Data Flow Security Assessment Form
Assess how data moves and is secured throughout your system.
What is the primary purpose of the system being assessed?
*
Which types of data does the system process?
*
Customer data
Internal business data
Operational/transactional data
Configuration/metadata
Other
How is data typically transferred between components?
*
Internally over private network
Over the internet (encrypted)
Over the internet (unencrypted)
Via third-party services/APIs
Other
Please rate the adequacy of access controls for each data flow stage.
*
Rows
Not Adequate
Partially Adequate
Adequate
Excellent
Data Entry
1
2
3
4
Data Storage
5
6
7
8
Data Transfer
9
10
11
12
Data Processing
13
14
15
16
Data Deletion
17
18
19
20
Are all data transfers encrypted end-to-end?
*
Yes, always
Sometimes, depending on the flow
No
Not sure
How frequently are data flow paths reviewed for security risks?
*
At least quarterly
Annually
Rarely
Never
Please rate the overall visibility and monitoring of data flows in your system.
*
1
2
3
4
5
Which of the following best describes your incident response process for data flow breaches?
*
Formal documented process
Ad hoc response
No defined process
Not sure
Select the primary controls in place to prevent unauthorized data flow.
*
Network segmentation
Firewall rules
Data loss prevention (DLP)
Role-based access controls
Other
Describe any known challenges or risks associated with your current data flow design.
*
Submit Assessment
Should be Empty: