Information Security GRC Assessment Form
Assess your organization’s governance, risk, and compliance posture for information security. Complete the fields below to summarize scope, current status, and priorities.
Assessment Overview
Organization Name
*
Department / Business Unit
Please Select
Finance
Human Resources
Information Technology
Legal
Operations
Sales
Other
Assessment Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Assessment Type / Scope
*
Annual Review
Ad Hoc Review
Vendor Assessment
Internal Audit Follow-up
Other
Governance and Risk Posture
Current security policy review status
*
Current
Overdue
In progress
Not established
Top risk domains needing attention
*
Access control
Asset management
Incident response
Third-party risk
Data protection
Vulnerability management
Business continuity
Security awareness
Other
Overall governance, risk, and compliance maturity
*
Ad hoc
1
2
3
4
5
6
7
8
9
Optimized
10
1 is Ad hoc, 10 is Optimized
Compliance and Control Tracking
Applicable frameworks or obligations
*
Internal policy
ISO 27001
NIST CSF
SOC 2
PCI DSS
GDPR
Other
Control implementation status summary
*
Rows
Implemented
Partially implemented
Not implemented
Notes
Access control
1
2
3
Asset management
4
5
6
Incident response
7
8
9
Risk assessment
10
11
12
Vendor management
13
14
15
Primary remediation priority
*
Highest risk exposure
Regulatory obligation
Audit finding
Customer requirement
Operational impact
Other
Target review completion date
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Submit Assessment
Should be Empty: