ERP Security Management Assessment Questionnaire Form
Evaluate your organization's ERP security management practices using this concise assessment form.
How well-defined are your ERP security policies and procedures?
*
Not defined
1
2
3
4
Fully defined and enforced
5
1 is Not defined, 5 is Fully defined and enforced
Please rate the effectiveness of user access controls within your ERP system.
*
1
2
3
4
5
How frequently are ERP user access rights reviewed and updated?
*
Quarterly
Bi-annually
Annually
Rarely/Never
Indicate your agreement with the following ERP security management statements.
*
Rows
Strongly Disagree
Disagree
Neutral
Agree
Strongly Agree
ERP security roles are clearly defined
1
2
3
4
5
System activity logs are regularly reviewed
6
7
8
9
10
Segregation of duties is enforced in the ERP
11
12
13
14
15
ERP security incidents are documented and analyzed
16
17
18
19
20
Is multi-factor authentication (MFA) enabled for ERP system access?
*
Yes, for all users
Yes, for privileged users only
No
How would you rate the frequency and quality of ERP security awareness training provided to users?
*
1
2
3
4
5
Which of the following best describes your ERP system's vulnerability management process?
*
Proactive (regular scanning and patching)
Reactive (patching after incidents)
Ad-hoc or infrequent
Please indicate how often your organization performs ERP security audits.
*
Annually
Every 2-3 years
Never
How confident are you in your ERP incident response plan?
*
Not confident
1
2
3
4
Highly confident
5
1 is Not confident, 5 is Highly confident
Please share any additional comments or observations about your ERP security management.
Submit Assessment
Should be Empty: