Internet Service Provider Security Evaluation Questionnaire
Please complete this questionnaire to help us assess your organization's security posture and practices as an Internet Service Provider.
Which of the following security frameworks does your organization align with?
*
ISO/IEC 27001
NIST Cybersecurity Framework
CIS Controls
None of the above
Other
How frequently does your organization conduct security risk assessments?
*
Quarterly
Bi-annually
Annually
As needed
Never
Please rate the effectiveness of your organization's network monitoring and intrusion detection systems.
*
1
2
3
4
5
Which of the following access controls are implemented for administrative systems?
*
Multi-factor authentication
Role-based access control
Least privilege principle
Password policies
Other
Does your organization maintain an incident response plan?
*
Yes, fully documented and tested
Yes, documented but not regularly tested
In development
No
How often are employees trained on security awareness topics?
*
At onboarding and annually
Annually
Bi-annually
Never
Please indicate which of the following security measures are applied to customer data.
*
Data encryption at rest
Data encryption in transit
Data loss prevention (DLP)
Regular data backups
Other
Vulnerability Management Practices
*
Rows
Not Implemented
Partially Implemented
Fully Implemented
Regular vulnerability scanning
1
2
3
Patch management process
4
5
6
Third-party software updates
7
8
9
How does your organization handle third-party vendor risk assessments?
*
Comprehensive reviews before onboarding and annually
Reviews before onboarding only
Ad-hoc reviews as needed
No formal process
Please provide any additional comments or details regarding your organization's security practices.
Submit
Should be Empty: