Governance 1–5
1. Someone in our organization is clearly accountable for governance and technology risk.
2. We have a documented risk register or equivalent risk-tracking tool.
3. Key policies are formally approved and reviewed on a schedule.
4. Management receives regular reporting on risk and control performance.
5. Risk acceptance decisions are documented and authorized at an appropriate level.
Risk 6–10
6. We have identified our most critical business processes and dependencies.
7. Risks are assessed using both likelihood and impact, not just gut feel.
8. We have a defined risk appetite or tolerance level.
9. Risks are reassessed periodically, not just once.
10. We consider emerging risks — new technology, new threats — as part of our process.
Cybersecurity 11–15
11. Multi-factor authentication is enforced for privileged and remote access.
12. We maintain an inventory of critical systems and cloud assets.
13. Vulnerabilities are identified and remediated on a risk-based timeline.
14. We have a documented incident response plan.
15. Employees receive security awareness training appropriate to their role.
Compliance 16–20
16. We know which laws, regulations, and contractual obligations apply to us.
17. Compliance obligations are assigned to accountable owners.
18. We monitor for changes in applicable regulatory requirements.
19. We can produce evidence supporting our compliance claims on request.
20. We have a process for preparing for customer or regulatory audits.
Third Parties 21–25
21. We maintain a complete inventory of material vendors.
22. Vendors are assessed for risk before onboarding.
23. Contracts include security, privacy, and incident notification requirements.
24. Critical vendors are reassessed periodically, not just once.
25. We know what would happen to us if a critical vendor failed or was breached.