Security

Information security readiness.

Answer ten questions against a recent case. Your responses remain in this browser.

Self-assessment

Describe what you can evidence.

01Is there an agreed scope for information and systems?
02Are security risks assessed with owners and treatment decisions?
03Are suppliers and access rights reviewed?
04Are incidents rehearsed and lessons retained?
05Is there a named owner for the information security readiness work and a clear escalation route?
06Can you retrieve a dated example that supports a claim made in this security assessment?
07Have the people who perform or depend on this work tested the current description against reality?
08Are changes, exceptions and unintended effects recorded and reviewed?
09Do you know which legal, customer, contractual or standard requirements actually apply?
10Can you show a decision from a recent review and whether its action worked?

Your result

A starting point, not a verdict.

Complete the questions to see a suggested priority. Nothing is sent to a server.

From score to action

Make the result useful.

Ask for a dated example for every answer scored 2. Compare the lowest three items with the outcome you want and the applicable requirements. Do not average away a critical risk.

  1. Describe the gap as an observable event and consequence.
  2. Name the action owner, due date, resource and evidence to keep.
  3. Check the action against a later real case and record any unintended effect.

Method and boundaries

Use the score responsibly.

Ten self-reported questions use a 0–2 scale: not in place, partly in place, working and evidenced. Use a recent real case for each answer. The result identifies discussion priorities; it is not an audit, legal opinion or certification decision.

Take the three lowest-scoring answers into a 30-minute review. For each, name the outcome, owner, evidence to inspect, action, due date and effectiveness check.