A CRM can contain customer identities, communications, sales notes, contracts, and commercial history. Security review should match the sensitivity of that data and the business impact of misuse or loss. This checklist organizes questions for the business owner and qualified security or privacy advisers; it is not a certification of any vendor.
Classify data and access
List the data planned for the CRM and explicitly exclude fields that have no approved purpose. Identify administrators, regular users, temporary staff, contractors, integrations, and service accounts. Define least-privilege roles for viewing, editing, exporting, deleting, configuring, and installing applications.
Require multifactor authentication where available, starting with administrative and sensitive accounts. CISA recommends MFA broadly and favors stronger phishing-resistant methods where practical. Test account recovery and offboarding so an employee departure does not leave active sessions, API keys, shared passwords, or personal ownership of critical integrations.
Review integrations and data movement
Map every connected form, email service, calendar, accounting tool, support desk, data warehouse, and automation service. Record what data each integration reads and writes, the credential owner, permission scope, log location, failure alert, and removal process. Avoid granting a connector full access when its documented purpose requires less.
Check how exports, backups, attachments, mobile apps, and browser extensions handle data. A vendor’s security page does not automatically cover every third-party app installed into the account.
Collect evidence for core controls
| Area | Question | Evidence to retain |
|---|---|---|
| Identity | Are MFA, SSO, and session controls available on the chosen tier? | Configuration screenshot and plan terms |
| Authorization | Can roles limit exports, deletion, and sensitive fields? | Normal-user permission test |
| Logging | Which admin and data events are recorded and retained? | Sample log and retention statement |
| Recovery | How are accidental deletion and service interruption handled? | Recovery documentation and tested process |
| Exit | Can records, relationships, and files be exported? | Opened sample export |
Document vendor and internal responsibilities
Review current contractual terms, privacy documentation, security statements, incident notification language, subprocessors, data location choices, support contacts, deletion procedures, and independent assurance reports appropriate to the decision. Have qualified reviewers address regulated or contractually restricted data.
Security also depends on internal operation. Assign owners for access reviews, integration inventory, configuration changes, incident reporting, vendor notices, backup or export routines, and user training. Reassess after a major plan change, acquisition, integration, incident, or renewal.
Sources and verification starting points
- CISA multifactor authentication guidance
- NIST multi-factor authentication guidance
- NIST small business information security fundamentals
Product features and documentation can change. Open current provider and authority pages before making a material decision.