Question 1 of 8
Do you have a written, up-to-date information security policy?
Question 2 of 8
Do you have a documented incident response plan that has been tested in the last year?
Question 3 of 8
Do employees receive security awareness training at least annually?
Question 4 of 8
Do you have a data breach notification procedure that meets your regulatory deadlines?
Question 5 of 8
Do you assess the security posture of vendors and third parties with access to your data?
Question 6 of 8
Do you maintain an inventory of what data you hold and where it lives?
Question 7 of 8
Have you had a third-party vulnerability assessment or penetration test in the last 12 months?
Question 8 of 8
Do you have a documented data retention and disposal policy?
Which frameworks apply to your organization? (optional)