0%
0 of 70 answered
Theme 1 — Governance
Governance & Accountability
0/5
Theme 2 — Risk
Risk Management
0/5
Theme 3 — Assets
Asset Management
0/5
Theme 4 — Identity
Identity & Access Management
0/5
Theme 5 — Data
Data Protection & Privacy
0/5
Theme 6 — Network
Network & Infrastructure Security
0/5
Theme 7 — Endpoint
Endpoint & Device Security
0/5
Theme 8 — Vulnerability
Vulnerability & Patch Management
0/5
Theme 9 — Incident
Incident Detection & Response
0/5
Theme 10 — BC/DR
Business Continuity & DR
0/5
Theme 11 — Supply Chain
Supply Chain & Third-Party Risk
0/5
Theme 12 — Awareness
Security Awareness & Training
0/5
Theme 13 — Dev
Secure Development & Change Mgmt
0/5
Theme 14 — Compliance
Compliance & Regulatory Alignment
0/5
Used to label the PDF report
Organisation size:
T1

Governance & Accountability

Board-level cyber accountability, policy framework, and security investment

Leadership & Board Accountability
Do you have a named individual (e.g., CISO, CTO, or Board member) accountable for cyber security?
Evidence could include your org chart, board papers, or leadership directory showing a named senior security lead (CISO, Head of IT Security, or equivalent).
Do you have a documented cyber security or information security policy?
Consider your documented information security policy, including version control, approval date, and named owner. A documented policy is foundational to IASME Governance.
Does your board or senior leadership receive regular cyber security reporting?
Evidence could include board or audit/risk committee meeting minutes, terms of reference confirming cyber is a standing agenda item, or board risk reports.
Have you defined your risk appetite for cyber security and technology risk?
Evidence could include your risk management framework, risk register, or board-approved governance statements that include a stated cyber/technology risk appetite or tolerance threshold.
Do you have a cyber security budget allocation or investment in security capabilities?
Evidence could include your budget documentation, board-approved security spend, or headcount allocation to security roles.
T2

Risk Management

Risk registers, assessments, third-party risk, and asset classification

Risk Assessment & Registers
Do you maintain a documented risk register or risk assessment process that includes cyber/technology risks?
Evidence could include your risk register, risk assessment methodology document, or board risk report. IASME requires documented risk assessment.
Do you conduct regular (at least annual) cyber risk assessments being conducted?
Consider your penetration testing records, vulnerability assessment reports, or documented risk review cycles.
Do you assess and manage risks from third parties and supply chain partners?
Evidence could include your supplier code of conduct, procurement security checklist, or third-party risk management policy.
Do you apply risk-based prioritisation of security controls and investment?
Evidence could include your risk matrices, heat maps, or risk-based decision-making records in governance documents.
Have you identified and classified your critical assets and crown jewels?
Evidence could include your asset register, data classification policy, or critical asset / crown jewels register.
T3

Asset Management

Hardware/software inventory, attack surface visibility, and data classification

Inventory & Lifecycle
Do you maintain an inventory of hardware and software assets?
Evidence could include your CMDB or IT asset management system, discovery tool outputs, or asset inventory documentation.
Do you have a defined process for managing end-of-life and unsupported systems?
Consider your technology roadmap, cloud migration plans, or documented patching/lifecycle policies. Legacy tech is a common IASME Governance red flag.
Do you have visibility of your internet-facing assets and external attack surface?
Self-assessable — review DNS records, attack surface intelligence, SSL certificate transparency logs, and whether you manage your external footprint.
Do you have data classification and data flow mapping?
Evidence could include your data protection policy, GDPR/privacy notices, or DPIA references that include data classification.
Do you track and manage software licensing and shadow IT?
Evidence could include your software asset management records, approved application catalogue, or CASB configuration.
T4

Identity & Access Management

MFA, least privilege, PAM, joiner/mover/leaver, access reviews

MFA & Access Controls
Do you enforce multi-factor authentication (MFA) for remote access and privileged accounts?
Consider your Azure AD / Entra ID conditional access policies, Okta or similar IdP MFA configuration, or documented MFA rollout scope. CE and IASME require MFA for admin and cloud accounts.
Do you apply a principle of least privilege and role-based access control?
Evidence could include your access control policy, identity governance tool configuration (e.g., Azure AD, Okta), or RBAC role definitions.
Do you have a defined joiner/mover/leaver process for access management?
Evidence could include your joiners/movers/leavers (JML) process documentation, HR-IT integration records, or IAM tool configuration. Especially important during periods of organisational change.
Do you use privileged access management (PAM) for administrative accounts?
Evidence could include your PAM tool configuration (CyberArk, BeyondTrust, etc.), privileged account inventory, or standing admin access reviews.
Do you conduct periodic access reviews or recertification?
Evidence could include your access review records, audit trail configuration, or compliance certification evidence (SOC 2, ISO 27001) that requires periodic access reviews.
T5

Data Protection & Privacy

UK GDPR, ICO registration, encryption, retention, and DPIAs

Privacy & Regulatory Compliance
Do you have a published privacy policy that complies with UK GDPR / Data Protection Act 2018?
Directly verifiable — review your website privacy policy for completeness, lawful bases, data subject rights, and ICO registration.
Are you registered with the ICO (Information Commissioner's Office)?
Check your ICO registration status at ico.org.uk. All UK organisations processing personal data must register unless exempt.
Do you have data encryption at rest and in transit for sensitive data?
Check your SSL/TLS configuration (e.g., SSL Labs score for your domains), encryption standards documentation, or data processing agreements referencing encryption requirements.
Do you have a documented data retention and disposal policy?
Evidence could include your data retention schedule, data management policy, or records of retention review and secure disposal.
Have you conducted Data Protection Impact Assessments (DPIAs) for high-risk processing?
Evidence could include your DPIA register, documented DPIA process, or data processing records flagging high-risk activities that require a DPIA. Required under UK GDPR Article 35.
T6

Network & Infrastructure Security

Firewalls, segmentation, VPN/zero-trust, monitoring, and OT/IT separation

Network Architecture & Monitoring
Do you use firewalls and network segmentation to protect critical systems?
Evidence could include your network architecture diagrams, firewall rule documentation, or cloud security group / NSG configurations.
Do you enforce secure configuration management (hardening) for servers, network devices, and cloud-managed assets (including storage such as Azure Blob or AWS S3)?
Consider your CIS Benchmark baselines, hardening standards documentation, configuration management tool outputs (Ansible, Puppet, Chef), or CSPM / cloud security centre findings.
Do you use a VPN or zero-trust architecture for remote access?
Evidence could include your VPN or ZTNA configuration, remote working policy, or zero-trust architecture documentation.
Do you have network monitoring and logging (e.g., SIEM, NDR)?
Evidence could include your SIEM configuration, SOC run-book, or MSSP contract and scope documentation.
Do you segregate operational technology (OT) from IT networks where applicable?
Relevant for organisations with industrial/manufacturing operations. Evidence could include OT security references, ICS/SCADA mentions, or Purdue model implementation evidence.
T7

Endpoint & Device Security

EDR, MDM, encryption, automated patching, and removable media controls

Endpoint Protection & Management
Do you deploy endpoint detection and response (EDR) or managed antivirus across all endpoints?
Evidence could include your EDR tool configuration (CrowdStrike, SentinelOne, Defender), endpoint security policy, or managed endpoint service scope.
Do you have a mobile device management (MDM) solution for corporate and BYOD devices?
Evidence could include your MDM tool configuration (Intune, Jamf, VMware WS1), device enrolment records, or BYOD policy documentation.
Do you enforce device encryption on laptops and mobile devices?
Evidence could include your BitLocker/FileVault deployment records, device security policy, or compliance certification scope covering full-disk encryption (CE, ISO 27001).
Do you use automated patching for operating systems and applications?
Evidence could include your patch management tool configuration (WSUS, SCCM, Intune), patching policy, or documented patch SLA commitments.
Do you restrict the use of removable media and enforce USB controls?
Evidence could include your acceptable use policy, DLP tool configuration, or removable media control settings. CE requires removable media controls.
T8

Vulnerability & Patch Management

Scanning, penetration testing, patch SLAs, remediation, and SCA

Vulnerability Management Programme
Do you conduct regular vulnerability scanning of internal and external systems?
Evidence could include your vulnerability management tool configuration (Qualys, Tenable, Rapid7), scanning schedules, or penetration test reports.
Do you conduct regular penetration testing (at least annual) by qualified testers?
Consider your CREST/CHECK/Cyber Scheme pen test reports, remediation tracking, or penetration testing vendor contracts.
Do you have defined SLAs for patching critical, high, medium, and low vulnerabilities?
Evidence could include your patching policy, documented SLA commitments, or vulnerability management process records. CE requires critical patches within 14 days.
Do you remediate identified vulnerabilities in a timely manner?
Evidence could include your vulnerability remediation records, CVE response history, or patch prioritisation process documentation.
Do you include third-party and open-source components in your vulnerability management scope?
Evidence could include your SCA tool configuration (e.g., Snyk, OWASP Dependency-Check), open-source usage policy, or software bill of materials (SBOM).
T9

Incident Detection & Response

IR plans, SOC capability, breach history, tabletop exercises, and escalation

IR Capability & History
Do you have a documented incident response plan?
Evidence could include your incident response plan document, including version, owner, last review date, and escalation contacts.
Do you have 24/7 security monitoring or SOC capability (in-house or outsourced)?
Evidence could include your SIEM alert rules, SOC run-book, or MSSP service scope and escalation procedures. A SOC or MSSP partnership is a strong indicator of detection maturity.
Have you experienced any publicly disclosed data breaches or security incidents?
Self-assessable — review ICO breach notifications, press coverage, Have I Been Pwned, and your own breach disclosure history. This question is scored in reverse: answering “No” is the positive outcome, because a clean breach history is the good result.
Do you conduct regular incident response exercises or tabletop simulations?
Evidence could include your IR exercise records, tabletop test reports, or cyber resilience simulation after-action reviews.
Do you have defined communication and escalation procedures for cyber incidents?
Evidence could include your incident communication plan, regulatory notification procedures (ICO, FCA, etc.), or crisis communication run-book.
T10

Business Continuity & Disaster Recovery

BC/DR plans, backup integrity, RTO/RPO, testing, and ransomware readiness

BC/DR Capability
Do you have documented business continuity and disaster recovery plans?
Evidence could include your business continuity plan, ISO 22301 certification scope, or board-approved BC policy.
Do you conduct regular backup procedures with tested restoration capabilities?
Evidence could include your backup strategy documentation, cloud DR configuration, or tested RPO/RTO commitments.
Do you have defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)?
Evidence could include your DR plan, defined RTO/RPO targets, and test evidence confirming those targets are achievable.
Do you conduct regular DR testing and BC plan exercises?
Evidence could include your DR test reports, test frequency schedule, and evidence that lessons learned are acted on.
Do you have ransomware-specific response and recovery procedures?
Evidence could include ransomware preparedness references, immutable backup mentions, or cyber insurance disclosures that cover ransomware events.
T11

Supply Chain & Third-Party Risk

Supplier inventory, due diligence, certification requirements, monitoring, and contractual controls

Third-Party Risk Management
Do you maintain an inventory of critical third-party suppliers and service providers?
Evidence could include your approved supplier register, vendor risk assessments, or supply chain security policy.
Do you conduct security due diligence on third-party suppliers before onboarding?
Evidence could include your procurement security requirements, supplier questionnaire templates, or third-party risk management tool usage (OneTrust, Prevalent).
Do you require key suppliers to hold security certifications (e.g., CE, ISO 27001, SOC 2)?
Evidence could include your supplier security requirements, contractual security clauses, or partner certification mandates.
Do you conduct ongoing monitoring of third-party security posture?
Evidence could include your continuous monitoring process, security rating service outputs (BitSight, SecurityScorecard), or vendor audit records.
Do you have contractual provisions for security requirements, breach notification, and audit rights with key suppliers?
Evidence could include your data processing agreements, contract templates with security clauses, or contract management records.
T12

Security Awareness & Training

All-staff training, phishing simulation, role-specific training, security culture, and onboarding

Training & Culture
Do you provide regular cyber security awareness training to all employees?
Evidence could include your security awareness training records, completion rates, phishing simulation results, or training platform configuration (KnowBe4, Proofpoint).
Do you run phishing simulation exercises?
Evidence could include your phishing simulation results, awareness programme completion rates, or security training platform metrics.
Do you provide role-specific security training for high-risk roles (e.g., developers, finance, executives)?
Evidence could include developer security training references (OWASP, secure coding), finance fraud awareness mentions, or executive cyber briefing evidence.
Do you have a security culture programme beyond basic compliance training?
Evidence could include security champion programme references, internal security newsletters, CTF events, or security culture mentions in employer branding.
Do you include cyber security in your employee onboarding process?
Evidence could include your onboarding programme documentation, new starter security checklist, or mandatory training completion records.
T13

Secure Development & Change Management

SSDLC, code review, change management, environment separation, and source code security

DevSecOps & Change Controls
Do you follow a secure software development lifecycle (SSDLC)?
Evidence could include your secure development lifecycle (SSDLC) policy, OWASP standards adoption, or DevSecOps pipeline configuration.
Do you conduct code review and security testing in the development pipeline?
Evidence could include your CI/CD pipeline security gate configuration, SAST/DAST tool outputs (SonarQube, Checkmarx, Snyk), or secure code review records.
Do you have a formal change management process for production systems?
Evidence could include ITIL/change management references, CAB (Change Advisory Board) mentions, or change management tool usage (ServiceNow, Jira Service Management).
Do you maintain separate development, testing, and production environments?
Evidence could include your environment separation documentation, infrastructure-as-code configuration, or cloud account / subscription structure showing prod/non-prod separation.
Do you manage and secure your source code repositories?
Evidence could include your source code repository access controls, branch protection rules, and code review records.
T14

Compliance & Regulatory Alignment

Certifications, sector regulations, enforcement history, cyber insurance, and audits

Certifications & Regulatory Standing
Do you hold any recognised cyber security certifications (CE, CE Plus, ISO 27001, SOC 2)?
Self-assessable — review your IASME/NCSC CE portal status, certification body correspondence, or certification badges displayed on your website.
Is your organisation subject to sector-specific cyber regulations, and is there evidence of compliance?
Check your regulatory compliance records, registration documentation (FCA, ICO, Ofcom, etc.), or sector-specific certification evidence.
Have you received any regulatory enforcement actions, fines, or notices related to cyber security or data protection?
Self-assessable — review ICO enforcement tracker, FCA enforcement notices, or press coverage of regulatory actions against your organisation.
Do you have cyber insurance coverage?
Evidence could include your cyber insurance policy documents, coverage schedule, or risk management framework referencing insurance as a risk transfer control.
Do you conduct regular internal or external security audits?
Evidence could include your internal audit programme, audit reports, or third-party security review findings.