Due Diligence

Assessment DD

Technology due-diligence questions (CSV-driven). Table or guided view.

Group by
0 / 211 answered0%
DD001

Provide a high-level overview of the company's technology environment.

Long text#overview#governanceDoc C (Security) No single source of truth for tech stack
DD002

Describe the primary products, platforms, websites, and digital services operated.

Long text#products#platformsDoc A (Eng/Product) Undocumented zombie services
DD003

Provide an organisational chart for Engineering/Development, IT Operations, and Security/Compliance.

Long text#org-chart#governanceDoc C (Security) Security reporting into Engineering without independence
DD004

How many employees are developers, IT administrators, security personnel, and contractors/freelancers?

Long text#headcount#resourcingDoc C (Security) Security team <5% of engineering
DD005

Describe the software development lifecycle (SDLC).

Long text#sdlc#processDoc A (Eng/Product) No formal SDLC gates
DD006

What are the primary technology objectives over the next 24 months?

Long text#strategy#roadmapDoc H (Finance) Objectives miss security or resilience
DD007

Provide details of all outsourced technology providers and managed service providers (MSPs).

Long text#outsourcing#vendorDoc G (Third-Party) No central MSP register
DD008

Identify any key-person dependencies in engineering or IT operations.

Long text#key-person#bus-factorDoc A (Eng/Product) Single person holds all cloud credentials
DD009

Describe current technology budget allocation across infrastructure, SaaS, security, contractors, and development.

Long text#budget#financeDoc H (Finance) Security <10% of IT budget
DD010

Describe the architecture of the company's websites and applications.

Long text#architecture#designDoc A (Eng/Product) No architecture diagram
DD011

List all production environments and hosting providers.

Long text#hosting#environmentsDoc B (Infra) Unknown staging/prod parity
DD012

Provide an inventory of websites, applications, APIs, CMS platforms, and mobile apps.

Long text#inventory#assetsDoc B (Infra) No asset inventory
DD013

Which technologies/frameworks are used?

Long text#tech-stack#frameworksDoc A (Eng/Product) Unsupported frameworks in production
DD014

Are systems monolithic or microservices-based?

Long text#microservices#architectureDoc A (Eng/Product) Distributed monolith with no service boundaries
DD015

Describe database technologies in use.

Long text#databases#storageDoc B (Infra) No database version control
DD016

Describe CDN and caching architecture.

Long text#cdn#cachingDoc B (Infra) Cache invalidation not tested
DD017

Are environments segregated (development/staging/production)?

Long text#environments#segregationDoc B (Infra) Dev can write to prod DB
DD018

Are infrastructure resources cloud-native, hybrid, or on-premise?

Long text#cloud#hybridDoc B (Infra) Undocumented on-prem dependency
DD019

Describe sprint/release methodology.

Long text#sprint#agileDoc A (Eng/Product) No predictable release cadence
DD020

How frequently are releases deployed?

Long text#deployment-frequency#releasesDoc A (Eng/Product) Releases less than weekly
DD021

Is CI/CD implemented? If so, describe tooling and controls.

Long text#cicd#automationDoc A (Eng/Product) Manual deployment to prod
DD022

Are code reviews mandatory?

Long text#code-review#qualityDoc A (Eng/Product) Code reviews optional
DD023

Describe branch management and version control practices.

Long text#git#branchingDoc A (Eng/Product) No branch protection rules
DD024

Is automated testing implemented?

Long text#testing#automationDoc A (Eng/Product) No unit/integration tests
DD025

Provide test coverage metrics where available.

Long text#coverage#testingDoc A (Eng/Product) Coverage <70%
DD026

Are security checks integrated into the development pipeline?

Long text#devsecops#securityDoc A (Eng/Product) No SAST/DAST in pipeline
DD027

Describe rollback and release recovery procedures.

Long text#rollback#recoveryDoc A (Eng/Product) Rollback takes >30min
DD028

Are coding standards formally documented?

Long text#coding-standards#qualityDoc A (Eng/Product) No style guide
DD029

Where is source code hosted?

Long text#source-code#hostingDoc A (Eng/Product) Code on unmanaged service
DD030

Who owns the intellectual property for internally developed software?

Long text#ip#intellectual-propertyDoc G (Third-Party) No signed IP assignment from contractors
DD031

Are any contractors involved in software development?

Long text#contractors#outsourcingDoc G (Third-Party) Contractors have prod access
DD032

Are signed IP assignment agreements in place?

Long text#ip-assignment#legalDoc G (Third-Party) No IP assignment on file
DD033

Identify any open-source software dependencies.

Long text#opensource#dependenciesDoc A (Eng/Product) No SBOM
DD034

Describe the process for managing open-source vulnerabilities and licensing risks.

Long text#opensource#vulnerabilitiesDoc C (Security) No automated vuln scanning
DD035

Are there any known technical debt concerns?

Long text#tech-debt#debtDoc A (Eng/Product) No tech debt register
DD036

Are there undocumented or unsupported legacy systems?

Long text#legacy#supportDoc B (Infra) EOL software in production
DD037

What uptime SLAs exist?

Long text#uptime#slaDoc B (Infra) No internal uptime SLO
DD038

Provide historical uptime/availability metrics for the past 24 months.

Long text#uptime#metricsDoc B (Infra) Unable to produce 24-month report
DD039

Describe monitoring and alerting capabilities.

Long text#monitoring#observabilityDoc B (Infra) No alerting on critical paths
DD040

How are traffic spikes handled?

Long text#scalability#trafficDoc B (Infra) No auto-scaling
DD041

Describe scalability testing performed.

Long text#scalability#testingDoc B (Infra) No load tests
DD042

Have there been any major outages in the past 24 months?

Long text#outages#incidentsDoc B (Infra) Untracked outages
DD043

Provide details of any Sev-1 or customer-impacting incidents.

Long text#sev1#incidentsDoc C (Security) No post-mortems
DD044

Provide a full inventory of servers, end-user devices, network equipment, and cloud services.

Long text#inventory#assetsDoc B (Infra) No CMDB
DD045

Describe the network architecture.

Long text#network#architectureDoc B (Infra) No network diagram
DD046

What cloud providers are used?

Long text#cloud#providersDoc B (Infra) Unapproved cloud usage
DD047

Are there any on-premise data centres?

Long text#on-prem#datacentreDoc B (Infra) No DC access logs
DD048

Describe remote access infrastructure.

Long text#remote-access#vpnDoc B (Infra) No VPN MFA
DD049

Describe Wi-Fi segmentation and guest network controls.

Long text#wifi#segmentationDoc B (Infra) Guest on corp SSID
DD050

Is infrastructure documented and regularly updated?

Long text#documentation#cmdbDoc B (Infra) Docs >6m old
DD051

What identity provider(s) are used?

Long text#idp#identityDoc C (Security) Multiple IdPs not synced
DD052

Is single sign-on (SSO) implemented?

Long text#sso#identityDoc C (Security) <50% apps on SSO
DD053

Is multi-factor authentication (MFA) enforced?

Long text#mfa#identityDoc C (Security) MFA not enforced for all users
DD054

Describe joiner/mover/leaver processes.

Long text#joiners#movers#leavers#iamDoc C (Security) No automated deprovisioning
DD055

How are privileged accounts managed?

Long text#pam#privilegeDoc C (Security) No PAM solution
DD056

Are shared accounts used?

Long text#shared-accounts#identityDoc C (Security) Shared root credentials
DD057

How frequently are access reviews conducted?

Long text#access-reviews#governanceDoc C (Security) No regular access reviews
DD058

Describe password policy enforcement.

Long text#password#policyDoc C (Security) No complexity/lifetime rules
DD059

Are admin accounts separated from standard user accounts?

Long text#admin-accounts#privilegeDoc C (Security) Daily use of admin accounts
DD060

What endpoint management platform is used?

Long text#endpoint#mdmDoc B (Infra) No endpoint management
DD061

Are devices centrally managed?

Long text#endpoint#mdmDoc B (Infra) BYOD unmanaged
DD062

Is full-disk encryption enforced?

Long text#fde#encryptionDoc C (Security) FDE not enforced
DD063

Describe patch management processes.

Long text#patching#vulnerabilityDoc B (Infra) No patch policy
DD064

What is the average patch deployment timeframe?

Long text#patching#mttrDoc B (Infra) Patching >30d
DD065

Are endpoint detection and response (EDR) tools deployed?

Long text#edr#endpointDoc C (Security) No EDR
DD066

Are BYOD devices permitted?

Long text#byod#mobileDoc B (Infra) BYOD with no controls
DD067

Describe mobile device management (MDM) controls.

Long text#mdm#mobileDoc B (Infra) No MDM
DD068

How are lost/stolen devices handled?

Long text#lost-device#responseDoc C (Security) No remote wipe
DD069

Describe the IT service desk structure.

Long text#servicedesk#itsmDoc B (Infra) No ticketing system
DD070

What ticketing system is used?

Long text#ticketing#itsmDoc B (Infra) Untracked requests
DD071

Describe change management procedures.

Long text#change-management#itsmDoc B (Infra) No CAB
DD072

Is there a formal asset lifecycle management process?

Long text#asset-lifecycle#itsmDoc B (Infra) No asset tracking
DD073

Describe backup procedures and retention policies.

Long text#backup#retentionDoc B (Infra) No backups
DD074

How often are restores tested?

Long text#backup#restoreDoc B (Infra) Backups never tested
DD075

What are the RPO and RTO targets?

Long text#rpo#rto#bcpDoc B (Infra) No documented RPO/RTO
DD076

Describe disaster recovery arrangements.

Long text#dr#bcpDoc B (Infra) No DR plan
DD077

Has disaster recovery been formally tested?

Long text#dr#testingDoc B (Infra) DR never tested
DD078

Provide copies of information security policies, acceptable use policies, incident response plans, and business continuity plans.

Long text#policies#governanceDoc C (Security) No policies available
DD079

Who is accountable for cybersecurity?

Long text#accountability#governanceDoc C (Security) No named security lead
DD080

Does the company maintain a security committee or governance forum?

Long text#security-committee#governanceDoc C (Security) No security governance
DD081

What security frameworks are followed?

Long text#framework#complianceDoc C (Security) No framework (ISO/SOC2/NIST)
DD082

Is there a formal risk register?

Long text#risk-register#governanceDoc C (Security) No risk register
DD083

Are cyber risks reported to the board?

Long text#board-reporting#governanceDoc C (Security) Board unaware of cyber risk
DD084

Describe perimeter security controls.

Long text#perimeter#networkDoc C (Security) No firewall rules documented
DD085

Is network segmentation implemented?

Long text#segmentation#networkDoc C (Security) Flat network
DD086

Are firewalls centrally managed?

Long text#firewall#networkDoc B (Infra) Local firewall rules per device
DD087

Is SIEM or centralised logging deployed?

Long text#siem#loggingDoc C (Security) No central logs
DD088

Describe vulnerability management processes.

Long text#vulnerability-management#vulnsDoc C (Security) No VM process
DD089

How frequently are vulnerability scans conducted?

Long text#vuln-scan#scansDoc C (Security) No regular scans
DD090

Are penetration tests performed annually?

Long text#pen-test#testingDoc C (Security) No pen test >12m
DD091

Provide summaries of the last penetration test, vulnerability assessment, and security audit.

Long text#pen-test#reportsDoc C (Security) No reports available
DD092

Describe email security protections.

Long text#email#securityDoc C (Security) No DMARC/SPF/DKIM
DD093

Are phishing simulations conducted?

Long text#phishing#awarenessDoc C (Security) No phishing tests
DD094

Is DNS/web filtering implemented?

Long text#dns#filteringDoc C (Security) No web filtering
DD095

Describe DLP controls.

Long text#dlp#data-lossDoc C (Security) No DLP
DD096

Is privileged access monitored and logged?

Long text#privilege-monitoring#pamDoc C (Security) No privileged logging
DD097

Describe encryption standards for data at rest and in transit.

Long text#encryption#cryptoDoc C (Security) No encryption standard
DD098

Describe the incident response process.

Long text#incident-response#irDoc C (Security) No IR plan
DD099

Has the company experienced any cybersecurity incidents in the last 5 years?

Long text#incidents#breachDoc C (Security) Undisclosed past incidents
DD100

Provide details of ransomware events, data breaches, business email compromise, or service disruptions.

Long text#ransomware#breachDoc C (Security) Previous ransomware
DD101

Were any incidents reported to the ICO?

Long text#ico#breachDoc C (Security) Unreported ICO breaches
DD102

Were customers or partners notified?

Long text#breach-notification#privacyDoc C (Security) No customer notification process
DD103

What lessons learned activities were completed?

Long text#post-mortem#irDoc C (Security) No post-mortem culture
DD104

Is mandatory security awareness training conducted?

Long text#awareness#trainingDoc C (Security) No security training
DD105

How frequently is training refreshed?

Long text#training#frequencyDoc C (Security) Training <annually
DD106

Are developers provided with secure coding training?

Long text#secure-coding#trainingDoc A (Eng/Product) No secure coding training
DD107

Are privileged users subject to enhanced controls/training?

Long text#privileged-users#pamDoc C (Security) Privileged users same training
DD108

Describe the company's GDPR compliance programme.

Long text#gdpr#complianceDoc C (Security) No GDPR programme
DD109

Who is the Data Protection Officer (DPO)?

Long text#dpo#governanceDoc C (Security) No DPO appointed
DD110

What categories of personal data are processed?

Long text#personal-data#datamapDoc C (Security) No data inventory
DD111

Are special category data processed?

Long text#special-category#datamapDoc C (Security) Special data with no safeguards
DD112

Describe lawful bases for processing.

Long text#lawful-basis#gdprDoc C (Security) No documented lawful basis
DD113

Provide records of processing activities (RoPA).

Long text#ropa#complianceDoc C (Security) No RoPA
DD114

Describe consent management processes.

Long text#consent#gdprDoc C (Security) No consent manager
DD115

Describe cookie compliance practices.

Long text#cookies#gdprDoc C (Security) Cookie banner missing
DD116

Are DPIAs conducted?

Long text#dpia#riskDoc C (Security) No DPIAs for high-risk processing
DD117

Describe data retention and deletion policies.

Long text#retention#deletionDoc C (Security) No retention schedule
DD118

Are international data transfers performed?

Long text#cross-border#gdprDoc C (Security) US transfers with no SCCs
DD119

What third parties process personal data?

Long text#third-party#processorsDoc G (Third-Party) No processor list
DD120

Are DPAs in place with all processors?

Long text#dpa#contractsDoc G (Third-Party) Missing DPAs
DD121

Has the company received any ICO complaints or investigations?

Long text#ico#enforcementDoc C (Security) Open ICO investigation
DD122

Describe subject access request (SAR) handling processes.

Long text#sar#rightsDoc C (Security) No SAR process
DD123

Describe data breach notification procedures.

Long text#breach-notification#gdprDoc C (Security) No 72h process
DD124

Provide a complete list of SaaS platforms, hosting providers, managed services, and security vendors.

Long text#vendor-list#saasDoc G (Third-Party) No vendor inventory
DD125

Which systems are considered business critical?

Long text#critical-systems#business-impactDoc G (Third-Party) No criticality rating
DD126

Describe vendor due diligence procedures.

Long text#vendor-due-diligence#procurementDoc G (Third-Party) No vendor DD
DD127

Are security reviews performed before onboarding vendors?

Long text#vendor-security#procurementDoc G (Third-Party) No security review
DD128

Are vendor SLAs formally monitored?

Long text#vendor-sla#monitoringDoc G (Third-Party) No SLA monitoring
DD129

Describe dependency risks relating to key vendors.

Long text#dependency#riskDoc G (Third-Party) Single vendor single point of failure
DD130

Are subcontractors used by critical vendors?

Long text#subcontractor#supply-chainDoc G (Third-Party) No subprocessor visibility
DD131

Are vendors contractually required to notify of breaches?

Long text#breach-notification#contractsDoc G (Third-Party) No breach clause
DD132

Describe offboarding procedures for terminated vendors.

Long text#vendor-offboarding#procurementDoc G (Third-Party) No offboarding process
DD133

Describe the digital publishing workflow.

Long text#publishing#workflowDoc D (Trust & Safety) No content approval flow
DD134

What CMS platforms are used?

Long text#cms#platformsDoc A (Eng/Product) Unpatched CMS plugins
DD135

How are editorial permissions managed?

Long text#editorial-permissions#iamDoc C (Security) Overly broad editorial access
DD136

Describe media asset storage architecture.

Long text#media-storage#assetsDoc B (Infra) No media lifecycle policy
DD137

Is DRM or content protection implemented?

Long text#drm#protectionDoc E (Video) No DRM for premium content
DD138

Describe video/audio transcoding infrastructure.

Long text#transcoding#videoDoc E (Video) No integrity check on transcoders
DD139

How are large media files transferred securely?

Long text#media-transfer#secureDoc B (Infra) FTP for raw footage
DD140

Describe advertising technology integrations.

Long text#adtech#programmaticDoc D (Trust & Safety) No ad tag sandboxing
DD141

Are audience analytics platforms integrated?

Long text#analytics#audienceDoc F (Data & ML) First-party data shared without DPAs
DD142

Describe controls around sponsored content and ad tech security.

Long text#sponsored#adsDoc D (Trust & Safety) No sponsored content review
DD143

Are there risks associated with third-party scripts or plugins?

Long text#third-party-scripts#client-sideDoc C (Security) No CSP policy
DD144

Describe moderation processes for user-generated content.

Long text#moderation#ugcDoc D (Trust & Safety) No pre-moderation for high-risk UGC
DD145

Identify any major planned infrastructure investments.

Long text#investment#planningDoc H (Finance) No budget for tech debt
DD146

Describe all material recurring software licensing costs.

Long text#licensing#costsDoc H (Finance) Uncapped licensing costs
DD147

Are any critical licences nearing expiration?

Long text#licensing#expiryDoc H (Finance) Licences expiring <90d
DD148

Are there unsupported/end-of-life systems in production?

Long text#eol#legacyDoc H (Finance) EOL OS in production
DD149

What percentage of infrastructure spend is variable vs fixed?

Long text#cloud-cost#financeDoc H (Finance) >80% fixed committed spend
DD150

Describe cloud cost management processes.

Long text#finops#costDoc H (Finance) No cloud cost monitoring
DD151

Are there material vendor lock-in risks?

Long text#vendor-lock#riskDoc H (Finance) Proprietary APIs only
DD152

Identify any pending litigation or disputes involving technology or IP.

Long text#litigation#legalDoc H (Finance) Open IP litigation
DD153

Are ads scanned pre-bid and pre-render for malvertising?

Long text#malvertising#adsDoc D (Trust & Safety) No ad scanning
DD154

Does bidstream include user IDs, precise location, or device fingerprints?

Long text#bidstream#data-leakageDoc D (Trust & Safety) Raw user data in bidstream
DD155

Which DSPs and SSPs are integrated? Are they vetted?

Long text#dsp#ssp#adtechDoc D (Trust & Safety) No DSP/SSP security reviews
DD156

Can you trace a malicious ad back to the buying source?

Long text#ad-forensics#investigationDoc D (Trust & Safety) No ad chain visibility
DD157

What brand safety blocks are in place (keywords, categories, content adjacency)?

Long text#brand-safety#adsDoc D (Trust & Safety) No brand safety controls
DD158

How is user-generated content scanned pre-publish (image, video, text)?

Long text#ugc#moderationDoc D (Trust & Safety) No pre-publish scanning
DD159

Is hash-based detection (e.g., PhotoDNA, PDQ) used for CSAM or terrorist content?

Long text#hash-matching#trust-safetyDoc D (Trust & Safety) No hash matching
DD160

What is median time for illegal content removal?

Long text#takedown#slaDoc D (Trust & Safety) Takedown >24h for regulated content
DD161

What tools do human moderators use? Are actions logged?

Long text#moderation-tools#trust-safetyDoc D (Trust & Safety) No audit trail for moderators
DD162

What wellbeing support is provided to content moderators?

Long text#moderator-wellbeing#trust-safetyDoc D (Trust & Safety) No psychological support
DD163

What is the user appeals process for content takedown?

Long text#appeals#ugcDoc D (Trust & Safety) No appeals mechanism
DD164

How are law enforcement requests (e.g., National Center for Missing & Exploited Children) handled?

Long text#legal-reporting#complianceDoc D (Trust & Safety) No LE reporting process
DD165

How is video packaged and encrypted (HLS, DASH, Clear Key, Widevine)?

Long text#packaging#drmDoc E (Video) No encryption on streaming
DD166

How often are encryption keys rotated? Where are keys stored?

Long text#key-rotation#drmDoc E (Video) Static keys >30d
DD167

Is the video player hardened against screen capture or stream ripping?

Long text#player-security#drmDoc E (Video) No player integrity checks
DD168

Can a specific video be purged from all CDN edges in <5 minutes?

Long text#cdn-purge#incidentDoc E (Video) No kill switch for content
DD169

Are transcoding jobs isolated per tenant/user?

Long text#transcoding#isolationDoc E (Video) Transcoding jobs can access other content
DD170

Is forensic watermarking used for leaked content?

Long text#watermarking#drmDoc E (Video) No forensic tracing
DD171

What is the account takeover rate over last 12 months? How detected?

Long text#ato#identityDoc C (Security) ATO rate >5% or unknown
DD172

Are login velocity, geovelocity, and device fingerprinting enforced?

Long text#login-anomalies#identityDoc C (Security) No rate limiting on login
DD173

What protections exist against credential stuffing attacks?

Long text#cred-stuffing#identityDoc C (Security) No breach credential checking
DD174

What signals detect bot/sybil account creation?

Long text#signup-fraud#identityDoc C (Security) No phone/email verification
DD175

What is the account recovery process? Is it vulnerable to social engineering?

Long text#account-recovery#identityDoc C (Security) SMS-only recovery
DD176

Is MFA offered to end users? Is it enforced for high-risk accounts?

Long text#user-mfa#identityDoc C (Security) No user MFA option
DD177

Are API rate limits per key, per IP, and per endpoint?

Long text#api-abuse#integrityDoc C (Security) No API quotas
DD178

How is large-scale scraping detected and mitigated?

Long text#scraping#integrityDoc C (Security) No anti-scraping controls
DD179

How is fake like/follow/share/friend activity detected?

Long text#engagement-fraud#integrityDoc D (Trust & Safety) No graph anomaly detection
DD180

How are coordinated inauthentic behaviour (networks) detected?

Long text#coordinated-behaviour#integrityDoc D (Trust & Safety) No network-based detection
DD181

What spam detection is applied to comments, DMs, and posts?

Long text#spam#integrityDoc D (Trust & Safety) No spam filtering
DD182

What user reporting mechanisms exist for abusive content?

Long text#user-reporting#integrityDoc D (Trust & Safety) No user reporting
DD183

How are recommendations generated? What data is used?

Long text#recommendations#mlDoc F (Data & ML) Black-box recommendations
DD184

Where does training data come from? Is it versioned and integrity-checked?

Long text#training-data#mlDoc F (Data & ML) Training data from untrusted sources
DD185

What protections exist against feedback loop poisoning?

Long text#data-poisoning#mlDoc F (Data & ML) User feedback directly retrains models
DD186

Can you explain why a specific post was recommended to a user?

Long text#explainability#mlDoc F (Data & ML) No model explainability
DD187

Are models tested for demographic or content bias?

Long text#bias#mlDoc F (Data & ML) No bias testing
DD188

What user profiles exist? Is profiling minimised?

Long text#profiling#privacyDoc F (Data & ML) Excessive user profiling
DD189

What is the process when an ad runs next to banned content?

Long text#brand-safety#crisisDoc D (Trust & Safety) No real-time brand safety
DD190

What is the process for a leak of internal comms or influencer platform data?

Long text#leak#crisisDoc C (Security) No leak response plan
DD191

What customer-facing comms template exists for major outages?

Long text#outage-comms#crisisDoc B (Infra) No customer comms plan
DD192

Who is notified internally for ICO/Ofcom/FTC inquiries?

Long text#regulatory#crisisDoc C (Security) No escalation tree
DD193

Please provide network diagrams.

Long text#diagrams#documentationDoc B (Infra) No diagrams
DD194

Please provide infrastructure architecture diagrams.

Long text#architecture-diagrams#documentationDoc B (Infra) No diagrams
DD195

Please provide asset inventory.

Long text#asset-inventory#documentationDoc B (Infra) No inventory
DD196

Please provide security policies.

Long text#security-policies#documentationDoc C (Security) No policies
DD197

Please provide DR/BCP documentation.

Long text#dr#bcp#documentationDoc B (Infra) No DR/BCP
DD198

Please provide penetration test reports.

Long text#pen-test-reports#documentationDoc C (Security) No reports
DD199

Please provide vulnerability assessment reports.

Long text#vuln-reports#documentationDoc C (Security) No reports
DD200

Please provide SOC reports/certifications.

Long text#soc-reports#documentationDoc C (Security) No SOC2/ISO
DD201

Please provide GDPR documentation.

Long text#gdpr-docs#documentationDoc C (Security) No GDPR docs
DD202

Please provide incident logs.

Long text#incident-logs#documentationDoc C (Security) No logs
DD203

Please provide uptime reports.

Long text#uptime-reports#documentationDoc B (Infra) No reports
DD204

Please provide cloud architecture diagrams.

Long text#cloud-diagrams#documentationDoc B (Infra) No diagrams
DD205

Please provide vendor list.

Long text#vendor-list#documentationDoc G (Third-Party) No list
DD206

Please provide software licence inventory.

Long text#licence-inventory#documentationDoc H (Finance) No inventory
DD207

Please provide SDLC documentation.

Long text#sdlc-docs#documentationDoc A (Eng/Product) No SDLC docs
DD208

Please provide access control matrix.

Long text#access-matrix#documentationDoc C (Security) No matrix
DD209

Please provide change management policies.

Long text#change-policies#documentationDoc B (Infra) No policy
DD210

Please provide backup and restore test evidence.

Long text#backup-evidence#documentationDoc B (Infra) No evidence
DD211

Please provide cyber insurance documentation.

Long text#cyber-insurance#documentationDoc H (Finance) No insurance