- Assessment Date*
- Asset and System Inventory*
- System Criticality*
- Internet Connectivity*
- Remote Access Enabled*
- Cybersecurity policies documented and approved*
- Asset management process in place*
- Access control enforced for systems and data*
- Multi-factor authentication enabled for critical access*
- Password hygiene requirements enforced*
- Patch management process regularly applied*
- Vulnerability scanning performed on a regular schedule*
- Network segmentation implemented to limit lateral movement*
- Endpoint protection deployed and centrally managed*
- Encryption, backup, restore testing, vendor risk management, and security training are established*
- Is there a documented incident response plan for cyber incidents?*
- Ransomware preparedness status*
- Date of last tabletop exercise
- Top cyber threats affecting operations*
- Should be Empty: