Reading an Australian security questionnaire: ISO 27001 questions and Essential Eight questions
By the Clause Desk · · Updated
Australian customer questionnaires often mix two frameworks. ISO 27001 questions ask whether you manage security as a system; Essential Eight questions ask how far eight specific controls go. Sorting them first makes the answers faster and more accurate.
Why do the questions look so different?
A questionnaire from an Australian customer may ask for your ISO 27001 certificate on page one and, a few pages later, ask whether administrative privileges are restricted, whether Microsoft Office macros are blocked and how often backups are tested. The first kind of question comes from ISO/IEC 27001:2022, the management system standard. The second comes from the Essential Eight, the eight mitigation strategies the Australian Signals Directorate describes as the most effective of its Strategies to mitigate cyber security incidents. The two sit side by side because they answer different concerns. A certificate shows that an audited management system exists. The Essential Eight shows whether a specific technical baseline is in place and at what maturity level.
How do you spot an ISO 27001 question?
ISO 27001 questions ask about the system: your scope, your risk assessment method, who approved the information security policy, whether you run internal audits and management reviews, and whether nonconformities are closed. They often ask for documents: the certificate with its scope, the Statement of Applicability, or a summary of the last audit. The right answer is usually a document plus a sentence of context. If your certificate scope does not cover the product the customer is buying, say so plainly and explain the plan.
How do you spot an Essential Eight question?
Essential Eight questions name the strategy: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. Many ask for a maturity level. ASD first published the maturity model in June 2017 and updates it regularly; the page we reviewed lists changes from the November 2023 release. A good answer states the level you target, the model version you assessed against, when you last assessed, and any gaps with a date to close them.
Where do the answers overlap?
Patching, MFA, administrative privileges and backups usually appear in an ISO 27001 Statement of Applicability too. If you store evidence once and map it to both frameworks, one patch report can support an ISO 27001 control and an Essential Eight strategy. The difference is that the Essential Eight answer must say how far the control goes across your environment, not only that a policy exists.
What should you prepare before the next questionnaire?
Four things. A short approved paragraph on your ISMS and certificate scope. A one-page Essential Eight summary: target level, model version, last assessment date and open gaps. An evidence index that points each common question to the current report. And an owner who approves new answers before they are reused, so the same question gets the same answer every time.
Which platforms help with this?
Most vendors on this site describe questionnaire features. Vanta lists Questionnaire Automation with 25 questionnaires a year on Plus and 144 on Professional. Sprinto lists 20 AI security questionnaires a year on Foundation. Scytale describes AI auto-fill with human expert review. Secureframe lists questionnaire automation on its Complete plan, and Drata lists AI Questionnaire Assistance on Foundation. For the Essential Eight content itself, only Vanta publishes an Essential Eight product page with templates pre-mapped across all eight strategies; for the other five we found no Essential Eight page on the pages reviewed. If you use another platform, ask whether you can hold the Essential Eight as a custom framework and who keeps the mapping current.
What is the takeaway?
Sort the questionnaire into ISO 27001 questions and Essential Eight questions before you answer anything. Answer the first set from your ISMS documents and the second from technical evidence with a stated maturity level. Keep both in one evidence store. That is faster than answering line by line, and it keeps your answers consistent across customers.