TENOVIA
Book a demo

Maturity self-assessment

Place your maturity on the NIST CSF 2.0 framework, function by function. Ten minutes, no commitment, and your gaps ranked by priority.

Self-assessment

How mature is your cyber security

38 questions structured along the NIST CSF 2.0 framework. Allow about ten minutes. Each question is scored from 0 to 5, or marked not applicable if it does not apply to you. Answer honestly : a flattering result protects nothing.

0 of 38 answered

IT · question 1 of 14

An information security policy is written, approved by executive management and reviewed at least once a year.

Evidence to check: Dated document, evidence of approval, date of last review.

IT · question 2 of 14

The inventory of privileged accounts is kept up to date and reviewed periodically.

Evidence to check: Named list, date of last review, designated owner.

IT · question 3 of 14

Multi-factor authentication is enforced on every account, with no untracked exception.

Evidence to check: Technical rule, list of exceptions and their justification.

IT · question 4 of 14

Administrative accounts are dedicated, separate from named accounts, and have no mailbox.

Evidence to check: Naming convention, sample of accounts.

IT · question 5 of 14

Devices accessing company data are inventoried and subject to a compliance policy.

Evidence to check: Management console, share of compliant devices.

IT · question 6 of 14

Security patches are applied within a defined and measured timeframe.

Evidence to check: Patching policy, average timeframe observed.

IT · question 7 of 14

Audit logs are enabled, retained for a defined period and usable for an investigation.

Evidence to check: Retention period, export to a log repository.

IT · question 8 of 14

Security alerts are handled through a written procedure, with a measured time to first response.

Evidence to check: Procedure, sample of tickets, average time.

IT · question 9 of 14

An incident response plan exists, names the roles and has been tested at least once.

Evidence to check: Dated plan, report from the last exercise.

IT · question 10 of 14

Backups are tested by real restores, at a defined frequency.

Evidence to check: Report from the last restore test.

IT · question 11 of 14

Recovery time and acceptable data loss are defined for each critical application.

Evidence to check: Table of recovery objectives, approved by the business.

IT · question 12 of 14

Third-party applications connected to the system are inventoried and their permissions reviewed.

Evidence to check: List of consents, date of last review.

IT · question 13 of 14

A security budget is identified and tracked separately from the general IT budget.

Evidence to check: Budget line, amount, trend.

IT · question 14 of 14

External document sharing is governed by a technical rule, not merely by an instruction.

Evidence to check: Configuration, list of authorised domains.

Human resources · question 1 of 6

When an employee leaves, their access is disabled within a defined and measured timeframe.

Evidence to check: Procedure, average timeframe observed on recent departures.

Human resources · question 2 of 6

When an employee joins, access is granted through a formal request approved by a manager.

Evidence to check: Request form, evidence of approval.

Human resources · question 3 of 6

Security awareness training is delivered on arrival and repeated periodically.

Evidence to check: Material, attendance rate, date of the last session.

Human resources · question 4 of 6

Phishing simulation exercises are run and their results tracked over time.

Evidence to check: Click rate of the most recent campaigns.

Human resources · question 5 of 6

The acceptable use policy is signed, enforceable and known to employees.

Evidence to check: Policy, evidence of signature, coverage rate.

Human resources · question 6 of 6

Internal moves trigger a review of access rights, not merely an addition.

Evidence to check: Internal mobility procedure, sample of cases.

Finance · question 1 of 5

Any change to a supplier's bank details requires verification through an independent channel.

Evidence to check: Written procedure, evidence of a call-back.

Finance · question 2 of 5

Payments above a defined threshold require approval by two separate people.

Evidence to check: Threshold, delegation matrix, audit trail.

Finance · question 3 of 5

Cyber risk is identified in the company's risk register.

Evidence to check: Dated risk register, cyber risk rating.

Finance · question 4 of 5

Cyber insurance cover is in place and its exclusions are known.

Evidence to check: Policy, deductibles, main exclusions.

Finance · question 5 of 5

The financial impact of a business interruption has been estimated.

Evidence to check: Quantified estimate, method used.

Legal and compliance · question 1 of 7

The record of processing activities is kept up to date and a data protection officer is identified.

Evidence to check: Dated record, contact details of the officer.

Legal and compliance · question 2 of 7

Whether NIS2 applies has been analysed and settled, with a written record.

Evidence to check: Analysis note, conclusion, date.

Legal and compliance · question 3 of 7

Critical supplier contracts include security clauses and incident notification obligations.

Evidence to check: Sample of contracts, relevant clauses.

Legal and compliance · question 4 of 7

The procedure for notifying a personal data breach within 72 hours is written and known.

Evidence to check: Procedure, authorised people, last exercise.

Legal and compliance · question 5 of 7

Data retention periods are defined and actually applied.

Evidence to check: Retention policy, evidence of deletion.

Legal and compliance · question 6 of 7

Transfers of data outside the European Union are identified and governed.

Evidence to check: List of transfers, safeguards relied upon.

Legal and compliance · question 7 of 7

Executive management is briefed on the level of cyber risk at least once a year.

Evidence to check: Committee minutes, date.

Operations and business lines · question 1 of 6

Critical business processes are identified and their IT dependencies known.

Evidence to check: Business impact analysis, date of last update.

Operations and business lines · question 2 of 6

A degraded mode of operation exists for critical processes, and it has been tested.

Evidence to check: Degraded operating procedure, exercise report.

Operations and business lines · question 3 of 6

A crisis team is in place and its members can be reached outside the information system.

Evidence to check: Crisis contact list, fallback means of communication.

Operations and business lines · question 4 of 6

Access granted to suppliers and external contributors is named, time-limited and revoked.

Evidence to check: List of external access, end dates.

Operations and business lines · question 5 of 6

Employees know who to report suspicious behaviour to, and they do.

Evidence to check: Reporting channel, number of reports over twelve months.

Operations and business lines · question 6 of 6

The business is involved in the security trade-offs that concern it.

Evidence to check: Minutes, examples of trade-offs.

No personal data is requested. Answers are kept in order to produce the result and are not passed on to third parties.