-
-
-
- How would you like to complete your assessment?
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Organization's Approximate Annual Revenue
-
-
- Does your organization have a documented cybersecurity mission statement aligned to business objectives?
- Have you formally identified internal and external cybersecurity stakeholders and their expectations?
- Have you documented the legal, regulatory, and contractual cybersecurity requirements that apply to your organization (including privacy and civil liberties)?
- Have you identified critical objectives, capabilities, and services that external stakeholders depend on?
- Have you documented outcomes, capabilities, and services the organization itself depends on (critical dependencies)?
- Are risk management objectives established and formally agreed upon by organizational stakeholders?
- Has your organization established and communicated a written risk appetite / risk tolerance statement?
- Is cybersecurity risk integrated into your enterprise risk management program (ERM)?
- Have you defined and communicated risk response strategies (accept, transfer, mitigate, avoid)?
- Are there established lines of communication across the organization for cybersecurity risks?
- Do you use a standardized method for calculating, documenting, and prioritizing cybersecurity risks?
- Are strategic opportunities (positive risks) characterized and included in cybersecurity risk discussions?
- Is organizational leadership formally accountable for cybersecurity risk and fostering a risk-aware culture?
- Are cybersecurity roles, responsibilities, and authorities formally established and communicated?
- Are adequate resources (budget, headcount, tools) allocated commensurate with the cybersecurity risk strategy?
- Is your cybersecurity policy reviewed, updated, and enforced on a defined schedule (at least annually)?
- Are cybersecurity risk management strategy outcomes regularly reviewed to inform strategy adjustments?
- Is the cybersecurity risk management strategy reviewed and adjusted based on changes in environment, mission, or risk?
- Is organizational cybersecurity performance evaluated and reviewed for adjustments?
- Do you formally understand, document, and communicate the cybersecurity risks posed by each critical supplier/service provider (e.g., via a risk register keyed to supplier tier)?
- Do you handle FCI or CUI / have DoD contracts?
-
- Have you identified and documented the CUI scope (systems, networks, physical locations that process/store/transmit CUI) for your CMMC assessment?
- Do you flow CMMC/DFARS 252.204-7012 / NIST SP 800-171 requirements down to subcontractors who will handle CUI?
-
- Is physical access to facilities containing FCI/CUI restricted to authorized personnel (e.g., badge access, locked server rooms, role-based clearance)?
- Are visitors to sensitive areas escorted at all times and required to sign in/out of an access log?
- Is the physical facility monitored for security (e.g., CCTV, alarm systems, guards) and are security logs reviewed?
- Are physical access logs (badge events, visitor logs, server-room sign-ins) maintained and retained for audit review?
- Do you maintain an inventory of physical access devices (keys, badges, combinations) with a process for issuance, revocation, and periodic review?
- Do you enforce safeguarding requirements (encryption, VPN, approved devices) for work performed at alternative work sites (home offices, co-working, travel)?
-
- Do systems enforce a limit on consecutive unsuccessful logon attempts (account lockout after N failures) per documented policy?
- Do systems display an approved privacy and security notice (warning banner) before granting access, consistent with applicable federal or contractual requirements?
- Do user sessions lock automatically after a defined period of inactivity, requiring re-authentication to resume?
- Are user sessions automatically terminated (not just locked) after a defined condition (e.g., timeout, end-of-shift)?
- Are all remote access sessions to systems containing CUI protected using cryptographic mechanisms (e.g., FIPS-validated VPN, TLS 1.2+)?
- Do you formally limit, track, and disable use of portable storage devices (USB drives, external HDD/SSD) on organizational systems?
-
- Do you synchronize system clocks to an authoritative time source (e.g., NTP tier-1 or DoD time source) to support reliable audit timestamps?
- Are audit logs and audit tools protected from unauthorized access, modification, or deletion (e.g., WORM storage, SIEM integrity, access controls)?
-
- Do you restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services on systems?
-
- Do you prevent reuse of identifiers (usernames, account IDs) for a defined period after account disablement?
- Are user identifiers disabled (not deleted) after a defined period of inactivity?
- Do systems obscure authentication feedback (mask passwords during entry, hide MFA codes in screen shares) to protect against observation?
-
- Do you perform scheduled and approved maintenance on organizational systems, and retain maintenance records?
- Are diagnostic and test programs (e.g., maintenance tools, USB devices used by technicians) inspected for malicious code before connecting to systems containing CUI?
- Are maintenance personnel supervised when they lack required access authorization (e.g., third-party technicians on-site)?
-
- Do you maintain accountability (chain of custody) for media containing CUI during transport outside of controlled areas?
- Do you control the use of removable media on systems that store or process CUI (e.g., whitelist, encrypted-only, auto-scan)?
- Do you prohibit the use of portable storage devices that have no identifiable owner (no tracking/assignment to an individual)?
-
- Do network communications terminate after a defined period of inactivity or at the end of a session (e.g., TCP timeout, VPN tunnel teardown)?
- Is VoIP use controlled and monitored (e.g., documented policy, authorized devices, encryption of signaling/media)?
-
- Do you maintain a Plan of Action and Milestones (POA&M) documenting identified security deficiencies, planned remediation, owners, and due dates?
- Do you perform continuous monitoring of security controls (not only point-in-time) to confirm ongoing effectiveness?
- Do you maintain a System Security Plan (SSP) describing system boundaries, control implementation, and relationships to other systems?
-
- Do you perform threat-informed risk assessments at least annually, incorporating current threat intelligence (e.g., DIB CS, ISAC, CISA)?
- Do you employ advanced automation, analytics, or dedicated staff to identify risks not discovered by standard vulnerability scanning (e.g., attack-path analysis, adversary emulation)?
- Do you formally document, review, and approve the rationale, assumptions, and constraints behind each selected security solution?
- Do you regularly evaluate the effectiveness of security solutions (e.g., red-team/BAS results, control testing, KPI review) and adjust accordingly?
- Do you conduct penetration testing annually that specifically exercises CUI-handling boundaries (not just public web assets)?
-
-
-
-
-
-
-
-
- Do you have an up-to-date IT Asset List?
- Do you utilize an Asset and Inventory Management System?
-
- Do you have documented representations (diagrams, maps) of authorized network communications and external connections?
- Are assets prioritized based on classification, criticality, and business impact?
- Are systems, hardware, software, services, and data managed throughout their full lifecycle (acquisition -> decommission)?
- Do you address unauthorized assets/devices when discovered (remove, quarantine, or authorize)?
- Do you use an active/passive discovery tool to identify unauthorized assets on the network?
- Do you address unauthorized software on enterprise assets (allowlist/block/remove)?
- Do you use automated software inventory tools?
- Do you ensure authorized software is supported by the vendor (no end-of-life without documented exception)?
-
-
-
-
- Do you have a Vendor Risk Management solution in place?
-
-
-
- Does any of your Staff work remotely?
- Does your IT + Cyber Security Staff work remotely?
-
- Are your employees subject to ongoing Background Checks?
-
- Are your employees subject to ongoing Identity Screening + Monitoring?
-
- Do you have a written Employee Policy in place for employees to notify your organization of Identity Breaches?
-
- Please tell us if any of the following Corporate Devices are issued to employees?
- Are your employees permitted to use their own Personal Devices?
- Does your organization utilize any of the following Mobile Devices in the course of operations?
- Do you have a Mobile Device Management solution implemented for all related devices?
-
- Do you have Mobile Protection and Information-Centric Endpoint Protection?
-
- Please indicate any Digital Assets that your organization owns:
- Do you have a Digital Asset Management Program?
-
- Are cybersecurity roles and responsibilities for suppliers, customers, and partners formally established, communicated, and coordinated?
- Is supply chain cybersecurity risk management integrated into your cybersecurity and enterprise risk management process?
- Do you classify and/or tier your service providers based on sensitivity and criticality?
- Do you formally assess service providers before onboarding AND periodically thereafter?
- Are relevant suppliers and third parties included in your incident response planning, exercises, and playbooks?
- Do you have a documented service provider decommissioning process (credential revocation, data return/destruction, access removal)?
- Do you classify data based on sensitivity (e.g., public, internal, confidential, restricted)?
- Are data access control lists configured to enforce least-privilege access to sensitive data?
- Do you enforce a documented data retention policy?
- Do you have a documented secure data disposal / media sanitization process?
- Do you maintain documented data flow diagrams for sensitive data?
- Do you encrypt data on removable media?
- Is sensitive data segmented from non-sensitive processing environments?
-
- Is your organization using any Web / Cloud Services?
-
-
-
-
-
- Are you using any Cloud Security Posture Management tools that covers all cloud risks: spanning misconfigurations, vulnerabilities, identity risks, data security, API / PII / crown jewel asset exposure, and advanced threats?
-
- Are you using any Cloud Native Endpoint Detection and Response solutions?
-
-
- Do you provide Remote Access of any kind to staff or customers / members?
-
- Do you have any Remote Monitoring tools in place for controlling the Configuration and State of systems?
-
-
- Do you have Endpoint Detection & Response (EDR)?*
-
- Do you have Next Generation Anti-Virus on all endpoints?*
-
- Do you have Managed Detection & Response (MDR) in place for all sources of active detection?*
-
- Do you have a Vulnerability Assessment and Management solution to discover and assess assets in your environment, including dynamic cloud or remote workforce assets?
-
-
- Do you have Advanced Email Protection for O365/G-Suite as well as your cloud-based collaboration platforms including: pre and post delivery protection, URL and attachment sandboxing, anti-malware scanning, data loss prevention, and encryption?*
-
- Do you have Multi-factor Authentication (MFA) implemented for all users?*
- Do you have Multi-factor Authentication (MFA) implemented for all remote access and 3rd party applications?*
-
- Do you have Password Identity Management and Administration tools in place?
-
- Do you have Access and Rights Management tools in place?
-
- Do you have Application Safelisting (whitelisting / blacklisting) enabled for all workstations and servers?*
- Do you have Zero Trust Segmentation implemented for all endpoints?*
-
- Do you use a Zero Trust Network Access Solution to control remote access?*
-
- Do you have Privileged Access Management (PAM) implemented for all privileged accounts?*
-
- Do you currently have Segregation of Duties + Business Controls in place for all outgoing payments / funds transfers?*
- Do you have Single Sign On (SSO) enabled and configured for all 3rd party applications?*
- Do you have At-Rest Encryption enabled for all endpoints and devices?*
- Do you have a formal Patch Management Program in place which is informed by critical security and vulnerability data within 30 days?*
- Do you have an Immutable Backup Strategy (REQUIRES: 3+ backup sources covering all systems / data and 1+ offline / inaccessible from the network where the systems/data reside)?*
-
- Do you have a Log Resilience/Centralization Platform (such as a SIEM)?*
-
- Do you have Next Generation Firewalls at all locations (REQUIRES: inbound / outbound proxy, threat detection, DoS protection, etc)?*
- Do you have a Data Loss Prevention (DLP) solution deployed?*
- Do you log sensitive data access?*
- Is data in use protected (e.g., memory protection, confidential computing, runtime protections)?*
- Is automatic session locking configured on endpoints and servers?*
- Do you run host-based firewalls on servers and end-user devices?*
- Are administrative/management channels for enterprise assets secured (out-of-band, jump hosts, bastion, dedicated admin workstations)?*
- Are default accounts on enterprise assets and software disabled, removed, or renamed and secured?*
- Are unnecessary services disabled or uninstalled on enterprise assets and software?*
- Are trusted DNS servers configured on enterprise assets?*
- Do you maintain an inventory of all accounts (user + service + admin)?*
- Do you disable dormant accounts after a defined period of inactivity (e.g., 45 days)?*
- Do you maintain an inventory of authentication and authorization systems (IdPs, directories, access brokers)?*
- Do you have a documented vulnerability remediation process (SLAs by severity, exceptions, tracking)?*
- Do you ingest threat intelligence and track known threats relevant to your environment?*
- Do you evaluate potential impacts and likelihoods of threats exploiting vulnerabilities?*
- Are changes and exceptions managed, assessed for risk impact, recorded, and tracked?*
- Do you have a process to receive, analyze, and respond to external vulnerability disclosures (e.g., a VDP or security@ mailbox)?*
- Do you assess the authenticity/integrity of hardware and software prior to acquisition (SBOM, signed software, vendor attestations)?*
- Do you ensure adequate log storage capacity and retention consistent with policy/regulation?*
- Is time synchronized across systems (NTP from trusted sources)?*
- Do you collect DNS, URL, and command-line audit logs?*
- Do you ensure only supported browsers and email clients are in use (no EOL)?*
- Do you use DNS filtering services on all enterprise assets?*
- Do you enforce network-based URL filtering?*
- Do you restrict unnecessary / unauthorized browser and email client extensions?*
- Have you implemented DMARC (plus SPF and DKIM) for all sending domains?*
- Have you disabled autorun/autoplay on removable media across endpoints?*
- Is anti-malware scanning configured to run automatically on removable media insertion?*
- Are anti-exploitation features (e.g., DEP, ASLR, CFG, EMET-equivalent) enabled on endpoints?*
- Is anti-malware centrally managed across the enterprise?*
- Is your network infrastructure firmware / OS up-to-date (no EOL/EOS devices)?*
- Do you maintain current network architecture diagrams?*
- Do you centralize AAA (authentication, authorization, accounting) for network infrastructure (e.g., RADIUS/TACACS+ with SSO/MFA)?*
- Do you use secure network management and communication protocols (SSH/HTTPS/SNMPv3 - no Telnet/SNMPv1)?*
- Do you have host-based intrusion detection deployed on servers/endpoints?*
- Do you have network intrusion prevention (NIPS) deployed at the perimeter/between segments?*
- Is the physical environment (data centers, wiring closets) monitored for tampering/unauthorized access?*
- Are environmental threats (fire, flood, power, HVAC) addressed with appropriate controls?*
- Are resilience mechanisms (redundancy, failover, capacity) implemented to meet availability requirements?*
- Is hardware maintained, replaced, and securely removed in alignment with risk?*
- Are identities proofed and bound to credentials based on the context of interactions (identity proofing per NIST 800-63-3 equivalent)?*
- Are identity assertions protected, conveyed, and verified (e.g., signed SAML/OIDC assertions)?*
- Do you collect DHCP lease logs (assignments, releases, conflicts) and retain them for asset inventory and incident investigation?*
- Is sensitive data encrypted in transit across untrusted networks (TLS 1.2+/IPsec) with weak ciphers disabled?*
- Do end-user devices automatically lock after a defined period of inactivity (e.g., 15 minutes) and after a limited number of failed login attempts?*
- Do you actively monitor service providers' security posture (e.g., annual attestation review, continuous monitoring tools, breach notification SLAs) and log/review provider access to your systems?*
- Do you monitor activity performed by external service providers (remote admin sessions, API usage, data egress by third parties) for anomalous or unauthorized behavior?*
-
- Do you have Operational Technologies?
- Do you have Operational Technology Detection and Response solutions?
-
- Do you develop Applications or Custom Code for yourself or customers?
- Do you have Application and Code Security solution in place?
-
- Do you develop Web Applications or APIs, or utilize APIs for any of your own Web Applications?
- Do you have Web Application and API Security solutions in place?
-
- Do you host your own Custom Email or any similar Custom Applications?
- Do you have a DDoS Attack Mitigation solution in place?
-
- Do you perform root-cause analysis on security vulnerabilities found in your applications?
- Do you use a formal severity rating system for application vulnerabilities (e.g., CVSS) with remediation SLAs?
- Are standard hardening configuration templates used for application infrastructure?
- Are production and non-production systems formally separated (distinct accounts, networks, and data)?
-
- Do you have a Written Cyber Security Program in place which aligns with regulatory requirements and/or industry standards (NIST, CIS, etc)?*
-
- Is your organization (OR any of your customers) subject to additional regulatory requirements by any of the following regulated industries?
- Do you have an Incident Response Plan in place currently?
- Is your Incident Response Plan approved by your insurance carrier?
- Do you have a dedicated Computer Security Incident Response Team (CSIRT)?
-
- Is your Computer Security Incident Response Team (CSIRT) approved by and aligned with your insurance carrier?
-
-
- Do you have a formal Security Awareness Training program with mandatory annual completion for all workforce?
- Does training cover recognizing social engineering / phishing attacks?
- Does training cover authentication best practices (password hygiene, MFA, passkeys)?
- Does training cover causes of unintentional data exposure (misconfig, accidental share, shadow IT)?
- Does training cover how to recognize and report security incidents?
- Does training cover how to identify and report missing/outdated security updates on assets?
- Does training cover dangers of connecting to / transmitting data over insecure networks?
- Do privileged role holders (admins, developers, IT staff) receive specialized, role-specific training at hire and at least annually?
- Have you assigned documented key roles and responsibilities in your Incident Response Plan (including executive sponsor, IC, legal, communications)?
- Have you established and documented incident severity thresholds / declaration criteria?
- Are incoming incident reports triaged and validated per a documented process?
- Are incidents formally categorized and prioritized on declaration?
- Are incidents escalated or elevated per a defined matrix (severity x role)?
- Are criteria defined and applied for initiating incident recovery?
- Is root-cause analysis performed for declared incidents, documented, and integrated into improvements?
- Are investigator actions recorded with chain-of-custody / integrity preservation?
- Is incident magnitude formally estimated and validated during response?
- Do you have documented containment procedures for common incident types (ransomware, BEC, data exfil)?
- Do you have documented eradication procedures for removing attacker presence?
- Is adverse-event impact/scope analysis performed (what was touched, how much data, what users)?
- Is adverse-event information provided to authorized staff and tools (SOAR, ticketing, ChatOps)?
- Is cyber threat intelligence integrated into adverse-event analysis?
- Do you have a documented recovery plan integrated with the Incident Response Plan?
- Are recovery actions selected, scoped, and prioritized per plan during incident response?
- Is backup/restoration asset integrity verified before use in recovery?
- Are critical mission functions considered to establish recovery priorities (RTO/RPO)?
- Is integrity of restored assets verified and normal operations formally declared resumed?
- Is the end of incident recovery declared based on defined criteria, and is documentation completed?
- Are recovery activities communicated to internal and external stakeholders per plan?
- Are public recovery updates provided using approved messaging and channels (PR/comms plan)?
- Are improvement opportunities formally captured from evaluations, exercises, and incidents?
- Do you have a formal Penetration Testing Program documenting scope, frequency, and rules of engagement?
- Do you perform external penetration tests at least annually?
- Do you perform internal penetration tests at least annually?
- Are penetration test findings tracked through to remediation with validation retesting?
- Do you validate security controls regularly (breach-attack simulation, purple team, control testing)?
- Does your Security Awareness Training include data handling best practices (classification, storage, transmission, disposal) with role-specific content for staff who handle sensitive data?
-
- Does your organization currently have Cyber Liability Insurance?
-
-
- Is the insurance policy part of a Group/Membership Plan or your own coverage?
-
-
- When is the Renewal Date for this policy?
- Have you received an Offer for Renewal?
-
- Is Cyber Liability Insurance desired?
-
- When would you like coverage to begin?
- Please indicate if you would like recommendations for any additional coverage:
-
-
- Date Submitted*
-
- Should be Empty: