Cybersecurity Assessment System Evaluation Checklist Form
Use this checklist to evaluate the cybersecurity assessment system, review control coverage, and record findings, risk level, and recommended actions.
Assessment Context
System Name
*
Organization / Team Name
*
Evaluator Name or Role
*
Evaluation Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Assessment Type
*
Internal Review
External Audit
Periodic Check
Post-Incident Review
Other
System / Environment Being Evaluated
*
Please Select
Production
Staging
Development
Cloud
On-Premises
Hybrid
Other
System Scope and Coverage
System scope coverage ratings
*
Rows
Not assessed
Needs improvement
Adequate
Strong
Not applicable
Network security
1
2
3
4
5
Endpoint security
6
7
8
9
10
Access control
11
12
13
14
15
Vulnerability management
16
17
18
19
20
Logging and monitoring
21
22
23
24
25
Incident response
26
27
28
29
30
Backup and recovery
31
32
33
34
35
Patch management
36
37
38
39
40
Configuration management
41
42
43
44
45
Third-party risk
46
47
48
49
50
Notes for network security
Notes for endpoint security
Notes for access control
Notes for vulnerability management
Notes for logging and monitoring
Notes for incident response
Notes for backup and recovery
Notes for patch management
Notes for configuration management
Notes for third-party risk
Control Evaluation
Authentication Controls Effectiveness
*
Ineffective
1
2
3
4
5
6
7
8
9
Highly Effective
10
1 is Ineffective, 10 is Highly Effective
Privileged Access Management Effectiveness
*
Ineffective
1
2
3
4
5
6
7
8
9
Highly Effective
10
1 is Ineffective, 10 is Highly Effective
Encryption Practices Effectiveness
*
Ineffective
1
2
3
4
5
6
7
8
9
Highly Effective
10
1 is Ineffective, 10 is Highly Effective
Security Awareness and Training Effectiveness
*
Ineffective
1
2
3
4
5
6
7
8
9
Highly Effective
10
1 is Ineffective, 10 is Highly Effective
Malware Protection Effectiveness
*
Ineffective
1
2
3
4
5
6
7
8
9
Highly Effective
10
1 is Ineffective, 10 is Highly Effective
Vulnerability Scanning Frequency
*
Ad Hoc
1
2
3
4
5
6
7
8
9
Continuous
10
1 is Ad Hoc, 10 is Continuous
Incident Detection Capability
*
Poor
1
2
3
4
5
6
7
8
9
Excellent
10
1 is Poor, 10 is Excellent
Remediation Workflow Effectiveness
*
Poor
1
2
3
4
5
6
7
8
9
Excellent
10
1 is Poor, 10 is Excellent
Policy Compliance
*
Non-Compliant
1
2
3
4
5
6
7
8
9
Fully Compliant
10
1 is Non-Compliant, 10 is Fully Compliant
Overall Control Maturity Rating
*
1
2
3
4
5
Risk and Findings Summary
Risk Level of the System
*
Low
Medium
High
Critical
Number of Findings or Issues Identified
*
Highest-Priority Issue Summary
*
Recommended Remediation Actions
*
Target Remediation Timeframe
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Follow-Up Required?
*
Yes, follow-up needed
No, follow-up not needed
Submit Assessment
Should be Empty: