Do you have a formal information security management system in place?

Yes
No

Is there senior leadership sponsorship for security initiatives?

Yes
No

Do you store or process any Personally Identified Information?

Yes
No

Are any of your applications or systems hosted in cloud infrastructure?

Yes
No

Do you have a information security Policy in place?

Yes
No

Do you have security council established that makes security related decisions?

Yes
No

Do you have Cyber incident policy in place?

Yes
No

Do you have data protection policy established and operationalized?

Yes
No

Do you have formal patch management process established?

Yes
No

Do you conduct regular security penetration testing?

Yes
No

Do you conduct vulnerability assessment on a regular basis?

Yes
No

Do you have a Security Information and Event Management system?

Yes
No

Do you have Host Intrusion Detection systems installed on all servers and devices?

Yes
No

Do you have a firewall in place?

Yes
No

Do you have Host Prevention Detection systems installed on all servers and devices?

Yes
No

Do you have Data loss prevention in place?

Yes
No
Total Score: 0