0%
0 of 70 answered
GOVERN
0/14
IDENTIFY
0/12
PROTECT
0/16
DETECT
0/10
RESPOND
0/10
RECOVER
0/8
GOVERN 0 / 14
Have you documented your organisation's cybersecurity context including mission objectives and stakeholder expectations?
Covers GV.OC-01: Organisational mission informs cybersecurity risk management strategy and priorities.
Have you identified internal and external stakeholders with an interest in your cybersecurity posture?
Covers GV.OC-02: Internal and external stakeholders are understood and their needs and expectations regarding cybersecurity risk management are considered.
Is cybersecurity risk managed within an enterprise risk management strategy that has been approved by leadership?
Covers GV.RM-01: Risk management objectives are established and agreed to by organisational stakeholders.
Have you defined and communicated your organisation's risk appetite and tolerance for cybersecurity?
Covers GV.RM-02: Risk appetite and risk tolerance statements regarding cybersecurity risk are established and communicated.
Are cybersecurity roles responsibilities and authorities formally assigned and communicated to all relevant personnel?
Covers GV.RR-01: Organisational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware and ethical.
Does senior leadership actively demonstrate accountability for cybersecurity risk management decisions and outcomes?
Covers GV.RR-02: Roles responsibilities and authorities related to cybersecurity risk management are established communicated understood and enforced.
Do you have approved cybersecurity policies that address purpose scope roles and management responsibilities?
Covers GV.PO-01: Policy for managing cybersecurity risks is established based on organisational context strategy risk appetite and mission.
Are cybersecurity policies reviewed and updated at least annually or following significant changes to the organisation or threat landscape?
Covers GV.PO-02: Policy for managing cybersecurity risks is reviewed updated communicated and enforced.
Do you track and report on cybersecurity risk management performance against defined metrics?
Covers GV.OV-01: Cybersecurity risk management strategy outcomes are reviewed to ensure alignment with the organisational context.
Do senior leaders periodically review and adjust the cybersecurity programme to maintain its alignment with business objectives?
Covers GV.OV-02: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organisational requirements and risks.
Have you identified and classified critical suppliers and third-party service providers based on their cybersecurity risk?
Covers GV.SC-01: A cybersecurity supply chain risk management programme strategy objectives policies and processes are established and agreed to by organisational stakeholders.
Are cybersecurity requirements included in supplier contracts and procurement processes?
Covers GV.SC-06: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
Do you monitor your key suppliers' cybersecurity posture on an ongoing basis?
Covers GV.SC-07: Suppliers and other third parties are monitored to confirm they are meeting contractual cybersecurity obligations.
Are your critical suppliers included in your incident response and recovery planning?
Covers GV.SC-08: Relevant suppliers and other third parties are included in incident planning response and recovery activities.
IDENTIFY 0 / 12
Do you maintain a complete and accurate inventory of hardware assets including servers endpoints network devices and IoT?
Covers ID.AM-01: Inventories of hardware managed by the organisation are maintained.
Do you maintain an inventory of software assets including applications services and cloud workloads?
Covers ID.AM-02: Inventories of software services and systems managed by the organisation are maintained.
Have you classified your data and information assets according to sensitivity criticality and regulatory requirements?
Covers ID.AM-05: Assets are prioritised based on classification criticality resources and impact on the organisational mission.
Do you understand the legal regulatory and contractual cybersecurity requirements applicable to your organisation?
Covers GV.OC-03: Legal regulatory and contractual requirements regarding cybersecurity management including privacy and civil liberties obligations are understood and managed.
Do you perform documented risk assessments that identify threats vulnerabilities likelihoods and business impacts?
Covers ID.RA-01 to ID.RA-05: Vulnerabilities and threats are identified and risk is assessed for likelihood and potential impact.
Are vulnerabilities in your systems identified tracked and remediated through a formal vulnerability management process?
Covers ID.RA-01: Vulnerabilities in assets are identified validated and recorded.
Do you consume threat intelligence from trusted sources to inform your risk assessments and defences?
Covers ID.RA-02: Cyber threat intelligence is received from information-sharing forums and sources.
Are risk response priorities determined based on likelihood impact and business criticality?
Covers ID.RA-06: Risks are responded to based on prioritisation to inform and refine the organisational risk register.
Do you incorporate lessons learned from incidents exercises and industry events into your risk programme?
Covers ID.IM-01: Improvements are identified from evaluations and ID.IM-02: Improvements are identified from security tests and exercises.
Do you conduct regular independent or third-party assessments to evaluate your cybersecurity posture?
Covers ID.IM-02: Improvements are identified from security tests and exercises including those done collaboratively with suppliers and relevant third parties.
Is there a defined process to communicate programme improvements and risk findings to leadership?
Covers ID.IM-03: Organisation-wide improvements are communicated with leadership to inform risk management outcomes.
Have you mapped your critical business functions to technology dependencies to model the impact of a cybersecurity failure?
Covers ID.AM-08 and ID.RA: Business impact analysis documents critical processes asset dependencies and acceptable downtime.
PROTECT 0 / 16
Do you manage user identities with unique named accounts and enforce least-privilege access principles?
Covers PR.AA-01: Identities and credentials for authorised users services and hardware are managed by the organisation.
Is multi-factor authentication enforced for all staff accessing critical systems remote access and administrative interfaces?
Covers PR.AA-03: Users services and hardware are authenticated commensurate with the risk of the transaction.
Are user access rights reviewed periodically and revoked promptly on role change or departure?
Covers PR.AA-05: Access permissions and authorisations are managed incorporating the principles of least privilege and separation of duties.
Do you operate a privileged access management solution to control monitor and audit administrative and service accounts?
Covers PR.AA-05: Least privilege and separation of duties for privileged access management.
Does your organisation deliver regular cybersecurity awareness training for all staff?
Covers PR.AT-01: Personnel are provided awareness and training so they have the knowledge and skills to perform general tasks with cybersecurity risk in mind.
Do personnel with specific cybersecurity responsibilities receive role-appropriate technical or procedural training?
Covers PR.AT-02: Individuals in specialised roles are provided awareness and training so they have the knowledge and skills to perform relevant tasks with cybersecurity risk in mind.
Are sensitive data classified labelled and handled in accordance with a documented data governance policy?
Covers PR.DS-01: The confidentiality integrity and availability of data-at-rest are protected and PR.DS-10: Data in use are protected.
Is sensitive data encrypted both at rest and in transit using approved cryptographic standards?
Covers PR.DS-01 and PR.DS-02: The confidentiality integrity and availability of data in transit are protected.
Do you operate data loss prevention controls to detect and prevent unauthorised data exfiltration?
Covers PR.DS-01 to PR.DS-02: Controls prevent unauthorised access use and exfiltration of data.
Are systems hardened using approved configuration baselines such as CIS Benchmarks or vendor security guidelines?
Covers PR.PS-01: Configuration management practices are established and applied to protect hardware software services and data.
Is software kept up to date through a formal patching process with defined remediation timelines for critical vulnerabilities?
Covers PR.PS-02: Software is maintained replaced and removed commensurate with risk.
Are endpoints and servers protected with anti-malware endpoint detection and response or equivalent controls?
Covers PR.PS-04: Log records are generated to enable monitoring of activity and PR.PS-05: Installation and execution of unauthorized software are prevented.
Is your network segmented to limit lateral movement and isolate critical systems from general-purpose networks?
Covers PR.IR-01: Networks and environments are protected from unauthorized logical access and usage.
Are backups of critical data and systems maintained off-site or offline and tested at regular intervals?
Covers PR.IR-04: Adequate resource capacity to ensure availability is maintained.
Have recovery time and recovery point objectives been defined tested and validated for all critical systems?
Covers PR.IR-04 and RC.RP-01: Recovery timelines are defined agreed and practiced to confirm they are achievable.
Do you have a tested business continuity and disaster recovery plan covering major cybersecurity incident scenarios?
Covers PR.IR-04 and RC.RP-01: A tested plan ensures the organisation can recover from a major cybersecurity event.
DETECT 0 / 10
Do you perform continuous monitoring of your network endpoints and cloud environments for potential security events?
Covers DE.CM-01: Networks and network services are monitored to detect potential adverse cybersecurity events.
Are security logs collected from critical systems and retained for an adequate period to support investigation and forensics?
Covers DE.CM-03: Personnel activity and technology usage are monitored to find potential cybersecurity events.
Do you operate a SIEM or equivalent log correlation and alerting capability?
Covers DE.CM-09: Computing hardware software and runtime environments are monitored to find potential adverse events.
Are security alerts triaged and escalated in a timely manner according to defined severity thresholds?
Covers DE.AE-04: The estimated impact and scope of adverse events are understood.
Do you conduct regular vulnerability scanning or penetration testing to identify exploitable weaknesses before attackers do?
Covers DE.CM-08: Vulnerability scans are performed and results are used to improve defences.
Are security events correlated across multiple data sources to identify patterns and indicators of compromise?
Covers DE.AE-07: Cyber threat intelligence and contextual information are integrated into the analysis of adverse events.
Do you integrate threat intelligence into your detection process to contextualise and prioritise alerts?
Covers DE.AE-07: Cyber threat intelligence and other contextual information are integrated into the analysis of adverse events.
Have you established security baselines for normal behaviour so that deviations can be detected?
Covers DE.CM-09: Computing hardware software and runtime environments are monitored — baseline deviation is a primary detection mechanism.
Are your detection capabilities validated through red team exercises breach-and-attack simulation or tabletop scenarios?
Covers DE.CM-09 and ID.IM-02: Testing and exercises validate detection coverage and identify gaps.
Is there a clearly defined and communicated escalation path when a potential security event is detected?
Covers DE.AE-06: Information on adverse events is provided to designated personnel and tools in a timely manner.
RESPOND 0 / 10
Do you have a documented incident response plan covering identification containment eradication recovery and post-incident review?
Covers RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared.
Is the incident response plan tested at least annually through exercises or tabletop simulations?
Covers RS.MA-01 and ID.IM-02: Improvements from security tests and exercises are captured and actioned.
Are incident response roles and responsibilities clearly assigned and understood by all relevant personnel?
Covers RS.MA-01: Incident response is coordinated with all assigned roles and responsibilities clearly understood and actionable.
Do you conduct root cause analysis following significant security incidents?
Covers RS.AN-03: Analysis is performed to establish what took place during an incident and the root cause of the event.
Are the business impact and scope of detected incidents formally assessed to prioritise response activities?
Covers RS.AN-04: Incidents are categorised consistent with response plans to enable effective analysis and resource allocation.
Do you have a process to notify regulators customers and other stakeholders of significant incidents within required regulatory timeframes?
Covers RS.CO-02: Internal and external stakeholders are notified of incidents in compliance with applicable laws regulations and policies.
Are communication plans maintained for coordinating with external parties such as law enforcement CERTs and insurers during incidents?
Covers RS.CO-04: Coordination with stakeholders occurs consistent with response plans.
Are containment and eradication actions taken promptly to prevent further damage following incident detection?
Covers RS.MI-01: Incidents are contained and RS.MI-02: Incidents are eradicated.
Is incident evidence preserved and managed in accordance with forensic chain-of-custody and legal requirements?
Covers RS.AN-05: Processes for receiving analysing and responding to vulnerabilities and incidents are established and protecting evidence integrity.
Are lessons learned from incidents documented and actioned to improve policies controls and the incident response plan?
Covers RS.AN-06: Actions performed during investigations are recorded and findings are used to improve future response.
RECOVER 0 / 8
Do you have a documented recovery plan that defines how to restore systems and business services following a cybersecurity incident?
Covers RC.RP-01: The recovery portion of the incident response plan is executed once initiated by the appropriate stakeholders.
Have recovery time and recovery point objectives been validated for critical systems through testing?
Covers RC.RP-01 and RC.RP-02: Recovery actions are selected scoped prioritised and performed to ensure timelines are met.
Is the recovery plan tested regularly to confirm that backup restoration and failover procedures are effective?
Covers RC.RP-03: The integrity of backups and restoration assets is verified before using them for restoration.
Are internal stakeholders kept informed of progress during active recovery operations?
Covers RC.CO-01: Public updates on incident recovery are shared using approved methods and messaging and RC.CO-02: Recovery progress is communicated to designated internal stakeholders.
Is there a communication plan to update customers partners regulators and media during and after a major incident?
Covers RC.CO-02: Recovery activities and progress in restoring operational capabilities are communicated to designated external stakeholders.
Do you conduct post-incident reviews to evaluate the effectiveness of the recovery process?
Covers RC.RP-04: The organisation's cyber resilience is assessed and validated following completion of recovery activities.
Are improvements identified during recovery incorporated into future plans controls and procedures?
Covers RC.RP-05: End of incident recovery is declared based on agreed criteria and all restoration activities are completed and validated.
Do you track recovery performance metrics and report outcomes to leadership?
Covers RC.RP-04 and ID.IM-03: Improvements are communicated to teams responsible for executing and overseeing the cybersecurity strategy.