher validation scores.
Note: Validation scores only appear on questionnaires that you customize using a Microsoft Excel spreadsheet that you can download. Learn more about creating custom templates in Excel.
How validation scores work
We calculate a validation score by weighing Yes, No, and multiple-choice responses that indicate positive security controls to increase the score or negative responses to decrease the score.
For example, a Yes answer might be 20 points and a No might be -20 points for the question Do you use multifactor authentication?
We calculate the points as a percentage, with 100 percent being a perfect score.
We start displaying the validation score when the vendor completes 10 percent of the questionnaire.
You can assign your own point scale for questions. Otherwise, we apply the following scale by default:
- Yes [+200]
- N/A [+100]
- No [+0]
- Unanswered [0]
- Attachment provided [+50]
See a questionnaire's validation score
- Find and select questionnaire in the Sent tab of the Questionnaires tool.
- View the score in the questionnaire summary.