Page 1 of 1
CSFv2 Assessment
20 quick questions on your security maturity. Rate each on a 0–4 scale: 0 = Not in place · 1 = Ad hoc · 2 = Partial · 3 = Mostly · 4 = Fully / optimized.
About you & your organization
First name
*
Last name
*
Company name
*
Business email
*
Phone
Website
Company size
*
Organization type
*
Primary pain point
*
Compliance need
*
Govern (GV)
Risk Management Strategy: maturity of the cybersecurity risk-management strategy and its integration into enterprise risk management (ERM)
*
0
1
2
3
4
Not in place
Fully / optimized
Roles and Responsibilities: extent cybersecurity roles, responsibilities, and authorities are established and communicated
*
0
1
2
3
4
Not in place
Fully / optimized
Cybersecurity Supply Chain Risk Management (C-SCRM): how effectively supply-chain cyber risks are identified, assessed, and managed
*
0
1
2
3
4
Not in place
Fully / optimized
Oversight: process for using cybersecurity results and performance reviews to inform and adjust the risk-management strategy
*
0
1
2
3
4
Not in place
Fully / optimized
Identify (ID)
Asset Management: completeness/accuracy of inventories of critical assets (hardware, software, services, data) and their lifecycles
*
0
1
2
3
4
Not in place
Fully / optimized
Risk Assessment: extent threats and vulnerabilities to assets and objectives are continuously identified, analyzed, documented
*
0
1
2
3
4
Not in place
Fully / optimized
Risk Response and Tracking: how effectively risk responses are chosen, prioritized, planned, and tracked
*
0
1
2
3
4
Not in place
Fully / optimized
Improvement: consistency of identifying and prioritizing improvements from lessons learned, tests, and operational feedback
*
0
1
2
3
4
Not in place
Fully / optimized
Protect (PR)
Identity Management, Authentication & Access Control: effectiveness at enforcing least privilege for users, services, and hardware
*
0
1
2
3
4
Not in place
Fully / optimized
Awareness and Training: extent all personnel receive role-appropriate cybersecurity awareness and training
*
0
1
2
3
4
Not in place
Fully / optimized
Data Security: maturity of safeguards (encryption, backups, secure disposal) protecting data at rest and in transit
*
0
1
2
3
4
Not in place
Fully / optimized
Platform Security: maturity of configuration management and secure software-development practices protecting platforms
*
0
1
2
3
4
Not in place
Fully / optimized
Detect (DE)
Continuous Monitoring: capability for continuous monitoring across assets and networks to find anomalies and adverse events
*
0
1
2
3
4
Not in place
Fully / optimized
Adverse Event Analysis: how effectively information from multiple sources is analyzed and correlated to declare incidents
*
0
1
2
3
4
Not in place
Fully / optimized
Threat Intelligence Integration: extent threat intelligence and context are integrated into adverse-event analysis
*
0
1
2
3
4
Not in place
Fully / optimized
Respond (RS)
Incident Management and Planning: extent of a formal, tested incident-response plan (roles, responsibilities, procedures)
*
0
1
2
3
4
Not in place
Fully / optimized
Incident Mitigation: ability to contain and eradicate incidents to prevent expansion and recurrence
*
0
1
2
3
4
Not in place
Fully / optimized
Communication: maturity of notifying and communicating with internal and external stakeholders during and after an incident
*
0
1
2
3
4
Not in place
Fully / optimized
Recover (RC)
Incident Recovery Plan Execution: maturity of recovery planning and execution to restore systems and services timely and securely
*
0
1
2
3
4
Not in place
Fully / optimized
Communication: extent communication plans coordinate recovery activities and report progress to stakeholders
*
0
1
2
3
4
Not in place
Fully / optimized
Submit