Page 1 of 1

CSFv2 Assessment

20 quick questions on your security maturity. Rate each on a 0–4 scale: 0 = Not in place · 1 = Ad hoc · 2 = Partial · 3 = Mostly · 4 = Fully / optimized.

About you & your organization

First name

Last name

Company name

Business email

Phone

Website

Company size

Organization type

Primary pain point

Compliance need

Govern (GV)

Risk Management Strategy: maturity of the cybersecurity risk-management strategy and its integration into enterprise risk management (ERM)

Not in placeFully / optimized

Roles and Responsibilities: extent cybersecurity roles, responsibilities, and authorities are established and communicated

Not in placeFully / optimized

Cybersecurity Supply Chain Risk Management (C-SCRM): how effectively supply-chain cyber risks are identified, assessed, and managed

Not in placeFully / optimized

Oversight: process for using cybersecurity results and performance reviews to inform and adjust the risk-management strategy

Not in placeFully / optimized

Identify (ID)

Asset Management: completeness/accuracy of inventories of critical assets (hardware, software, services, data) and their lifecycles

Not in placeFully / optimized

Risk Assessment: extent threats and vulnerabilities to assets and objectives are continuously identified, analyzed, documented

Not in placeFully / optimized

Risk Response and Tracking: how effectively risk responses are chosen, prioritized, planned, and tracked

Not in placeFully / optimized

Improvement: consistency of identifying and prioritizing improvements from lessons learned, tests, and operational feedback

Not in placeFully / optimized

Protect (PR)

Identity Management, Authentication & Access Control: effectiveness at enforcing least privilege for users, services, and hardware

Not in placeFully / optimized

Awareness and Training: extent all personnel receive role-appropriate cybersecurity awareness and training

Not in placeFully / optimized

Data Security: maturity of safeguards (encryption, backups, secure disposal) protecting data at rest and in transit

Not in placeFully / optimized

Platform Security: maturity of configuration management and secure software-development practices protecting platforms

Not in placeFully / optimized

Detect (DE)

Continuous Monitoring: capability for continuous monitoring across assets and networks to find anomalies and adverse events

Not in placeFully / optimized

Adverse Event Analysis: how effectively information from multiple sources is analyzed and correlated to declare incidents

Not in placeFully / optimized

Threat Intelligence Integration: extent threat intelligence and context are integrated into adverse-event analysis

Not in placeFully / optimized

Respond (RS)

Incident Management and Planning: extent of a formal, tested incident-response plan (roles, responsibilities, procedures)

Not in placeFully / optimized

Incident Mitigation: ability to contain and eradicate incidents to prevent expansion and recurrence

Not in placeFully / optimized

Communication: maturity of notifying and communicating with internal and external stakeholders during and after an incident

Not in placeFully / optimized

Recover (RC)

Incident Recovery Plan Execution: maturity of recovery planning and execution to restore systems and services timely and securely

Not in placeFully / optimized

Communication: extent communication plans coordinate recovery activities and report progress to stakeholders

Not in placeFully / optimized