Page 1 of 1
CIS IG1 — SMB Cyber Hygiene Assessment
20 quick questions on your security maturity. Rate each on a 0–4 scale: 0 = Not in place · 1 = Ad hoc · 2 = Partial · 3 = Mostly · 4 = Fully / optimized.
About you & your organization
First name
*
Last name
*
Company name
*
Business email
*
Phone
Website
Company size
*
Organization type
*
Primary pain point
*
Compliance need
*
Asset Inventory & Configuration
Hardware asset inventory accuracy (laptops/servers/mobile/cloud)
*
0
1
2
3
4
Not in place
Fully / optimized
Software/application inventory documentation
*
0
1
2
3
4
Not in place
Fully / optimized
Secure baseline configuration documentation for new OS/software
*
0
1
2
3
4
Not in place
Fully / optimized
Centralized enforcement/verification of secure configurations
*
0
1
2
3
4
Not in place
Fully / optimized
Review/update frequency for network device software (firewalls/routers/switches)
*
0
1
2
3
4
Not in place
Fully / optimized
Identity & Access Control
MFA implementation for user/admin accounts (cloud/critical systems/VPN)
*
0
1
2
3
4
Not in place
Fully / optimized
Least privilege enforcement for user accounts
*
0
1
2
3
4
Not in place
Fully / optimized
Speed of disabling terminated/inactive accounts (including credentials)
*
0
1
2
3
4
Not in place
Fully / optimized
Need-to-know access control for sensitive data (PII/financial)
*
0
1
2
3
4
Not in place
Fully / optimized
Security awareness education standardization
*
0
1
2
3
4
Not in place
Fully / optimized
Vulnerability & Endpoint Defense
Endpoint protection/anti-malware coverage across assets
*
0
1
2
3
4
Not in place
Fully / optimized
Anti-malware signature/software update reliability
*
0
1
2
3
4
Not in place
Fully / optimized
Vulnerability assessment/tracking process formalization
*
0
1
2
3
4
Not in place
Fully / optimized
OS patching effectiveness (routine/automated/timely)
*
0
1
2
3
4
Not in place
Fully / optimized
Third-party app patching effectiveness (routine/automated/timely)
*
0
1
2
3
4
Not in place
Fully / optimized
Recovery & Monitoring
Backup automation/consistency for critical data & configurations
*
0
1
2
3
4
Not in place
Fully / optimized
Offline/isolated/segmented backup copy protections (ransomware/breach)
*
0
1
2
3
4
Not in place
Fully / optimized
Backup recovery testing frequency (sample restores)
*
0
1
2
3
4
Not in place
Fully / optimized
Security log collection/retention from key assets
*
0
1
2
3
4
Not in place
Fully / optimized
Incident triage/communication/response procedure definition
*
0
1
2
3
4
Not in place
Fully / optimized
Submit