Self-assessment · Information security

ISO 27001 Self-Assessment

In 15 simple questions, find out whether your company is ready to pursue ISO 27001 certification (the leading standard for protecting your information). Instant score; detailed per-criterion analysis on request.

No expertise required: answer honestly, based on your organisation’s real situation. It takes about 5 minutes.

  1. 1

    Do you know which sensitive information you need to protect, and where it is?

  2. 2

    Has management put its information security rules in writing?

  3. 3

    Is it clear who is responsible for IT security in the company?

  4. 4

    Do you take the time to identify the main threats to your information?

  5. 5

    For each important risk, have you decided and written down what you do to reduce it?

  6. 6

    Do you keep an up-to-date list of your key equipment, software and data?

  7. 7

    Do you control who has access to what, and remove access as soon as it is no longer needed?

  8. 8

    Do you train employees on security (passwords, phishing) and handle joiners and leavers properly?

  9. 9

    Do you check that your providers and suppliers protect your data properly?

  10. 10

    Do you know how to react to an incident (hack, data leak or loss)?

  11. 11

    Could you keep working after a major IT outage or disaster, and have you tested it?

  12. 12

    Do you keep a record of logins and activity to spot unusual behaviour?

  13. 13

    Do you physically protect your premises, equipment and sensitive backups?

  14. 14

    Do you regularly check, yourself, that your security rules are actually applied?

  15. 15

    Does management regularly review security in order to improve it?

0 / 15