- Assessment Date*
- What is the current status of policy ownership?*
- What is the current status of formal accountability for cybersecurity governance?*
- What is the current status of executive or board oversight cadence for cybersecurity?*
- What is the current status of documented compliance tracking for cybersecurity requirements?*
- MFA coverage status*
- Account lifecycle management status*
- Configuration baseline enforcement*
- Incident response plan in place*
- Escalation path defined and communicated*
- Lessons-learned tracking after incidents
- Do third-party security requirements exist for vendors and suppliers?*
- Which security attestations are required from critical suppliers?
- Are critical suppliers continuously monitored for material security changes?*
- Target completion date*
- Should be Empty: