IT · question 1 of 14
An information security policy is written, approved by executive management and reviewed at least once a year.
Evidence to check: Dated document, evidence of approval, date of last review.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 2 of 14
The inventory of privileged accounts is kept up to date and reviewed periodically.
Evidence to check: Named list, date of last review, designated owner.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 3 of 14
Multi-factor authentication is enforced on every account, with no untracked exception.
Evidence to check: Technical rule, list of exceptions and their justification.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 4 of 14
Administrative accounts are dedicated, separate from named accounts, and have no mailbox.
Evidence to check: Naming convention, sample of accounts.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 5 of 14
Devices accessing company data are inventoried and subject to a compliance policy.
Evidence to check: Management console, share of compliant devices.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 6 of 14
Security patches are applied within a defined and measured timeframe.
Evidence to check: Patching policy, average timeframe observed.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 7 of 14
Audit logs are enabled, retained for a defined period and usable for an investigation.
Evidence to check: Retention period, export to a log repository.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 8 of 14
Security alerts are handled through a written procedure, with a measured time to first response.
Evidence to check: Procedure, sample of tickets, average time.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 9 of 14
An incident response plan exists, names the roles and has been tested at least once.
Evidence to check: Dated plan, report from the last exercise.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 10 of 14
Backups are tested by real restores, at a defined frequency.
Evidence to check: Report from the last restore test.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 11 of 14
Recovery time and acceptable data loss are defined for each critical application.
Evidence to check: Table of recovery objectives, approved by the business.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 12 of 14
Third-party applications connected to the system are inventoried and their permissions reviewed.
Evidence to check: List of consents, date of last review.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 13 of 14
A security budget is identified and tracked separately from the general IT budget.
Evidence to check: Budget line, amount, trend.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next
IT · question 14 of 14
External document sharing is governed by a technical rule, not merely by an instruction.
Evidence to check: Configuration, list of authorised domains.
0
Non-existent Nothing is in place, the topic has not been identified.
1
Initial The practice happens occasionally, carried by individuals, with no written rule.
2
Repeatable The practice is applied regularly but remains informal and unverified.
3
Defined The practice is written, known, applied consistently and recorded.
4
Measured The practice is measured through indicators, reviewed periodically and corrected.
5
Optimised The practice is improved continuously and holds up as threats evolve.
NA
Not applicable This question does not apply to us. It will be excluded from the score.
Previous
Next