ISO 27002 Risk Assessment Questionnaire Form
Evaluate your organization's information security risks and control maturity with this ISO 27002-aligned assessment.
How would you rate your organization's overall information security risk level?
*
Very Low
Low
Moderate
High
Very High
Please assess the maturity of your organization's information security policies.
*
No policy
1
2
3
4
Fully implemented & reviewed
5
1 is No policy, 5 is Fully implemented & reviewed
How effective are your access control measures?
*
1
2
3
4
5
Incident Response Readiness
*
Rows
Not Implemented
Partially Implemented
Fully Implemented
Incident detection process
1
2
3
Incident response plan
4
5
6
Post-incident review
7
8
9
How frequently are information security risks reviewed?
*
Quarterly
Bi-annually
Annually
Ad hoc
Evaluate asset management practices in your organization.
*
No inventory
1
2
3
4
Comprehensive & updated
5
1 is No inventory, 5 is Comprehensive & updated
To what extent are supplier information security requirements defined and monitored?
*
Not defined
Partially defined
Fully defined and monitored
Physical and Environmental Security
*
Rows
Not Implemented
Partially Implemented
Fully Implemented
Physical access controls
10
11
12
Equipment security
13
14
15
Environmental controls
16
17
18
How well are employees aware of security policies and procedures?
*
Not aware
1
2
3
4
Fully aware
5
1 is Not aware, 5 is Fully aware
Describe any recent improvements or planned actions for your information security program.
Submit Assessment
Should be Empty: