NoLimitSecu #546 - Questionnaires de Sécurité

NoLimitSecu #546 - Questionnaires de Sécurité

🎙 NoLimitSecu 👥 2K 📅 June 29, 2026 ⏱ 38 min 👁 186 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

questionnairesecuritysupplierriskISO 27001

Summary

In this episode of NoLimitSecu, the host welcomes Claire to present the ‘La Boite à Crypto’ project, an educational initiative by ARCSI to teach cryptography through hands-on workshops. The main segment features Étienne Retout, co-founder of Galink, discussing security questionnaires in supplier risk management. Retout shares his experience as both a supplier and a consultant, highlighting common pitfalls such as overly long and generic questionnaires, the burden on suppliers, and the inefficiency of Excel-based formats. He advocates for a risk-based approach, differentiating between critical and non-critical suppliers, and using lighter questionnaires for certified suppliers. He recommends using closed-ended questions to facilitate analysis and flag risks automatically, and emphasizes that questionnaires should not replace human interaction, suggesting calls for clarification. The discussion also touches on the role of AI in generating responses and the limitations of universal questionnaires. The episode concludes with practical advice on building effective questionnaires and integrating them into a broader risk management process.

156 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into the real-world challenges of security questionnaires. Retout’s dual perspective as a former supplier and current consultant provides a balanced view, making the arguments credible and relatable. The discussion is well-structured, moving from the initial purpose of questionnaires to common issues, then to best practices and future considerations. The argumentation is solid, supported by concrete examples and clear reasoning, such as the comparison between questionnaire length and supplier criticality, and the suggestion to leverage existing certifications like ISO 27001 to reduce redundancy. The emphasis on closed-ended questions and automated risk flagging is particularly valuable for practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the content is based on professional experience rather than formal research, but it aligns with industry best practices. The sources cited are minimal, with only one link provided (ARCSI’s La Boite à Crypto), which is not directly related to the main topic. The discussion references ISO 27001 and SOC 2, but without specific documentation. The title accurately reflects the content, and the episode also includes a brief presentation of an educational project, which is clearly separated from the main topic. Overall, the information is reliable for practical guidance, but lacks formal references.

219 words

Title / Content Match

The title accurately reflects the main topic: security questionnaires in the context of supplier risk management.

Quality & Reliability

7/10

The discussion is based on the speaker's extensive professional experience (7 years as a supplier responding to questionnaires, 3 years as a consultant on the client side). The content is practical and grounded, but lacks formal citations or references to standards beyond general mentions of ISO 27001 and SOC 2. The presentation is opinion-based rather than data-driven, but the arguments are coherent and well-illustrated with concrete examples.

Key Moments

Cited Sources

Concurring Sources

  • ISO/IEC 27001 — Referenced as a common certification that can reduce the need for detailed questionnaires.

Contribution & Novelties

The episode provides a practical, experience-based perspective on security questionnaires, emphasizing the need for a risk-based approach and the use of closed-ended questions to streamline analysis. It also highlights the potential pitfalls of AI-generated responses and the limitations of universal questionnaires.

Pour aller plus loin :

  • ISO/IEC 27001 — International standard for information security management, referenced as a key certification.
  • SOC 2 — AICPA’s trust services criteria, commonly used in the US.
  • Third-party risk management — Overview of the discipline.

80 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, with a slight emphasis on practical applicability. This indicates a well-rounded discussion that is informative and credible, though not deeply technical or research-heavy.

Reliability 7/10