Self-assessment · Information security
ISO 27001 Self-Assessment
In 15 simple questions, find out whether your company is ready to pursue ISO 27001 certification (the leading standard for protecting your information). Instant score; detailed per-criterion analysis on request.
No expertise required: answer honestly, based on your organisation’s real situation. It takes about 5 minutes.
- 1
Do you know which sensitive information you need to protect, and where it is?
- 2
Has management put its information security rules in writing?
- 3
Is it clear who is responsible for IT security in the company?
- 4
Do you take the time to identify the main threats to your information?
- 5
For each important risk, have you decided and written down what you do to reduce it?
- 6
Do you keep an up-to-date list of your key equipment, software and data?
- 7
Do you control who has access to what, and remove access as soon as it is no longer needed?
- 8
Do you train employees on security (passwords, phishing) and handle joiners and leavers properly?
- 9
Do you check that your providers and suppliers protect your data properly?
- 10
Do you know how to react to an incident (hack, data leak or loss)?
- 11
Could you keep working after a major IT outage or disaster, and have you tested it?
- 12
Do you keep a record of logins and activity to spot unusual behaviour?
- 13
Do you physically protect your premises, equipment and sensitive backups?
- 14
Do you regularly check, yourself, that your security rules are actually applied?
- 15
Does management regularly review security in order to improve it?
0 / 15