FMEA: the analysis is worth what the actions are worth
An FMEA that ends in a scored table has produced nothing. The output is the list of things you changed, and most teams stop one step before it.
The CAIQ is a spreadsheet of a few hundred yes-or-no questions about your cloud service. Completing it once turns most incoming security questionnaires into a file attachment.
The CAIQ — Consensus Assessments Initiative Questionnaire — is a standardised set of questions published by the Cloud Security Alliance for cloud service providers to document their security controls. It maps to the Cloud Controls Matrix, the CSA’s control framework, and it exists so that providers and customers stop inventing a new questionnaire for every deal.
For a provider its value is leverage. Completing it once, properly, gives you a document you can send in response to most incoming enquiries — and because it is recognised, buyers frequently accept it in place of their own list. For a customer it does the reverse: it lets you compare two suppliers on the same questions instead of on two differently-shaped marketing pages.
A completed CAIQ can be published to the CSA’s STAR Registry as a self-assessment, which is the entry level of that programme; higher levels involve third-party audit. Be clear-eyed about what the self-assessment signals: it shows the provider has done the work of documenting its controls and is willing to publish the answers, which is genuinely more than most do — and it remains a self-report. Buyers who care will still ask for the audit report behind the claims, and providers who publish one should expect that.
Answer the shared responsibility questions precisely. "Yes" against a control your customer actually operates is not a small inaccuracy — it is the answer that produces an argument after an incident, when both sides discover each assumed the other had it covered.
The CAIQ is filled in once with great effort and then rots quietly. Your subprocessor list changes, a control is automated, the penetration test cadence shifts, a region is added. A stale questionnaire is worse than none, because it is being relied on. Set a review cycle — annually at minimum, plus a trigger on any material infrastructure change — and give each domain an owner rather than leaving the whole sheet to one person who has since changed jobs.
Ettex Sheets holds the completed questionnaire with a column for the answer, the explanation, the owner and the last review date, so what is stale is visible at a glance; Ettex Records keeps the evidence behind each domain and the versions sent to specific customers; and the wider process of responding to buyers is covered in security questionnaire.
Plainly: this is a spreadsheet and a record, not a compliance platform, and we are not the CSA. The questionnaire and the Cloud Controls Matrix are the CSA’s documents, published on their site, and the registry is theirs to run.
The Consensus Assessments Initiative Questionnaire — a standardised set of security questions for cloud service providers, published by the Cloud Security Alliance and mapped to the Cloud Controls Matrix.
The basic level is a self-assessment. Higher levels of the CSA STAR programme involve third-party audit; the self-assessment is a published self-report.
No, it is voluntary. Providers complete it because it answers most incoming buyer questionnaires with one document.
At least annually, and whenever infrastructure, subprocessors or controls change materially. A stale questionnaire is relied on by buyers, which makes it worse than none.
An FMEA that ends in a scored table has produced nothing. The output is the list of things you changed, and most teams stop one step before it.
Collecting certificates is easy. The failure is always the same one: a policy expires in month seven of a two-year contract and nobody finds out until there is a claim.
The OSHA 300 log is not a list of everything that went wrong. Recordability has a definition, and both over-recording and under-recording cause problems.