1 / 20
Is MFA mandatory for administrators and remote access?
2 / 20
Are accounts removed promptly when someone leaves?
3 / 20
Are access rights reviewed periodically?
4 / 20
Do you maintain an up-to-date inventory of critical systems and applications?
5 / 20
Has a formal risk assessment been performed in the last 12 months?
6 / 20
Do you have an incident response procedure?
7 / 20
Is it clear who must report and handle security incidents?
8 / 20
Are incidents centrally registered?
9 / 20
Are backups created automatically?
10 / 20
Is restore from backup tested regularly?
11 / 20
Do you have a business continuity or recovery plan?
12 / 20
Are critical suppliers assessed for security?
13 / 20
Are security requirements included in supplier agreements or contracts?
14 / 20
Do you maintain an up-to-date supplier register?
15 / 20
Do employees receive periodic security awareness training?
16 / 20
Do you run phishing or social-engineering exercises?
17 / 20
Are systems and software patched systematically?
18 / 20
Is endpoint protection centrally managed?
19 / 20
Are key security measures documented with evidence?
20 / 20
Does management review information security periodically?