GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

Question Bank

528 questions across 201 controls

Profile11 out-of-scope controls hiddenApplicability statement →
AIG-001AI Policy
boolean

Does your organisation have a documented AI governance policy or charter?

The policy should be formally approved by an executive sponsor, enumerate prohibited AI use cases, assign accountability for AI risk decisions, and specify a review cadence. Absence of a policy is a foundational gap that downstream controls cannot compensate for.

multi

Which of the following topics does your AI governance policy cover?

Prohibited or restricted AI use casesNamed executive sponsor or accountable ownerAccountability structure for AI risk decisionsAlignment with applicable laws and regulationsAnnual or more frequent review obligationCommunication requirements to relevant personnelNone of the above

A mature policy covers all six areas. Policies limited to high-level principles without accountability assignments or prohibited use lists provide weak governance foundations for enterprise buyers.

boolean

Has your organisation documented its AI risk tolerance, the types and levels of AI risk it is willing to accept?

Risk tolerance is the decision rule that determines when AI risks require treatment. Without it, risk management decisions are inconsistent and cannot be audited. Look for explicit statements covering safety, fairness, privacy, reliability, and regulatory compliance.

AIG-002AI Roles and Responsibilities
boolean

Are named roles with defined accountability for AI risk management documented and assigned in your organisation?

Diffuse accountability is the most common AI governance failure mode. Look for a RACI or equivalent document that names an executive AI governance sponsor and assigns a system owner to every production AI system.

multi

Which of the following AI governance roles are formally defined and assigned in your organisation?

Accountable executive for AI governanceNamed owner for each production AI systemData scientist / ML engineer AI risk responsibilitiesOperator responsibilities for AI system oversightCompetency or training requirements for oversight personnelNone of the above

All five should be present for a mature programme. Missing executive accountability or per-system ownership are the most significant gaps: they indicate AI governance cannot be enforced or audited.

AIG-003AI System Inventory
boolean

Does your organisation maintain a current inventory of all AI systems in use or under development?

An AI inventory is the prerequisite for proportionate risk treatment. It should cover production, staging, and development systems and be reviewed at least quarterly.

multi

Which of the following fields does your AI system inventory record for each entry?

System name and versionNamed ownerIntended purposeDeployment status (development / staging / production)Risk classification or tierThird-party model or framework dependenciesNone of the above

All six fields should be present. Risk classification and dependency tracking are the most commonly missing fields; without them the inventory cannot drive proportionate risk controls or supply chain oversight.

multi

For AI systems that a regulator classifies, which of the following does your inventory hold?

The classification determination with its reasoning and dateThe name of the person who made the determinationA re-determination after each substantial modificationThe public database registration reference, including for systems assessed as exemptThe measure any notification threshold is set against, with its current valueThe reference of any threshold-based notification made to a regulatorNone of the above

Options run from the most commonly held to the least. A classification field with no determination behind it is a claim, not a record, and the determination is what an authority asks to see. Systems assessed as exempt are the ones most often missing a registration reference, because the exemption is read as removing the filing rather than pairing with it.

AIG-005AI Risk Management Process
boolean

Does your organisation apply a documented risk management process to AI systems throughout their lifecycle?

The process should cover risk identification, analysis, evaluation, treatment, and residual risk acceptance. It should be triggered before deployment and after any substantial modification, not only at initial development.

multi

At which points in the AI system lifecycle is a formal risk assessment conducted?

Before initial deploymentAnnually for all production AI systemsAfter any substantial modification to the systemWhen the system's deployment context or user population changes materiallyWhen new regulatory obligations come into effectNone of the above

Assessments conducted only at initial deployment miss risk accumulation from model drift, changed use contexts, and regulatory evolution. A mature process triggers reassessment at all five points.

select

How are your AI risk tolerance statements expressed?

Qualitative principles only (e.g. 'we prioritise safety')Qualitative with some measurable targets for selected dimensionsMeasurable thresholds defined for all major risk dimensionsMeasurable thresholds linked to specific AI governance objectives with tracked progress

Enterprise buyers should expect at minimum quantified thresholds for the risk dimensions relevant to your AI use cases. Qualitative-only statements cannot be verified or used to drive consistent risk treatment decisions.

AIG-006AI Impact Assessment
boolean

Does your organisation complete a documented impact assessment before deploying an AI system that may affect individuals or groups?

AI impact assessments must go beyond standard risk assessments to address population-scale harms including discrimination, privacy, economic effects, and societal impacts. The assessment should be retained and revisited when system purpose or data inputs change.

multi

Which of the following harm categories does your AI impact assessment explicitly evaluate?

Discrimination or differential treatment of individualsPrivacy and data subject rights impactsPhysical safety risksEconomic effects on individualsSocietal or systemic harms (e.g. labour displacement, systemic bias)Impacts on vulnerable groups including minorsNone of the above

All six categories should be assessed for systems affecting individuals. Missing vulnerable group analysis or societal harm evaluation are common gaps that create regulatory exposure under the EU AI Act and GDPR.

AIG-007AI System Requirements and Design Documentation
boolean

Is a design document approved for each AI system before development begins?

Undocumented intent makes post-deployment evaluation and audit impossible. Look for version-controlled design documents that predate development commencement and are approved by the system owner.

multi

Which of the following are recorded in your AI system design documentation before development proceeds?

Intended purpose and success criteriaDeployment context and target user populationFairness and bias design decisionsExplainability approach and requirementsSafety modes and failure handlingKnown constraints and limitationsNone of the above

All six elements are expected. The socio-technical decisions, fairness, explainability and safety modes, are the ones most often absent from documentation inherited from a general software development template.

AIG-008AI System Verification, Validation and Testing
boolean

Are defined verification and validation procedures executed before any AI system is deployed or after a substantial modification?

AI V&V must cover dimensions conventional software testing misses: distributional robustness, fairness across population subgroups, and safety failure modes. Testing should not be performed solely by the team that built the system.

multi

Which of the following are included in your AI system V&V testing?

Functional accuracy against pre-specified metrics and thresholdsRobustness to distributional shift or out-of-distribution inputsSafety and failure-mode testingFairness and bias evaluation across protected characteristic subgroupsIndependent review (not solely by the development team)Documented and retained test datasets and resultsNone of the above

All six elements characterise a mature AI V&V process. Fairness evaluation and independent review are the most frequently absent from programmes that inherit generic software testing practices.

AIG-009AI System Deployment and Change Management
boolean

Does a documented deployment plan exist for each production AI system, dated before its deployment?

The plan is the artefact, not the intention. An assessor compares the plan date against the deployment record date for a sample of releases; a plan written after go-live does not meet the control.

multi

Which of the following does the deployment plan record for each production AI system?

The pre-deployment checks completedThe verification and validation sign-offThe impact assessment it relies onThe rollback procedureThe communication to affected usersThe definition of a substantial modification, with worked examplesThe same pre-deployment checks completed for each substantial modificationNone of the above

Options run from the most commonly recorded to the least. Without a worked definition of a substantial modification, teams reach inconsistent judgements about when a change needs the full gate. Retraining on a new data source and a change to an inference threshold are the two cases worth naming.

AIG-010AI Model Registry and Versioning
boolean

Does your organisation maintain a model registry that tracks all ML models in development and production?

A model registry is the prerequisite for tracing production models to their training data and evaluation results, essential for incident response, audit, and debugging. Net-new control: not addressed at this operational level by NIST AI RMF, ISO 42001, or the EU AI Act.

multi

Which of the following are recorded in your model registry for each entry?

Model name and version identifierFramework and library versionsTraining dataset name and versionEvaluation metrics at registration timeCurrent deployment status (development / staging / production / archived)Owning teamNone of the above

All six fields should be present. Missing training dataset references or evaluation metrics at registration time are the most common gaps: they prevent traceability between production behaviour and training decisions.

boolean

Is a completed model registry entry required before a model can be promoted from staging to production?

A mandatory promotion gate ensures the registry accurately reflects what is running in production. Registries that are populated after deployment rather than as a gate provide much weaker auditability.

AIG-011AI System Decommissioning
boolean

Does your organisation have a documented procedure for decommissioning AI systems?

Retired AI systems that remain partially active (orphaned model endpoints, residual data pipelines) create unmonitored risk. Decommissioning should be a controlled, auditable process with system owner sign-off.

multi

Which of the following steps does your AI system decommissioning procedure require?

Notification to affected users and operatorsData deletion or retention consistent with the data retention policyArchival of technical documentation and evaluation recordsVerification that automated pipelines and downstream integrations have been removedSystem owner sign-offNone of the above

All five steps should be present. The most commonly missed is verification of downstream pipeline removal. Orphaned integrations calling decommissioned endpoints are a recurring production incident pattern.

AIG-012Training Data Management and Quality
boolean

Are the data used to train, fine-tune or evaluate AI models subject to documented data management practices?

Training data quality is the single largest determinant of AI system quality. Practices should include documented quality requirements, bias identification steps, and validation before use.

multi

Which of the following training data management practices are applied before model training begins?

Documented acquisition and selection criteriaQuality validation (completeness, representativeness, accuracy)Labelling or annotation procedures with quality controlsBias identification and mitigation reviewHandling documented for underrepresented subgroupsDataset versioned and referenced in the model registryNone of the above

All six practices are expected for a mature data governance programme. Missing bias identification or subgroup handling documentation creates exposure to fairness failures that surface after deployment.

AIG-013Training Data Provenance
boolean

Is the provenance of every dataset used to train, fine-tune or evaluate a production model recorded?

Answer for the datasets behind the models currently in production. A record that covers the most recent dataset but not the ones earlier versions were trained on does not meet the control, because the obligation attaches to the model for as long as it is in use.

multi

What does your training data provenance record include for each data source?

Origin of the source, whether internal, third-party, licensed, web-sourced or syntheticLicence and copyright statusCollection or acquisition dateTransformations applied to the dataLawful basis relied on for any personal data the source holdsA link to the model registry entry for the models trained on itNone of the above

All six elements are expected for any source used by a production model. The link to the model registry is the element most often absent and the one that decides whether a disputed source can be traced to the models that consumed it.

AIG-014Special Category Data in Training and Evaluation Datasets
boolean

Does every training and evaluation dataset carry a recorded special-category screening result?

The screening result records what the dataset was screened for, the outcome and the date, whether or not special category data was found. A dataset that has never been screened does not meet the control even if it holds no such data.

multi

Where a training or evaluation dataset holds special category personal data, which of the following are recorded for it?

The lawful basis relied on for that categoryA necessity assessment showing no less intrusive alternative was availableThe security measures applied to the datasetA named sign-offA retention and deletion scheduleA separate record for any dataset held solely for bias detection and correction, with its own deletion dateAccess restricted to the roles the record namesNone of the above

Answer for the datasets that screened positive. If no dataset holds special category data, the screening results in Q1 are the evidence and this question does not apply. Absence should be recorded positively rather than assumed.

AIG-015AI System Technical Documentation
boolean

Does technical documentation exist for each AI system before it is deployed?

Technical documentation is the primary evidence artefact for AI governance audits and regulatory inspections. It must be version-controlled and the current version should correspond to the deployed model version.

multi

Which of the following sections are included in your AI system technical documentation?

System architecture and componentsIntended purpose and the use cases in scopePerformance measures and the limits of that performanceTraining data summaryKnown failure modes and edge casesHuman oversight mechanismsHardware and compute requirementsMaintenance and update scheduleNone of the above

All eight sections are expected. Known failure modes and human oversight mechanisms are the two sections most often missing from documentation inherited from a general software template. They are also the two an enterprise buyer reads first.

boolean

Does the current version of each system's technical documentation correspond to the version of the system in production?

Compare the documentation version against the model or release version recorded in the registry for a sample of systems. Documentation that describes a version no longer deployed fails this question even where every required section is present.

AIG-016AI Interaction and Output Disclosure
boolean

Are users of your AI systems informed that they are interacting with an AI before or at the point of first interaction?

Undisclosed AI interaction is deceptive and a regulatory obligation in most jurisdictions. Disclosure must be presented before interaction begins and should not be easily dismissed or hidden.

multi

For AI systems that generate synthetic content or converse with users, which of the following disclosure mechanisms are in place?

Machine-readable marking of AI-generated outputs (e.g. C2PA metadata, watermark)Visible label or badge indicating AI-generated contentDisclosure to affected parties when synthetic media depicts real individualsRobustness testing confirming the marking cannot be trivially removedA recorded review of a persona-bearing interface for cues that present the system as human, before release and after a persona changeNone of the above

All four mechanisms apply to generative AI systems producing synthetic media. Organisations using AI only for classification or decision-support (not synthetic media generation) should note which apply and which do not. The persona review item applies to any system with a name, an avatar or a conversational voice: it asks whether someone looked at the interface for human images, statements of feeling and humanoid imagery and recorded a decision on each.

multi

For AI systems that make or inform decisions about people, which of the following are in place?

Affected people are told that an AI system was used in the decisionA published route for an affected person to ask for an explanationA defined period within which an explanation is givenExplanations state the part the system played in the decisionExplanations set out the main elements of the decision itselfNone of the above

Options run from the most commonly in place to the least. The population here is wider than the users of the product: a person refused a service never sees the interface, so a disclosure built into the product reaches none of them. An explanation that points the reader at published model documentation does not set out the main elements of their decision.

AIG-017AI Model Explainability
boolean

Is the explainability capability of each AI system that produces decisions or recommendations affecting users documented?

Unexplainable AI outputs prevent operators from identifying errors or challenging decisions. Documentation should specify what explanations are available (feature attribution, confidence scores, decision paths) and, where explanation is not technically feasible, state this limitation explicitly.

multi

Which of the following does your explainability documentation record?

Feature attribution or importance scoresConfidence or probability scoresDecision paths or rule tracesCounterfactual explanationsThe known limits on how far the explanations generaliseGuidance for operators on how to interpret the outputsWhere explanation is not technically feasible, that limitation, how it is disclosed and how human oversight accounts for itNone of the above

Options run from the most commonly recorded to the least. At least one explanation type applies to any system in scope. Where explanation is not technically feasible the last item is the honest answer. It is a weak position unless the oversight design in AIG-022 carries the weight instead.

AIG-018AI System Operational Monitoring
boolean

Does each production AI system have a documented monitoring plan?

AI system behaviour degrades in ways not visible from infrastructure metrics alone. Monitoring must include AI-specific measures: confidence score distributions, null or refusal rates, output category distributions, in addition to standard latency and error rate metrics.

multi

Which AI-specific metrics are included in your production monitoring for AI systems?

Output confidence score distributionNull rate or refusal rateOutput category or label distributionHuman override or escalation rateInput data distribution shiftsModel error rate (distinct from application error rate)Departure of an agent from its authorised objective, where the system runs agents that select their own actionsNone of the above

Programmes that monitor only latency and error rates are using generic application performance tooling, which misses the behavioural degradation patterns specific to AI systems. The last item applies only where agents select their own actions; where they do, it is the metric that shows an agent pursuing something other than the task it was given.

multi

Which of the following does the monitoring plan record for each production AI system?

An alert threshold for each metric trackedThe interval at which monitoring output is reviewedThe person accountable for reviewing alertsA named route for deployers and users to report performance dataAnalysis of that field data at a defined cadenceAn evaluation of whether the system still meets the requirements it was released againstAnalysis of the system's interaction with other AI systems it runs alongsideThe plan is held and versioned with the system's technical documentationNone of the above

Options run from the most commonly in place to the least. Operational monitoring answers whether the system is healthy now; the field data limb answers whether what was claimed about it at release still holds. The conformity evaluation is the element most often missing, because collecting field data is easier than drawing a conclusion from it.

AIG-019AI Model Performance and Drift Detection
boolean

Are deployed AI models evaluated on a scheduled basis for performance degradation and distribution shift (data drift, concept drift)?

Model drift is an AI-specific failure mode with no equivalent in conventional software. Without scheduled evaluation, degraded models operate undetected. Evaluation should use held-out test data or shadow deployments and trigger a documented escalation path when thresholds are breached.

select

How frequently are your production AI models evaluated for drift or performance degradation?

Continuously or weekly through automated toolingMonthlyQuarterlyAnnuallyAd hoc, only when an issue is reported

Options run from strongest to weakest. Frequency should match the velocity of the underlying domain: a fast-moving domain such as fraud or content moderation needs monthly evaluation or better. Annual evaluation is insufficient wherever the data environment changes.

AIG-020AI System Event Logging
boolean

Do your AI systems record an event log for each inference or decision?

AI event logs are the primary forensic artefact when AI-driven decisions are challenged or incidents require root-cause analysis. Logs must be protected from tampering and retained for the period required by applicable regulations.

select

What is the log retention period applied to your AI system event logs?

Less than 6 months6 months12 months24 months or more

Answer with the retention actually configured on the AI event log store. The control requires retention to meet the period applicable regulation sets and to align with the audit log retention in MON-003; where a deployment is subject to the EU AI Act the deployer floor is six months. Longer retention carries its own data protection cost and should be set deliberately rather than by default.

multi

Which fields are captured in your AI system event logs?

Request identifier and timestampModel version in useInput data type or identifier rather than the raw inputOutput or output categoryConfidence score where one existsHuman override or interventionSystem error or exceptionFor generative systems, the session or user identifier, pseudonymised where data protection law requires itFor generative systems, the system prompt or prompt template identifierFor generative systems, the tool calls the model madeFor a safety-critical use case or a decision about a person, the full prompt and response under access controlNone of the above

The first seven fields apply to every AI system. The generative fields apply where the system produces free text or media. Full prompt and response content is required only for the last case and has to be protected by access controls restricting it to security and operations roles.

AIG-021AI Incident Response and Error Communication
boolean

Does a documented process exist for detecting, investigating and responding to AI system incidents?

A generic IT incident process does not meet the control. The AI process has to define AI-specific incident categories and the notification obligations that attach to a serious incident; Q2 captures which parts are present.

multi

Which of the following are covered in your AI incident response process?

AI-specific incident categories such as systematic bias, unsafe output at scale, suspected poisoning and loss of control of an AI-driven actionA definition of what counts as a serious incidentSeverity classification with defined criteriaAn escalation path that reaches legal and complianceCommunication obligations to affected usersReporting deadlines for a serious incident and the point from which they runA bar on altering the system in a way that would prevent evaluation before the report is madeA post-incident review requirement with a defined timeframeNone of the above

The serious incident definition, the reporting deadlines and the bar on altering the system are the three a process inherited from IT incident management will be missing. The deadline runs from the moment the organisation or an operator becomes aware of the incident, not from the moment the investigation concludes. AIG-043 asks about corrective action on a system found not to conform and about what an authority can ask for afterwards.

AIG-022Human Oversight of AI Outputs
boolean

Do AI systems that produce outputs used in decisions affecting individuals have documented human oversight mechanisms proportionate to their risk level?

Human oversight is the last line of defence against harmful AI outputs. It must be substantively designed, not nominal. Oversight persons must have defined competencies, training, and sufficient time to conduct meaningful review.

multi

Which of the following are true of the human oversight of your AI systems used in decisions affecting individuals?

The oversight design is documented and specific to each systemThe design states whether review takes place before the output is acted on or afterThe oversight role has defined competency requirementsTraining for the oversight role covers automation biasThe design states the time allowed for each reviewOverride and escalation paths are documented and accessible to the reviewerOverride rates are monitored against an expected rangeNone of the above

Every item applies to each system in scope. An override rate at or near zero sustained over a long period is a signal that review is nominal rather than substantive, which is why monitoring the rate against an expected range matters more than the rate itself.

AIG-023AI System Override and Safe-State Mechanisms
boolean

Is there a documented override and safe-state procedure for each production AI system?

AI systems that cannot be safely stopped or overridden are ungovernable. Override, suspension, and deactivation procedures must be documented, accessible to operators, and tested at least annually, not left to vendor support.

multi

Which of the following override and safe-state capabilities have been tested within the defined interval for your production AI systems?

Rejection or override of an individual output by an authorised operatorSuspension of AI-assisted processing with fallback to a manual procedureDeactivation of the system into a defined safe stateDeactivation completed by the organisation's own operators without supplier involvementNone of the above

The test record is the evidence, not the documented procedure. The fourth item is the one that decides whether the mechanism works during an incident: a deactivation that requires a supplier support ticket is not available at the moment it is needed.

AIG-024Prohibited AI Practices
boolean

Does your organisation maintain a documented list of AI use cases that are prohibited?

A prohibited use list translates regulatory red lines (EU AI Act Art. 5) and organisational ethics commitments into concrete guardrails that engineering and product teams can evaluate against during design and launch review.

multi

Which of the following categories are named in your prohibited AI use list?

Manipulation through subliminal or deliberately deceptive techniquesExploitation of vulnerabilities arising from age, disability or social or economic situationSocial scoring of personsPrediction of criminal offending from profiling aloneUntargeted scraping of facial images to build recognition databasesInference of emotion in workplaces and educational settingsBiometric categorisation of persons by protected characteristicReal-time remote biometric identification in publicly accessible spacesGeneration or manipulation of intimate or sexually explicit material depicting an identifiable person without their consentGeneration or manipulation of child sexual abuse materialNone of the above

The ten categories are the minimum the control asks for. The last two were added to the EU AI Act Article 5 prohibitions by Regulation (EU) 2026/1744 and apply from 2 December 2026, so a list written before that date will usually be missing them. Organisational prohibitions beyond the ten are expected and are not scored here.

AIG-025AI Fairness and Bias Controls
boolean

Do AI systems that score, rank, recommend or classify individuals have documented fairness objectives?

Bias cannot be detected without predefined, measurable fairness criteria. Objectives should specify the fairness metric (e.g. demographic parity, equalised odds) and the pass/fail threshold, relative to the system's purpose and affected population.

multi

How is bias testing conducted for AI systems subject to bias risk in your organisation?

Before initial deployment, disaggregated by relevant protected characteristicsPeriodically in production on a defined scheduleUsing pre-specified fairness metrics and pass/fail thresholdsResults are retained and traceable to the deployed model versionThreshold failures require a documented remediation action before continued deploymentNone of the above

All five practices are expected. Bias testing conducted only at deployment without production monitoring misses in-production bias accumulation from feedback loops and data drift.

AIG-026AI Security and Adversarial Robustness
boolean

Are AI systems evaluated for AI-specific security vulnerabilities?

AI-specific attacks are not detected by conventional SAST/DAST tooling. Evaluation must be explicitly scoped to AI attack classes and conducted separately from standard application security testing.

multi

Which AI-specific attack classes are evaluated in your AI security testing programme?

Data poisoning attacks on training pipelinesModel poisoning attacksAdversarial examples crafted to cause misclassificationModel inversion attacks reconstructing training data from outputsModel extraction attacks replicating the model through queriesMembership inference attacksNone of the above

Coverage of all six attack classes characterises a mature AI security evaluation. The results belong in a report of their own: an application penetration test that mentions the AI endpoint does not evidence this control, because it tests the interface rather than the model.

multi

Which of the following training data extraction controls are applied to your LLM-based systems?

Membership inference testing performed before deployment with documented resultsDirect extraction probing for known sensitive training data (PII, credentials, copyrighted content)System prompt configuration reviewed for extraction facilitation risksDocumented risk threshold above which mitigations are requiredOutput length constraints to limit verbatim reproductionPII redaction applied to LLM outputsDifferential privacy applied during model trainingNone of the above

Membership inference testing and extraction probing are the minimum baseline. Mitigations (output length constraints, PII redaction, differential privacy) are required for any LLM that scores above the documented risk threshold in its evaluation. The risk evaluation methodology and results must be retained.

AIG-027AI Output Validation and Confidence Controls
boolean

Do AI systems whose outputs are acted upon have a defined acceptable output range or confidence threshold?

Net-new control: confidence-gating is a structural quality control unique to probabilistic AI systems, not addressed by existing frameworks at an operational level. Outputs acted upon without confidence validation create uncontrolled downstream risk.

select

What action is taken when an AI output falls below the defined confidence threshold?

Output is escalated with a mandatory review before action is takenOutput is routed to a human review queueThe system abstains and requests additional inputA warning flag is added to the output but no action is requiredOutput is passed through unchangedNo threshold or fallback is defined

Options run from strongest to weakest. Mandatory escalation, human review and abstention all meet the control. Passing a low-confidence output through unchanged does not, because nothing downstream can tell it apart from a confident one.

AIG-028Hallucination and Factual Accuracy Controls
boolean

Is a measured hallucination rate recorded for each generative use case whose outputs users may rely on as factual?

The measurement is the control. A use case with grounding mechanisms in place but no measured rate against a documented threshold does not meet the first clause.

multi

Which of the following are in place for your generative use cases that produce statements users may rely on as factual?

An acceptable hallucination rate is documented for each use caseA measured rate from an evaluation against a named dataset is recorded before deploymentThe measurement is repeated in production at defined intervalsAt least one grounding or verification mechanism is active in the serving pathUse cases documented as safety-critical carry a human verification step before the output is acted onA measured rate above the threshold carries a recorded remediation decision and a re-measurement resultNone of the above

Every item applies to each use case in scope. The grounding mechanism may be retrieval with source citation, a post-processing verification step, an uncertainty score carried with the output or another mechanism that does the same job; the control does not require a named technique. A disclaimer on its own is a disclosure, not a grounding mechanism.

AIG-029Prompt Injection Protection
boolean

Is prompt injection named in the threat model of each system that places user-supplied or externally sourced content into a model prompt?

Answer for the systems in scope, not for the organisation. A threat model that names injection only as a generic input validation risk does not meet the control; the entry should identify the untrusted content sources the system consumes.

multi

Which of the following are in place for your systems that place user-supplied or externally sourced content into a model prompt?

Prompt injection is named in the threat model for each system in scopeSecurity testing exercises direct injection through user inputSecurity testing exercises indirect injection through retrieved documents, tool results or other externally sourced contentTool-calling systems enforce privilege separation between the model and the tools it may invokeTool execution runs in a sandboxInjection attempts detected at runtime are logged with the pattern that matchedDetection patterns are updated from the test resultsNone of the above

Every item applies to each system in scope. Indirect injection is the path most often untested: content arriving from a retrieved document, a web page or a tool response carries instructions without any hostile user being present. For a system that calls tools, the last four items are the containment that decides how far a successful injection reaches.

AIG-031AI Misuse, Jailbreak and Abuse Detection
boolean

Do your AI systems exposed to external users have a mechanism to detect misuse attempts?

Net-new control: public-facing LLM systems face continuous adversarial probing. Misuse detection is an AI-specific operational security control with no equivalent in classical application security and is not addressed operationally by any existing framework.

multi

Which misuse and abuse detection capabilities are active for your public-facing AI systems?

Jailbreak pattern detection (attempts to bypass safety instructions)Policy violation detection (requests for prohibited content categories)Abnormal usage pattern detection by volume, sequence or content, including automated abuseAI-specific rate limits configured independently of generic API rate limitsResource ceilings per request, per inference job and per agent run that halt the work when reachedA budget ceiling per credential, per user and per account that halts inference rather than raising an alertDocumented violation response actions (rate limiting, session termination, account action)Periodic misuse pattern review to update detection logicNone of the above

Options run from the most commonly in place to the least. AI-specific rate limits separate from generic API rate limits are often absent: shared limits allow targeted abuse to consume a disproportionate share of capacity before a generic control notices. A ceiling is a different instrument from a rate limit and is the item most often missing: it bounds what one request, job or run may consume and it stops the work, where an alert on a budget is outrun by a fast workload.

multi

For each generative model or modality you place on the market, which of the following are recorded?

The prohibited generation outcomes that are reasonably foreseeable without significant technical modificationThe technical safeguard that prevents each of those outcomesTest evidence that each safeguard holdsThe correction made to a safeguard after misuse was observed or reportedNone of the above

Options run from the most commonly recorded to the least. A detection-only posture answers whether misuse is being caught, not whether the outcome was reachable without real effort and whether anything stopped it first. Where the law turns on foreseeability and on the adequacy of safeguards, an undocumented judgement is not a defence.

AIG-032Third-Party AI Risk Management
boolean

Does your organisation perform a documented risk assessment before integrating a third-party AI system, model, or AI-enabled service?

Third-party AI systems introduce risks distinct from conventional software vendor risk: model changes without notice, training data leakage, provider-level safety failures. Assessment should cover data practices, change notification policies, and exit options.

multi

Which of the following dimensions does your third-party AI risk assessment cover?

Intended use scope constraints imposed by the providerKnown limitations and failure modesData processing and retention practices (including whether inputs are used for training)Confirmation that customer prompts and data are not used to train the provider's foundation modelsModel change and deprecation notification policyExit options and contingency planningTraining data practices and safety alignment methods (for foundation model providers)Provider incident historyAlignment of the provider with the organisation's AI policyProvider obligations to supply technical documentation and to notify incidents and model changes within defined timeframesNone of the above

All seven dimensions are expected for foundation model providers such as LLM APIs. Whether inputs are used for model training is often the most commercially sensitive dimension and should be confirmed in contract terms, not assumed from general documentation.

boolean

Do your written agreements with third-party AI providers allocate responsibility for compliance with applicable AI regulation?

The same model can shift from non-high-risk to high-risk depending on how it is deployed, so the agreement states who carries which regulatory duty and what documentation, incident and model-change information the provider supplies, with timeframes.

AIG-034Customer and Deployer Obligations Communication
boolean

Where your organisation provides an AI system that a customer deploys, do customers receive written instructions for use?

A provider bears upstream responsibility for enabling customers to govern the AI systems they deploy. Incomplete instructions create downstream governance failures and regulatory exposure for both parties under the EU AI Act.

multi

Which of the following are included in the instructions for use you provide to customer deployers?

Known limitations and performance characteristicsGuidance on implementing appropriate human oversightInformation required for deployers to conduct a data protection impact assessmentNotification of model updates or material changesA deployer obligations checklistThe provider's name or trade mark and a contact address, on the system or in its documentationVersioned documentation kept current and accessible to customersNone of the above

Options run from the most commonly provided to the least. Impact assessment information packs and deployer obligation checklists are the usual gaps: they shift the compliance burden onto customers who lack the technical context to carry it. For the identification marking, answer against what a customer can see in the product or its documentation, not against what appears on your website footer.

multi

Which of the following are addressed in your agreements with integrators that build on your AI systems?

Each party's responsibilities for compliance with applicable AI regulationsTechnical documentation exchange obligationsIncident notification obligations with defined timeframesModel change notification obligations with defined timeframesObligations that apply when the integrator's use triggers a high-risk classificationIntegrators bound to deployer obligations equivalent to EU AI Act Art. 25None of the above

All six provisions are expected for agreements covering high-risk AI systems. The obligation covering high-risk reclassification by downstream use is the provision most often absent from AI supply chain contracts.

AIG-036AI Quality Management System
boolean

Is there a documented quality management system covering how your AI systems are developed, tested and released?

Answer yes only where a single approved document set exists that names procedures and owners. An AI policy on its own, or a set of procedures with nothing binding them together, is a no here and is covered by AIG-001 and by the lifecycle controls instead.

multi

Which of the following does your AI quality management system cover?

Regulatory compliance strategy, including the conformity assessment route and how modifications are handledDesign control and verification techniquesDevelopment, quality control and quality assurance proceduresExamination, testing and validation procedures with the frequency each runs atThe technical specifications and standards appliedData management proceduresThe AI risk management processPost-market monitoring and serious incident reportingCommunication procedures with authorities and with operatorsRecord keeping, resource allocation and accountabilityNone of the above

Options are listed in the order the elements appear in a typical manual, not in order of importance. Tick an element only where the system names the procedure that implements it; a heading with no procedure behind it does not count.

select

How often is the quality management system reviewed with the review recorded?

At least quarterlyAt least twice a yearAt least annuallyAt a defined interval longer than a yearThere is no scheduled review

Options run from the most frequent to the least. Answer on the recorded reviews rather than the interval the manual states: a documented annual cycle with no minutes from the last cycle is the last option.

AIG-037AI Regulatory Conformity Assessment and Declaration
boolean

Has a conformity assessment been completed for every AI system you have determined falls into an assessed category?

The determination itself is recorded against each system in the AI system inventory (AIG-003). Where you have determined that no system falls into an assessed category, answer yes and keep the determination available; the assessor tests the determination, not the absence of assessments.

multi

Which of the following does your conformity assessment record contain?

The assessment route taken and why it appliesThe standards or specifications appliedThe evidence examined against each requirementThe identity of the person who signed it offWhether a third-party body was involved and its identificationA signed declaration of conformity identifying the systemThe retention arrangement for the declarationThe recorded placement of the conformity markingNone of the above

Options follow the order in which the items are produced. Tick the evidence item only where each requirement has a named artefact against it; a summary statement that the requirements are met does not count.

select

Who completes and signs off the conformity assessment?

An accredited third-party body assesses conformityAn internal function independent of the development team completes the assessment and a separate authority signs itThe development team completes the assessment and an approver outside the team signs itThe development team completes and signs the assessmentNo conformity assessment is completed

Options run from the most independent to the least. Answer for the route actually used in the last twelve months, not the route the procedure allows for.

AIG-038AI Feedback and Adverse Impact Reporting Channel
boolean

Is there a published channel through which someone outside your organisation can report an adverse impact of an AI system?

A general support queue counts only where it is published as a route for adverse-impact reports and reaches people who are not customers. An internal reporting route for staff is HRS-009 and does not answer this question.

multi

Which of the following apply to reports received through the channel?

Each report is logged with a receipt dateEach report is triaged against documented severity criteriaThe reporter receives a documented acknowledgementEach report is adjudicated to a recorded outcomeA no-action outcome carries a stated reasonReports contesting an output are routed to the human oversight processA periodic review reads the reports as a set and records what changedNone of the above

Options follow the path a report takes from receipt to review. Tick the adjudication item only where the outcome is recorded against the report; closing a ticket without an outcome does not count.

select

Who adjudicates reports received through the channel?

A panel that includes people outside the team that builds or operates the systemA named function outside the team that builds or operates the systemThe team that builds or operates the system, with outcomes reviewed by someone elseThe team that builds or operates the system aloneReports are not formally adjudicated

Options run from the most independent to the least. Answer for the reports actually received in the last twelve months; where none were received, answer for the route the procedure assigns.

AIG-039Responsible and Intended Use of AI Systems
boolean

Is there a register recording what each AI system you operate is used for?

The AI system inventory (AIG-003) records that a system exists and who owns it. This question is about the use: the purpose it is put to and the uses its instructions permit and exclude. One register can serve both provided both sets of fields are present.

multi

Which of the following are recorded for the AI systems you operate?

The purpose each system is used forThe uses the accompanying instructions permit and excludeThe objectives the use is meant to meetAn accountable owner for staying inside the intended purposeExceptions for use outside the intended purpose, with a justification and an expiry dateAcceptable-use rules for AI systems, acknowledged by personnelChecks that input data you supply is relevant and representativeNone of the above

Options follow the order the items appear in a use register. Answer for what is recorded today, not for what the process says should be recorded.

select

How is use outside a system stated intended purpose handled?

It is prevented, with any need for it going through an exception carrying a justification, an owner and an expiry dateIt is recorded as an exception with a justification, an owner and an expiry dateIt is recorded, without an expiry dateIt is noticed informally and discussedIt is not tracked

Options run from the strongest handling to the weakest. Answer for what happened the last time a use fell outside the instructions, not for what the process states.

AIG-040Customer Data Use in Model Training
boolean

Does your customer agreement state whether customer content may be used to train or fine-tune your models?

An agreement that is silent on the question is a no. Answer yes where the agreement addresses it either way, including where it states that customer content is never used for training.

multi

Which of the following apply to your use of customer data in model training?

The agreement and the product documentation say the same thing about itA basis is recorded per customer, with the date it was obtainedThe customer can operate a control that stops its data entering trainingThat control takes effect inside a period stated in the agreementDatasets are filtered by recorded permission in the pipeline itselfDataset lineage records which customer sources each version drew onNone of the above

Options follow the path from the agreement through to the dataset. Tick the pipeline item only where the filter is enforced by the build; a documented instruction to engineers does not count. Where you never use customer content for training, tick the first item and the lineage item if they hold; the assessor then tests the exclusion instead of the permission.

select

How is the exclusion of a customer data from training enforced?

The build filters on recorded permission and fails when a source has no permission stateThe build filters on recorded permission and skips sources without oneA scheduled job removes excluded sources before each buildAn engineer applies the exclusion list manually before each buildThere is no enforcement step

Options run from the strongest enforcement to the weakest. Answer for the pipeline that produced your most recent training dataset.

AIG-041Regulatory Authorised Representative
boolean

Have you recorded, for each market you place an AI system or model on, whether a local representative is required?

This asks for the determination, not the appointment. A recorded conclusion that no representative is required, with the reason, is a yes. An assumption that the obligation does not apply, with nothing written down, is a no.

multi

Where a representative is appointed, which of the following does the written mandate contain?

The tasks the representative is empowered to performThe documents it holds on your behalfThe period it holds those documents forThe grounds on which it terminates the mandateA date of appointment before the product was made available in that marketContact details recorded against the system in your AI system inventoryNone of the above

Answer for the mandates in force today. Where you have determined that no representative is required in any market, select None of the above; the determination is tested under question one.

select

When is the representative determination revisited?

On a defined interval and on any change of representative or of the markets the product is placed onOn any change of representative or of the markets the product is placed onOn a defined interval onlyWhen someone raises itIt has not been revisited since it was first made

Options run from the most complete trigger set to the least. A determination made once at launch and never revisited is the last option even where it remains correct.

AIG-042Agentic Tool Permissions and Action Authorisation
boolean

Does each AI agent that can invoke tools hold a permission set enforced by the system rather than described in its prompt?

A prompt instruction telling an agent which tools to use is not an enforced permission set. Answer yes only where the orchestrator or the tool layer refuses a call outside the set. Where you run no agents that invoke tools, this control does not apply to you.

multi

Which of the following are in place for agent tool permissions?

A grant record naming the requester, the approver, the task and an expiryA recorded classification of which actions are consequentialRecorded human approval before a consequential action executesAn invocation record carrying the authorisation that permitted the callPermissions that can be revoked while the agent is runningScopes that limit what a permitted tool call may reach, not only which tool may be calledA run for a named user bounded by the authorisations that user holdsTools that execute under the calling agent's identity and restrictions rather than a standing credentialConstraints inherited by a sub-agent, which may narrow the scope and never widen itNone of the above

Options follow the path from grant to invocation and then to delegation. The scope item asks whether a permission to call a tool is bounded, for example to one account, one repository or one spend limit, rather than being a permission to call it for anything. The last three items are about borrowed authority: an agent acting for a user, a shared tool and a sub-agent are the three places an authority quietly widens.

select

What happens when an agent attempts an action classified as consequential?

It is held until a named person approves the action and its parameters, with the approval recordedIt is held until a named person approves it, without the parameters being recordedIt executes and a person is notified in time to reverse itIt executes and appears in a log reviewed laterConsequential actions are not distinguished from any other action

Options run from the strongest gate to the weakest. Answer for the behaviour of the system in production, not for the behaviour a configuration flag could produce.

AIG-043AI Non-Conformity Corrective Action and Authority Cooperation
boolean

Is there a defined route for handling an AI system found not to conform with the requirements applicable to it?

Answer yes where the route is written down and has an owner, whether or not it has been used. A general product defect or bug process counts only where it names the corrective actions available and the parties outside the organisation who have to be told; Q2 captures which parts are present.

multi

Which of the following does your non-conformity and authority cooperation handling cover?

Bringing the system back into conformity as a recorded actionWithdrawing the system as a recorded actionDisabling the system by a tested route such as a feature flag or a model rollbackRecalling the system as a recorded actionInvestigation of the causes, with the deployer that reported the finding where there was oneA current list of the distributors, deployers, importers, authorised representatives and certifying bodies to informNotification of the competent market surveillance authority where the system presents a riskA register of reasoned requests from competent authoritiesProduction of the information and documentation demonstrating conformity in the official language an authority namesA route that gives an authority access to the system's automatically generated logsNone of the above

Options are grouped, the four corrective actions first, then the notification duties, then the authority request route. Tick an option only where the route exists for a named system rather than as a general intention. The two authority request options are the ones an organisation that has never had a request tends to leave untested. They are also the ones with a deadline attached when a request arrives.

AIG-055Training Pipeline Security
boolean

Is the pipeline that trains, fine-tunes and evaluates production models secured as a system in its own right?

Answer for the training run and its storage, not for the application build pipeline, which is APP-012. An organisation that trains no model and only calls a provider's model answers no and records that the control does not apply.

multi

Which of the following are in place on the training pipeline?

Secrets and credentials held in a managed store, not in code or configurationVersion-controlled configuration with approved, traceable changesJob submission, alteration and cancellation limited to named rolesAccess to inputs and checkpoints limited to named rolesActivity logged with detection for unauthorised jobs, altered inputs and unexpected artefact movementMeasures assessed at defined intervals and after a change or a new threatNone of the above

Options follow the pipeline from configuration to assessment. Detection over the logs is the item most often missing; logging alone is the fifth option only when a rule fires on it.

select

When are the pipeline security measures assessed?

At a defined interval and after each pipeline change or newly identified threatAt a defined interval onlyAfter an incidentNot assessed

Options run from the fullest cadence to none. A threat named in an assessment record is what shows the assessment considered anything.

AIG-056Agent Memory and Context Integrity
boolean

Are reads and writes to the durable memory your AI agents keep between tasks authorised within the user, tenant, agent and session scope of the request?

Durable memory is any state an agent reads or writes across tasks or sessions: saved preferences, conversation summaries, stored history, episodic or semantic memories and agent-managed experience stores. A store that any agent or session can read or write in full is not scoped. Where no agent keeps state between tasks, this control does not apply to you.

multi

Which of the following are in place for agent memory?

A memory policy stating size, update-frequency, retention and deletion limits per entry classEntries segregated by user session and by domain contextWrites accepted only from named source classes and validated before they commitThe agent's own output validated like external content before it enters trusted memorySource, time and writer recorded on every entryA version history that allows the store to be returned to a known good stateExpiry of entries whose source cannot be verifiedQuarantine or rollback of an entry suspected of poisoning, with the action recordedRetrieval weighted by trust tier, with verified provenance before a consequential actionMonitoring that alerts on unusual update frequency or repeated self-authored updatesNone of the above

Options follow the lifecycle from policy to write, from write to retrieval and from retrieval to recovery. The self-authored output item asks whether an agent can promote its own conclusions into memory it will later trust without a check; that is the loop a poisoned entry reinforces itself through.

select

What happens when an entry in agent memory is suspected of being poisoned?

It is quarantined or the store is rolled back to a known good version, with the action recordedIt is deleted by hand and there is no version history to return toIt is flagged but stays readable to the agentNothing is done until the store is rebuilt from scratchThere is no way to tell that an entry is suspect

Options run from the strongest response to the weakest. Answer for the procedure that has actually been used or tested, not for a capability the store could offer.

AIG-057Inbound Synthetic Media Detection
boolean

Does each point where your systems rely on user-supplied or external audio, image or video as evidence of identity, provenance or a real-world event run a detection step for synthetic or manipulated media before the content is relied on?

Identity verification, onboarding checks, evidence uploads and moderation queues are the usual intake points. A step that runs after the decision has been made, or that only logs a score, is not a detection step in this sense. Where a documented assessment concludes that no system relies on inbound media in this way, answer on that assessment.

multi

Which of the following are in place for inbound media at those points?

A documented assessment naming each intake point and the decision it feedsA named detection method for each intake pointMeasured detection and false positive rates against a named evaluation setA recorded threshold at which content is blocked or referredVerification of a provenance credential where the content carries oneFailing content blocked or routed to a human check rather than acceptedThe outcome recorded against each intake eventThe evaluation repeated at defined intervals and after a change to the methodThe method updated from confirmed casesNone of the above

Options run from the assessment to the step, from the step to the outcome and from the outcome back to the method. The rates item asks for numbers measured on a set the organisation can name, not a vendor's published figure.

select

What happens to inbound media that fails the synthetic media detection step?

It is blocked or routed to a human check and the outcome is recorded against the eventIt is routed to a human check without the outcome being recordedIt is accepted with a flag that a person may look at laterIt is accepted and the detection result is only loggedThere is no detection step

Options run from the strongest disposition to the weakest. Answer for the behaviour of the system in production at the intake point with the highest-impact decision.

APP-001Secure Development Lifecycle Policy
boolean

Does your organisation have a documented secure software development lifecycle (SDLC) policy that defines required security activities at each development phase?

The policy must cover all phases: requirements, design, development, testing, deployment, and maintenance. It should have a named owner, effective date, and defined review cadence.

select

How frequently is the secure SDLC policy reviewed and updated?

Every 6 months or more frequentlyAnnuallyEvery 2 yearsNo defined review cadence / ad hoc

Annual review is the minimum. The policy should be updated whenever there is a significant change in development technology, tooling, or regulatory requirements.

multi

Which of the following does your secure development lifecycle documentation record?

The security activities required at each lifecycle phaseThe development standards the team is held toThe security tools used at each phaseThe configured options set for each of those toolsA recorded approval for a change to a standard, a tool or a tool configurationNone of the above

Options run from the most commonly documented to the least. Tool configurations are the element most often left out, and they are where a requirement quietly stops being met: a scanner running with its rule classes disabled still satisfies an unqualified requirement to run a scanner. Name capabilities rather than products in the register itself.

APP-002Security Requirements in Design
boolean

Are information security and privacy requirements formally identified, documented, and approved before development begins on new applications or significant features?

Requirements must be documented before the first development sprint, not derived after implementation. Traceability from requirement to implementation and testing is expected.

multi

How are security requirements derived for new development work?

Threat modelling (e.g. STRIDE, attack tree analysis)Risk assessment outputRegulatory or compliance obligation mappingSecurity-focused user stories or abuse casesReference to a security requirements baseline (e.g. ASVS, internal standard)Ad hoc, based on individual developer judgementNone of the above

Requirements derived from threat modelling and risk assessments are most robust. Ad hoc approaches without a defined method introduce inconsistency and gaps.

select

For which development work is a documented threat model produced?

Every new system and every significant change, including components a supplier buildsEvery new system and every significant change to systems built in houseNew systems onlySelected high-risk projects onlyThreat models are not produced

Options run strongest to weakest. Coverage of supplier-built components is the limb most often missing: the threats are the same and the analysis arrives only if the agreement asks for it. A threat model produced after the design is settled tests documentation rather than design.

APP-003Secure Coding Standards
boolean

Has your organisation adopted documented secure coding standards?

Standards must be accessible to and used by all developers, not just security specialists. They should reference an industry taxonomy (e.g. OWASP Top 10, CWE Top 25) and be reviewed at least annually.

multi

Which of the following apply to your secure coding standards?

They reference a named vulnerability taxonomy such as the OWASP Top 10 or the CWE Top 25They are published where every developer can reach themThey are reviewed and updated at defined intervalsStatic analysis runs in continuous integration and enforces them automaticallySecurity-focused code review is performed by a trained reviewer on sensitive changesDeveloper security training is provided at onboarding and refreshed at defined intervalsThey are referenced in the definition of done for development tasksNone of the above

Options run from the most commonly in place to the least. Automated enforcement in continuous integration is the strongest mechanism. Standards published with no enforcement and no training give weak assurance. Standards naming no taxonomy cannot be tested against anything.

APP-004Security Testing in the Development Pipeline
boolean

Is security testing integrated into your development and release pipeline?

Security testing must be automated in CI/CD, not performed only before major releases. Blocking gates for critical and high findings are expected.

multi

Which security testing activities are integrated into your development pipeline?

SAST on every pull requestDAST on every release candidate or staging deploymentSoftware composition analysis (SCA) on every pull requestSecurity-focused code review by a qualified reviewerInfrastructure-as-code (IaC) scanningContainer image scanningSecurity testing is performed ad hoc or only before major releasesNo security testing in the pipelineNone of the above

SAST and SCA on every PR are baseline expectations for a mature secure development pipeline. DAST on release candidates and IaC scanning indicate a more comprehensive posture.

APP-005Penetration Testing
boolean

Is penetration testing of production applications, APIs and infrastructure conducted at a defined frequency of at least annually?

Testing must be performed by a party independent of the development team, either an external firm or a distinct internal red team. Self-assessed or developer-led testing does not satisfy this control.

select

How are penetration test findings managed after testing is complete?

All findings are tracked in an issue tracker, with SLA-based remediation and retest confirmation for critical/high findings, whoever commissioned the testAll findings are tracked in an issue tracker, with SLA-based remediation and retest confirmation for critical/high findingsFindings are documented and remediated but retest is not always performedFindings are reviewed but remediation is prioritised informally without defined SLAsNo formal process for tracking or remediating pen test findings

Every finding must have a corresponding ticket. Critical findings should be remediated and retested within 30 days. Untracked or unconfirmed remediation significantly weakens the value of the pen test. The strongest option separates out the case that usually leaks: a test a customer commissioned against the production estate produces findings that belong in the same tracker on the same terms, not in a report filed with the account team.

select

Which of the following best describes the scope and approach of your most recent penetration test?

External firm, full-scope test covering web applications, APIs, infrastructure and internal network, plus an adversary simulation under agreed rules of engagementExternal firm, full-scope test covering web applications, APIs, infrastructure and internal networkExternal firm, scoped test covering external-facing APIs and web applications onlyInternal team independent of the systems under test, full scopeBug bounty programme only, with no structured penetration testNo penetration test in the last 12 months

Options run strongest to weakest. At minimum, production APIs and public-facing applications belong in scope. Count an adversary simulation only where written rules of engagement were agreed before it started; an unscoped exercise is a different activity with a different risk profile. A bug bounty alone does not satisfy this control.

APP-007Software Supply Chain and Dependency Management
boolean

Is a software bill of materials generated for each production build?

Monitoring must be continuous, not just at the time of initial selection. SCA tooling integrated into CI is the expected mechanism, not periodic manual checks.

multi

Which dependency and patch management practices are in place?

Software composition analysis runs automatically in continuous integrationDependency findings above a defined severity threshold block deploymentsEnd-of-life or unsupported components are tracked with migration plansSecurity patches for critical dependency vulnerabilities are applied within the defined SLABinary-only components without source availability or a supplier warranty are barred except on a recorded, approved exceptionDependencies are reviewed manually at periodic intervalsNone of the above

Options run from the most commonly in place to the least. Automated composition analysis in the pipeline with a deployment gate is the baseline; manual-only review leaves published vulnerabilities unaddressed for weeks. A binary-only component from an unwarranted source is worse than an unpatched one: nobody can read it, nobody is obliged to fix it, and the scanner reports only what its metadata claims.

APP-008Secrets Management
boolean

Are all secrets held in an approved secrets management system rather than in source code, configuration files, version control or a prompt the model reads?

Answer for the secrets in production use. A prohibition on hardcoding that is stated in a policy but not enforced by scanning in the pipeline does not meet the control; Q2 captures which enforcement is in place. A system prompt counts: whatever the model can see, a user can eventually see.

multi

Which secrets management controls are in place in your development and deployment environment?

Centralised secrets vault in use (e.g. HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, Azure Key Vault)Secret scanning runs automatically in CI on every pull requestHistorical git repository scanning for committed secrets has been performedPrompt templates and system prompt configuration are in the scanned scopeAccess to secrets is logged and auditableSecrets are rotated on a defined schedule or automaticallySecrets are injected at runtime and never stored in config files or environment files committed to version controlNone of the above

A vault combined with CI-based secret scanning provides both preventative and detective coverage. Prompt templates are the surface most often left out of the scan, because they are treated as content rather than as configuration.

APP-009Change Management
boolean

Are all changes to production systems, applications, infrastructure and configuration subject to a formal change management process?

Every production change, including infrastructure and configuration changes, must have a traceable record. Emergency changes require an expedited but still documented approval, not zero oversight.

select

How are production changes authorised and deployed in your organisation?

All changes go through a formal change management system with documented approval before deployment; emergency changes use an expedited documented processMost planned changes are approved in advance; emergency changes sometimes bypass the formal processChanges are reviewed informally by the team but without a formal approval recordNo formal change management process: changes are deployed directly

Every production deployment should be traceable to an approved change record. The ability to audit who approved what change, and when, is a key audit expectation.

multi

Which of the following are part of your change approval and post-change process?

A security representative sits on the change approval body, named by roleA privacy representative sits on the change approval body, named by roleThe impact analysis names the controls a change touchesThose controls are verified after deployment and the result is recordedA failed verification triggers a rollback or a recorded remediationA rollback procedure is defined before the change is deployedEach change is logged with its initiator, its approver and a timestampNone of the above

Options run from the most commonly in place to the least. Naming who approves keeps security and privacy from being represented by whoever is nearest. Testing that a change works is not testing that the controls it touched still do: a change that quietly disables logging on a subsystem passes every test written for the change itself.

APP-010Environment Separation
boolean

Are development, test and production environments separated logically or physically?

Separation must be structural (e.g. separate cloud accounts, VPCs, Kubernetes namespaces), not solely procedural. Developers with write access to dev/test must not hold equivalent production write access.

select

Is production data permitted in development or test environments?

No: production data is never used in lower environmentsOnly with documented approval and verified de-identification or anonymisationSometimes used without formal de-identification or approvalRegularly used without restriction

Use of production data in non-production environments without de-identification is a data protection risk and a finding in most audit frameworks. Any approved exceptions must have a de-identification record.

multi

Which of the following apply to the separation between your development, test and production environments?

Distinct access controls in each environmentDistinct credentials in each environmentDistinct deployment rights in each environmentPromotion of a change between environments follows a defined approval pathEach promotion is recordedNone of the above

Options run from the most commonly in place to the least. Separation enforced only by naming convention is not separation. The test is whether an account that can deploy to test can also deploy to production.

APP-011API Security
boolean

Are all externally exposed and internally significant APIs subject to a defined set of security controls?

Authentication and authorisation must be enforced on every endpoint. Unauthenticated routes should be the exception with documented justification, not the default. Sensitive data must not appear in query parameters or error responses.

multi

Which API security controls are implemented in your production environment?

Authentication required on all external endpoints (OAuth 2.0, API key, JWT, or equivalent)Authorisation enforced at the object/resource level (not just at the route level)Rate limiting enforced at the API gateway or application layerInput validation applied on all endpointsSensitive data excluded from query parameters and error responsesAPI inventory is maintained and kept current (e.g. via OpenAPI specification)API security is included in the security testing scope (DAST, API scanning)None of the above

Authentication, object-level authorisation, and rate limiting are the three most impactful controls for preventing the most common API vulnerabilities (OWASP API Top 10).

APP-012Software Integrity Verification
boolean

Are build artefacts cryptographically signed?

Signing and verification must both be in place and automated. Signing without verification provides no meaningful protection. Unsigned artefacts should be rejected by the deployment pipeline.

multi

Which software integrity controls are in place in your build and deployment pipeline?

Build artefacts are signed using a defined mechanismSignature verification is enforced at deployment and unsigned artefacts are rejectedThe container registry or artefact repository blocks unsigned imagesRuntime integrity monitoring is active on production systemsFile integrity monitoring alerts on unexpected changes to deployed softwareA response is bound in advance to a detected integrity violation: halt, restart from a verified artefact or another defined controlA software bill of materials is generated and stored with each buildNone of the above

Options run from the most commonly in place to the least. Signing plus verification at deployment is the baseline; signing without verification protects nothing. For the bound response, count only an action the tooling takes on its own, not a runbook step a responder follows after reading an alert.

APP-013Secure System Architecture and Design Principles
boolean

Are documented secure architecture and engineering principles formally adopted?

The principles must be documented, accessible to engineers, and demonstrably applied in design decisions, not merely stated in a policy document. Architecture decision records (ADRs) are a typical artefact.

select

How are security architecture principles applied during the design of new systems or significant changes?

Formal design review process with a security stakeholder (architect or security lead) who approves designs before development beginsSecurity principles are referenced in design documents but review is informalArchitecture decisions are made by individual developers without a formal design reviewNo defined process for applying secure architecture principles

A formal design review with a security stakeholder, producing documented architecture decision records (ADRs), is the expected practice for significant systems.

APP-014Vulnerability Disclosure Programme
boolean

Does your organisation have a publicly accessible vulnerability disclosure programme (VDP) or responsible disclosure policy that defines how external researchers can report security vulnerabilities?

The VDP must be publicly reachable without authentication, include a defined submission channel, scope statement, response timeline commitment, and a safe-harbour clause protecting good-faith researchers.

select

How is your vulnerability disclosure programme operated?

Managed bug bounty programme on a dedicated platform (e.g. HackerOne, Bugcrowd) with defined scope and rewardsPublic VDP page with a defined submission channel and response SLA, but no financial rewardssecurity.txt file referencing an email address, without a formal programme pageAd hoc: no formal VDP; reports are handled informally if they arriveNo vulnerability disclosure mechanism in place

A formal VDP page with a defined SLA is the minimum. A managed bug bounty programme with scope, triage, and tracking provides stronger coverage. The absence of any disclosure channel leaves reported vulnerabilities without a clear path to resolution.

APP-015Processing Integrity
boolean

Is there a documented processing specification for each service that transforms customer data?

The specification is what an integrity check is tested against. Without one, a completeness check can only confirm that the job ran.

multi

Which processing integrity controls are in place?

Inputs validated for completeness and accuracy before processingRecords that fail validation rejected or quarantined rather than processedProcessing and delivery failures detected and logged with the records they affectedA defined correction process that records what was correctedOutputs checked against the specification before deliveryStored inputs and outputs reconciled against each other at defined intervalsNone of the above

Quarantine and correction are the pair that matters: a pipeline that drops bad records silently passes a completeness check on what it kept.

select

How are processing exceptions handled?

Every exception is investigated to a recorded outcome within a defined periodExceptions are investigated and the outcome is recorded, without a defined periodExceptions are reviewed in aggregateExceptions are visible in logs and acted on when noticedExceptions are not tracked

Options run from strongest to weakest. This measures whether an exception reaches a conclusion, not whether it is visible.

APP-016Sandboxed Execution of Untrusted Code
boolean

Does code from outside your own build pipeline execute only inside a confined environment?

Customer-supplied scripts, third-party plug-ins and code a model writes at run time all count. If any of them executes in the application process, the answer is no.

multi

Which restrictions apply to the environment that runs external code?

No ambient credentials reachable from the environmentOutbound network access denied by default with named exceptionsFilesystem read-only or scoped to the single executionProcessor, memory and run time limitsSeparation from other tenants' executionsExecution events, denials and limit breaches loggedNone of the above

The credential question is the one that decides the blast radius: an environment that can reach the cloud instance metadata service holds the privileges of the host regardless of its other limits.

select

What boundary confines the execution?

A separate virtual machine or microVM for each executionA container with a restricted system call profile and a network policyA process-level sandbox provided by the application runtimeRestrictions applied inside the interpreter onlyNo confinement boundary

Options run from strongest to weakest by how much of the host is reachable after an escape. An interpreter restriction is defeated by any bug in the interpreter.

BCM-001Business Continuity Plan
boolean

Does your organisation have a documented business continuity plan?

The BCP should be formally approved by senior management, version-controlled, and updated following any significant incident or organisational change.

select

When was the Business Continuity Plan last formally reviewed and approved?

Within the last 6 months6 to 12 months ago12 to 24 months agoMore than 24 months agoNo formal BCP exists

Annual review is the minimum requirement. A review triggered by a significant incident or major organisational change within the review period also satisfies this requirement.

multi

Which of the following does your business continuity plan record?

Critical services and their recovery prioritiesThe security controls that remain in force during degraded or failover operationA compensating measure and an approver for any control deliberately suspendedThe related response plans it interlocks with and the owner of eachThe points at which control passes between those plansContinuity exercises scheduled with the owners of those plansRecovery roles, communication protocols and escalation pathsNone of the above

Options run from the most commonly present to the least. Failover regularly costs centralised logging or a break-glass boundary, so the security posture under disruption is worth writing down before it is discovered during one. The handover points between plans are where multi-plan incidents fail.

BCM-002Disaster Recovery Plan
boolean

Does your organisation have a documented disaster recovery plan?

The DRP is distinct from the BCP: it should contain specific technical runbooks for recovering each critical system from backup or failover infrastructure.

multi

What does the Disaster Recovery Plan include?

System-specific recovery runbooks for each critical serviceA defined recovery sequence and dependency orderNamed roles and current contact details for the recovery teamBackup locations and failover targetsSpecific recovery commands or procedures rather than high-level guidanceTransaction recovery procedures returning transaction-based systems to a consistent stateLessons from the most recent recovery test incorporated into the current versionNone of the above

Options run from the most commonly present to the least. A plan carrying only high-level guidance is not usable under pressure. Transaction recovery is the element most often absent: restoring the last snapshot brings a system back running while leaving in-flight transactions half applied, so the service is available and the data is wrong.

BCM-003RTO and RPO Definitions
boolean

Are recovery time objectives and recovery point objectives defined for each critical service?

RTOs and RPOs must be explicitly defined, not inferred from backup frequency or infrastructure configuration. Each objective should be signed off by a named business owner.

multi

Which of the following apply to your recovery time and recovery point objectives?

Each objective is agreed with a named business ownerThey are recorded in the business continuity plan and the disaster recovery planThey are communicated to the teams that would carry out the recoveryThey are validated against contractual availability commitmentsThey are validated against regulatory commitmentsNone of the above

Options run from the most commonly in place to the least. The control requires the objectives to be defined and agreed, not any particular number. An objective the recovery team has never seen is a commitment made on their behalf.

BCM-004Backup Policy and Implementation
boolean

Are data and system backups performed at a frequency that satisfies the defined recovery point objective?

Backups should cover application data, system state, and configuration. Encryption using a managed KMS key and IAM-restricted access to backup storage are expected.

multi

Which of the following characteristics apply to your production backup implementation?

Backups run at a frequency meeting or exceeding the defined RPOBackups stored in a geographically separate region or off-site locationBackup data encrypted at rest using an approved keyAccess to backup storage restricted to a named authorised roleBackup scope includes application data, system state, and infrastructure configurationAutomated backup job monitoring with alerts on failureNone of the above

All six characteristics are expected for a production backup implementation that satisfies RPO commitments and audit requirements.

BCM-005Backup Restoration Testing
boolean

Is backup restoration tested at a defined frequency of at least annually?

Restoration tests must use actual production backup data, not synthetic test backups. Test results should document measured recovery time and data integrity outcomes.

select

What was the outcome of the most recent backup restoration test?

Pass: recovery completed within RTO/RPO targets; results documented and signed offPass with observations: recovery succeeded but minor issues were identified and remediatedFail: recovery did not meet RTO/RPO targets; remediation completed before next test cycleFail: remediation still in progressNo restoration test has been conducted

A passing test with documented results is the expected outcome. Any failure should trigger remediation before the next test cycle. An untested backup set should be treated as unverified.

BCM-006BCM and DR Testing
boolean

Are business continuity and disaster recovery plans exercised at least annually?

Exercises should include personnel with defined response roles. Lessons learned must be captured and result in updates to the BCP, DRP, or related procedures.

select

What type of BCM/DR exercise was most recently conducted, and when?

Full simulation or live failover test within the last 12 monthsFunctional test (partial systems or processes tested) within the last 12 monthsTabletop exercise within the last 12 monthsAny exercise type but more than 12 months agoNo BCM/DR exercise has been conducted

A tabletop exercise is the minimum acceptable exercise type. A full simulation or live failover test provides the strongest evidence of plan effectiveness.

multi

Which of the following follow each continuity or recovery exercise?

The result is recorded against the scenario exercisedPersonnel holding defined response roles took partLessons learned are recorded with named ownersThe continuity or recovery plan is updated where the exercise found a gapThe scenarios exercised are drawn from the disruptions most likely to affect the serviceNone of the above

Options run from the most commonly in place to the least. An exercise that produces no change to any plan is usually an exercise that tested the plan nobody doubted. Record the scenario as well as the outcome, because the scenario is what decides whether the test was worth running.

BCM-007Alternate Processing and Communications
boolean

Do documented provisions exist for processing critical workloads from an alternate site or cloud region?

Alternate processing provisions must not depend on access to the primary site or primary-site telecommunications. Out-of-band channels (e.g. personal mobile numbers, separate messaging platform) should be verified annually.

multi

Which alternate processing and communication provisions are documented and tested?

A named alternate cloud region or site with documented capacityActivation procedures that do not require access to primary-site systemsOut-of-band communication channels such as personal mobile contacts or an alternate messaging platformA contact list verified within the last 12 monthsAlternate processing tested as part of the most recent recovery exercisePrimary-site telecommunications dependencies documentedAccessibility problems at the alternate locations under an area-wide disruption, each with a mitigationNone of the above

Options run from the most commonly documented to the least. Untested provisions and unverified contact lists are the usual gaps. Accessibility is the assumption least often checked: an alternate region picked for latency often shares a power grid, a carrier or a staffing pool with the primary, so the event that takes out one reaches the other.

BCM-008Business Impact Analysis
boolean

Does a business impact analysis exist that ranks business processes by recovery priority?

The analysis ranks business processes, not servers. A list of systems by criticality is an asset inventory and answers a different question.

multi

Which of the following does the business impact analysis record for each process?

The services, systems and data the process depends onThird-party dependenciesImpact measured at more than one outage durationOperational, financial, regulatory and reputational impactThe maximum tolerable period of disruptionThe recovery priority and the business owner who agreed itNone of the above

Impact at more than one duration is what produces a defensible tolerable disruption period. A single worst-case figure ranks everything as critical and tells the recovery team nothing.

select

When is the business impact analysis reviewed?

At defined intervals and after any change that alters the criticality of a process or its dependenciesAt defined intervalsWhen a continuity plan is rewrittenIt has not been reviewed since it was produced

Options run from strongest to weakest. The change trigger matters more than the interval: a new product line or a new third party can move a process two priority bands between annual reviews.

BCM-009Backup Immutability and Isolation
boolean

Is at least one backup copy written to a store that cannot be altered or deleted before its retention period expires?

The store has to refuse the deletion. Answer no where deletion is prevented by a permission an administrator can grant themselves, or by a policy that says not to.

multi

Which of the following apply to that copy?

The retention lock is applied as the copy is writtenIt sits in an account or subscription separate from productionIt uses credentials that production roles do not holdNo production or backup-administration role can delete it or shorten its retentionA retention change or deletion requires a second authorised approverAn attempted deletion raises an alertNone of the above

The test an assessor runs is to try the deletion with the credentials an attacker would have taken. Answer against what those credentials can do today, not against the intended design.

select

How much of the recovery scope has an immutable isolated copy?

Every system within the recovery scopeThe systems holding customer dataOne or two systems, as a pilotNo system has one

Options run from strongest to weakest. Recovery scope means the systems the continuity plan commits to restoring, so the answer is measured against that list rather than against the backup estate as a whole.

BCM-010Third-Party and AI Provider Service Continuity
boolean

Is there a list of third-party services whose loss would breach a recovery objective?

This is a shorter list than the vendor inventory: only the services whose unavailability would stop a process from meeting its recovery objective. Model and inference providers count.

multi

Which of the following does each entry record?

The internal service that depends on the providerThe continuity commitment the provider has givenThe contingency that runs while the service is unavailableFor a model provider, the versions in production and the deprecation notice committed toAn exit plan naming the alternative and the work to move to itFor a customer-committed service, the clause of the third party's own contract requiring a contingency plan and its testing, with the service level attachedNone of the above

A contingency is what the service does, not what the incident team would decide at the time. For model providers the pinned version matters because a withdrawn version is an outage with a date on it. The last item is the one usually taken on trust: a provider that promises a customer continuity through a chain it has not contracted for is promising something it cannot enforce.

select

How is the contingency for a listed provider exercised?

Exercised at defined intervals by removing or blocking the provider, with the result recordedExercised once by removing or blocking the provider, with the result recordedWalked through on paperDocumented but not exercisedNo contingency is documented

Options run from strongest to weakest. Blocking the provider in a production-equivalent environment is what finds the retry loop, the missing timeout and the fallback that was never wired up.

DAT-001Data Classification Scheme
boolean

Does your organisation maintain a documented data classification scheme?

The policy should define at least three tiers (e.g. Public / Internal / Confidential / Restricted) and specify handling rules for storage, transmission, sharing and disposal at each tier. It must be approved by a named owner and reviewed within the last 12 months.

select

How are data assets assigned a classification tier?

Automated classification tooling (e.g. DLP, sensitivity labels)Manual classification by data owners at creationClassification applied during periodic data inventory reviewsClassification is not consistently applied

Automated tooling provides the most reliable coverage at scale. Manual classification by data owners is acceptable for smaller or less dynamic data sets, provided a data inventory confirms consistent application.

multi

For which of the following does the classification scheme define handling controls at each sensitivity level?

StorageTransmissionSharing with third partiesDisposal and destructionLabellingNone of the above

A scheme that names sensitivity levels without saying what changes between them gives an asset owner nothing to apply. Answer against the scheme as written, not against what the organisation does in practice.

DAT-002Information Labelling
boolean

Are information assets labelled in accordance with the data classification scheme so that recipients can identify the classification at the point of use?

Labels should be visible on documents, data stores, outputs and transmissions. Automated labelling via DLP or sensitivity label tooling (e.g. Microsoft Purview, Google Workspace) is preferred over purely manual labelling.

multi

Which asset types have classification labels actively applied?

Documents and files (internal collaboration tools)Emails and attachmentsDatabase records or data store metadataAPI outputs and data exportsCloud storage objects (e.g. S3 buckets, blob storage)None of the above

A mature labelling programme covers all major asset types. At minimum, documents, emails and data exports should be labelled. Gaps in cloud storage or database labelling should be noted.

DAT-003Encryption at Rest
boolean

Is all sensitive and confidential data encrypted at rest using an approved algorithm (AES-256 or equivalent) across databases, object storage, file systems and backup media?

Encryption must cover all environments holding sensitive or personal data including production databases, object stores (e.g. S3, Cloud Storage), backup snapshots, and attached volumes. Verify the algorithm meets AES-256 or an equivalent approved standard.

multi

At which layer(s) is encryption at rest applied?

Storage volume encryption (e.g. EBS, persistent disk)Object storage server-side encryption (e.g. S3-SSE, GCS CMEK)Database-level transparent data encryption (TDE)Field-level or application-level encryption for the most sensitive fieldsBackup encryptionNone of the above

A defence-in-depth approach applies encryption at multiple layers. Field-level encryption for highly sensitive fields (e.g. national IDs, payment data) provides the strongest protection against logical access to the database layer.

DAT-004Encryption in Transit
boolean

Is all data transmitted over networks, internal and external, protected by an approved transport encryption protocol?

TLS 1.3 is preferred. TLS 1.0 and 1.1 must be disabled. This applies to all public-facing endpoints and to service-to-service communication within the infrastructure.

select

What is the minimum TLS version enforced on external-facing endpoints?

TLS 1.3 onlyTLS 1.2 minimum (TLS 1.3 also supported)TLS 1.2 minimum (TLS 1.3 not yet enabled)TLS 1.1 or lower is still permitted on some endpointsNot assessed

TLS 1.2 is the minimum acceptable baseline. TLS 1.3 is strongly preferred. Any answer indicating TLS 1.1 or lower requires a remediation plan.

multi

Which of the following are in place for the certificates and transport encryption configuration of your production endpoints?

A documented certificate policy names the approved issuing authoritiesA certificate inventory records every certificate with its expiry dateCertificates are renewed automatically before expiryCertificates are revoked on suspected compromiseManaged trust stores contain only approved trust anchorsCertificate status is checked at validation time against revocation dataThe transport encryption configuration is scanned at defined intervals and after any cryptographic configuration changeDeprecated protocol versions and weak cipher suites are disabled on every endpointNone of the above

Automatic renewal removes the commonest outage behind this control, an expired certificate nobody was watching. Scanning on each deployment is stronger than a scheduled scan; either meets the last item provided it also runs after a change to a load balancer, an API gateway or a certificate.

DAT-005Cryptographic Key Management
boolean

Does your organisation have a documented cryptographic key management policy that covers the full key lifecycle: generation, storage, rotation, revocation and destruction?

The policy must specify key rotation periods, require keys to be stored separately from the data they protect, restrict and log access to key material, and be approved within the last 24 months.

select

How are encryption keys managed in your production environment?

Cloud provider KMS with automatic rotation enabled for all customer-managed keysCloud provider KMS with manual rotation on a documented scheduleOn-premises HSM or dedicated key management solutionKeys managed within the application without a dedicated KMS or HSMNo formal key management in place

Cloud KMS with automatic rotation is the baseline expectation where the environment runs on a cloud provider. Keys managed within the application without separation represent a significant control weakness.

multi

Which of the following does your key management programme record?

A named accountable role for the keyA single recorded purposeA cryptoperiod with rotation enforced against itThe current lifecycle state (pre-activation, active, suspended, deactivated, compromised, archived, destroyed)The date and approver of the last state changeA documented recovery route for the keying materialAn approved list of protocols, algorithms, cipher strengths and usage practices, with the strength required per asset classNone of the above

The first six items are recorded per key, the last is recorded once for the organisation. Options run from the most commonly held to the least. A programme that records purpose and rotation but no lifecycle state can show that a rotation policy exists without showing that any individual key followed it. The recovery route is the element most often left to the key management platform's defaults, and the approved list is the one most organisations hold somewhere without connecting it to the keys in use.

DAT-006Data Inventory and Records of Processing
boolean

Does your organisation maintain a current Records of Processing Activities (RoPA) or equivalent data inventory documenting all personal data processing with the fields required by GDPR Article 30?

The RoPA must include: processing purposes, data categories, data subject categories, legal basis, retention periods, third-party recipients, cross-border transfers, and applicable safeguards. It should be reviewed and updated at least annually.

select

How is the data inventory or RoPA maintained?

Privacy management platform that discovers data flows and flags entries that have gone out of dateRegister held in a documentation or collaboration system with a named owner and a scheduled reviewSpreadsheet maintained by the privacy or legal teamNo structured record: data flows are described informally

Options run from the strongest record to the weakest. A privacy management platform discovers flows and raises the entries nobody has touched; OneTrust, Securiti and TrustArc are examples of the category. A register in a documentation or collaboration system such as Confluence, Notion or SharePoint holds up where the number of processing activities is small and one person owns the review. A spreadsheet is acceptable at that size and fails the same way a register does, by going stale between annual reviews with nobody watching.

DAT-007Data Minimisation and Purpose Limitation
boolean

Does your organisation have a documented policy or procedure requiring that only the minimum personal data necessary for a specific, documented purpose is collected?

The policy should explicitly prohibit collection of personal data without a documented purpose and require review when product capabilities change. It should be approved by the DPO or equivalent authority.

multi

How does your organisation enforce data minimisation and purpose limitation in practice?

Privacy or data minimisation review gate in the product development processDPO or privacy lead sign-off required before new data fields are added to a productProcessing purposes are reviewed when product features changeData fields are periodically audited against stated purposes and removed if unjustifiedNo formal enforcement mechanism: minimisation is applied on a best-efforts basisNone of the above

A mandatory review gate in the development process (e.g. a privacy design review ticket) is the most effective control. Selecting multiple overlapping mechanisms indicates a mature programme.

boolean

Is a compatibility assessment recorded before personal data is used for a purpose that was not disclosed when it was collected?

The assessment covers the link between the old and new purposes, the context of collection, the nature of the data, the consequences for individuals and the safeguards applied. Answer yes only where the assessment is written down and dated before the new processing started. A decision recorded in a meeting note without those five elements is not one.

DAT-008Data Retention and Deletion
boolean

Does your organisation maintain documented retention schedules for all data categories?

Retention schedules should be assigned to all personal data categories in the RoPA, with a legal or business justification for each period. Deletion should cover primary storage, backups and replicas.

select

How is data deletion or anonymisation executed when a retention period expires?

Fully automated deletion jobs scheduled per retention schedule, including backups and replicasAutomated deletion for primary storage; manual deletion from backups on a periodic cycleManual deletion triggered by a periodic review processDeletion is performed on a case-by-case basis without a structured scheduleNo active deletion process in place

Fully automated deletion across all storage tiers (primary, backup, replica) is the strongest control. Any manual or ad hoc approach must be supported by execution records to demonstrate completeness.

multi

What does the retention schedule state about customer data once a contract ends?

The retrieval period during which the data stays available to the customerThe erasure that follows the expiry of that retrieval periodThat erasure waits until the customer has finished moving to another service or to its own infrastructureThe customer's digital assets inside the erasure scopeNone of the above

Options run from the most commonly stated to the least. The sequence matters more than the periods: an erasure clocked from termination rather than from the end of the retrieval window deletes data a customer is still entitled to collect, and one with no completion condition deletes it mid-migration. Digital assets are the item most often left out, because they are held by a different team from the one that owns the retention schedule.

DAT-009Privacy Notice and Transparency
boolean

Is a current privacy notice published at or before the point of personal data collection, disclosing all information required by GDPR Articles 13 and 14?

The notice must include: controller identity and contact details, DPO contact (if applicable), processing purposes and legal bases, retention periods, third-party recipients, international transfer mechanisms, and all six data subject rights. It should be dated and reviewed within the last 12 months.

select

What process ensures the privacy notice remains current when processing activities change?

The privacy notice is updated as part of every product release or processing change that affects personal data, with DPO reviewThe privacy notice is reviewed on a fixed annual cycle regardless of changesThe notice is updated reactively when a change is flagged by the legal or privacy teamNo formal update process: the notice is updated on an ad hoc basis

The notice should be updated proactively when new purposes, new third-party recipients, or changes to data subject rights mechanisms are introduced. Annual review alone is insufficient for a product whose processing changes between releases.

multi

Which of the following apply to the way your privacy information is presented?

Concise, transparent and easily accessible formClear and plain language, tested against a stated reading levelA version addressed to children where the service reaches themAn oral route where the individual's identity is proven by other meansIndividuals are told of a new purpose before their data is processed for itNone of the above

Options run from the most commonly in place to the least. Form and content fail differently: a notice listing every required element in six thousand words of legal prose is complete and not intelligible. The further-processing notice is owed before the processing starts, not at the next annual refresh of the notice.

DAT-010Consent Management
boolean

Where consent is relied upon as the legal basis for processing, does your organisation use a consent management mechanism that records granular, freely given, specific and withdrawable consent?

Consent must be opt-in by default (no pre-ticked boxes). Withdrawal must be as easy as granting consent. Consent records should include timestamp, version, and categories consented to.

select

How is individual consent recorded and managed?

Consent management platform holding a record per individual and per purpose with an audit logConsent capture built into the product, writing a record per individual and per purpose to a queryable storeConsent captured at sign-up with no record per individual and purposeNo structured or retrievable record of consent

Options run from the strongest record to the weakest. A consent management platform and a mechanism built into the product are both acceptable, provided the record holds the individual, the timestamp, the consent version and the purposes agreed to; OneTrust, Cookiebot and Usercentrics are examples of the platform category. The test is whether a question about one person on one date can be answered from the record. Consent captured once at sign-up cannot be withdrawn for one purpose while the others stand.

multi

Where a consent request sits inside a wider declaration such as terms of service, which of the following apply?

The consent request is presented separately from the other matters in the declarationThe request uses clear and plain language in an easily accessible formThe right to withdraw is stated to the individual before consent is takenWithdrawal takes no more steps than giving consentNone of the above

Options run from the most commonly in place to the least. Consent buried in terms of service is the commonest reason a recorded consent turns out to be invalid: the individual agreed to a document rather than to the processing. If no consent request is bundled into a wider declaration, answer against the standalone flow.

DAT-011Data Subject Rights Fulfilment
boolean

Is there a documented process for handling data subject rights requests?

Each right should have a documented workflow, identity verification step, and defined internal handoff. A request tracking log must demonstrate requests are actioned within 30 days (or 90 days with documented extension).

multi

Which data subject rights can your organisation fulfil without requiring manual engineering intervention?

Access (subject access request, export of personal data)Rectification (correction of personal data)Erasure (deletion of personal data across all systems)Restriction (suppressing processing without deleting data)Portability (machine-readable export of personal data)Objection (suppressing processing for a stated reason)None of the above

Self-service or tooling-assisted fulfilment for access, portability and erasure is the expected standard for a mature product. Rights that require manual engineering effort introduce delay and error risk.

multi

Which of the following does your rights request process do?

Tells the individual the reasons when a request is refusedNames the supervisory authority complaint route and the judicial remedy in every refusalHandles requests free of chargeApplies a fee or a refusal only where a request is shown to be manifestly unfounded or excessive, with that evidence recordedAsks for identifying information only where there is a reasonable doubt about identityCompletes or refuses each request within the statutory response period, with any extension recordedNone of the above

Options run from the most commonly in place to the least. A refusal with no reasons and no complaint route leaves the individual with nowhere to go. Demanding identity documents for every request deters more people than it protects, and the burden of showing a request is excessive sits with the organisation rather than the requester.

DAT-012Data Protection by Design and Default
boolean

Does a design review against privacy and security requirements take place before a feature involving personal data is deployed?

A privacy-by-design gate (e.g. design review ticket, DPO sign-off) must be completed before any new feature involving personal data is released to production. Default configurations should expose the minimum necessary data.

select

How are privacy-by-design requirements enforced in the development lifecycle?

Mandatory privacy design review ticket with DPO or Privacy Engineer sign-off as a deployment gatePrivacy requirements included in definition of done but not formally gatedPrivacy review is conducted post-deployment during a retrospective or audit cycleNo formal privacy review: engineers apply privacy principles on a best-efforts basis

A mandatory deployment gate with documented sign-off is the most effective control. Post-deployment review or best-efforts application indicates a significant control gap.

boolean

Do the default configurations in your product expose the minimum personal data necessary for the feature to work?

Answer against the state a new account or a new feature arrives in, before anyone changes a setting. A privacy-protective option that a user has to find and switch on is a setting, not a default.

DAT-013Data Protection Impact Assessment
boolean

Does your organisation conduct Data Protection Impact Assessments (DPIAs) before initiating processing activities that are likely to result in high risk to individuals, including AI-driven processing, large-scale profiling, or use of new technologies?

DPIAs must be completed before high-risk processing commences. GDPR Article 35 mandates them for systematic profiling, large-scale processing of special category data, and use of new technologies. AI-driven features frequently meet this threshold.

multi

What triggers a mandatory DPIA in your organisation?

Large-scale processing of personal dataSystematic profiling of individualsUse of AI or automated decision-making that significantly affects individualsProcessing of special categories of data (e.g. health, biometric)Introduction of a new technology or significant change to an existing processing activityDPIAs are conducted at a fixed periodic interval only, not triggered by activity typeNone of the above

Trigger criteria should align with the ICO or EDPB list of processing operations requiring a DPIA. AI processing, profiling and special category data must be included. Fixed-interval-only DPIAs without activity triggers indicate a control gap.

boolean

Where an impact assessment leaves a high residual risk that cannot be mitigated, is the supervisory authority consulted before the processing begins?

Answer yes only where the consultation happens before processing starts and the authority's written advice is recorded against the assessment. The consultation has a statutory clock of its own, so a project that discovers the requirement late loses weeks. A recorded decision not to proceed also satisfies the clause.

DAT-015Data Transfer Controls
boolean

Are all cross-border transfers of personal data to countries without an EU adequacy decision governed by an approved transfer mechanism such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)?

The 2021 EC SCCs must be used for transfers under the GDPR. Pre-2021 SCCs invalidated post-Schrems II are not acceptable. A Transfer Impact Assessment should accompany transfers to high-risk jurisdictions.

multi

Which transfer mechanism(s) does your organisation rely upon for international transfers of personal data?

EU Standard Contractual Clauses (2021 SCCs)Adequacy decision for the destination countryBinding Corporate Rules (BCRs)UK International Data Transfer Agreement (IDTA)Derogations under GDPR Article 49 (e.g. explicit consent, performance of a contract)Transfers have not been assessed for cross-border implicationsNone of the above

Most providers rely on 2021 SCCs for transfers to the US and other non-adequate countries. Sole reliance on Article 49 derogations for routine processing is not permitted under GDPR.

DAT-016Data Masking and Pseudonymisation
boolean

Is sensitive and personal data masked, pseudonymised or replaced with synthetic data in non-production environments (development, staging, test) and in analytics, support tooling and logs?

Production personal data must not appear unmasked in non-production environments or in internal tooling unless there is a documented and DPO-approved exception with appropriate compensating controls.

select

What approach is used to protect personal data in non-production environments?

Automated masking pipeline runs before production data is copied to any non-production environmentSynthetic or generated test data is used exclusively: no production data in non-productionManual masking applied by engineers on an as-needed basis with no automated enforcementProduction data is used in non-production environments with access restrictions as the primary controlNo controls in place: production data is freely available in non-production environments

Automated masking or exclusive use of synthetic data are the strongest controls. Manual masking without automated enforcement is unreliable. Using production data in non-production environments with access-only controls is not an acceptable substitute for masking.

DAT-017Data Leakage Prevention
boolean

Does your organisation have technical controls to detect and prevent unauthorised exfiltration of sensitive and personal data?

DLP controls should monitor all major egress channels (email, cloud storage, API exports, messaging). Network egress should be restricted by default. Alerts should route to a responsible reviewer.

multi

Which data leakage prevention controls are active in your environment?

DLP tooling monitoring email and collaboration platforms for sensitive dataDLP policies covering API exports and bulk data downloads from the applicationNetwork egress filtering restricting outbound traffic to approved destinationsAnomaly detection alerts for bulk data access or unusual export volumesCloud access security broker (CASB) monitoring for unsanctioned data transfersNone of the above

A layered approach combining application-level DLP, network egress controls and anomaly detection provides the strongest coverage. At minimum, DLP should cover email and bulk export channels for Confidential and Restricted data.

DAT-018Data Protection Officer
boolean

Has your organisation recorded an assessment of whether it is required to designate a data protection officer?

The assessment is the artefact, whatever it concludes. An organisation that has concluded no duty applies meets this question if the conclusion, the criteria tested and the date are written down. Q2 covers the appointment where the duty does apply.

select

How is the DPO role structured within your organisation?

Full-time internal DPO, formally appointed in writing, reporting to board levelPart-time internal DPO combined with another role that does not create a conflict of interestExternal DPO engaged under a service contractA privacy lead or equivalent role that is not a formally designated GDPR DPONo DPO or privacy lead in place

The DPO must not hold a role that creates a conflict of interest (e.g. CISO, legal counsel for processing decisions, or head of marketing). An external DPO is permitted under GDPR provided independence and access requirements are met.

DAT-019Lawful Basis for Processing
boolean

Does every personal data processing activity in your organisation have a documented lawful basis under GDPR Article 6 (or Article 9 for special categories) recorded in the data inventory or RoPA?

The legal basis must be specific to each processing purpose and disclosed in the privacy notice. Processing without a valid, documented legal basis is unlawful regardless of the technical security measures in place.

multi

Which of the following does your record of lawful bases do?

Records a lawful basis for every processing activity in the data inventoryRecords the basis against the processing purpose rather than against the systemRecords an Article 9 condition wherever special category data is processedDiscloses the basis for each purpose in the privacy noticeCarries a legitimate interests assessment wherever that basis is relied onStops or does not start processing where no valid basis is recordedNone of the above

Options run from the most commonly in place to the least. Every basis in Article 6 is a valid answer, so the question is not which ones are used but whether each one is recorded, disclosed and supported. A basis recorded against a system rather than a purpose cannot be shown to fit the processing it covers.

DAT-020Accuracy of Personal Data
boolean

Does your organisation have a process to keep the personal data it holds accurate?

Users should be able to update their own core personal data fields (name, email, contact details) directly in the product without requiring a formal request. Corrections should propagate to all systems holding the inaccurate record.

multi

How are inaccurate personal data records identified and corrected?

Users can update their own personal data via self-service account or profile settingsA formal data subject rectification request process is in place (tracked and responded to within 30 days)Automated data quality checks flag anomalies or stale records for reviewData pipelines include validation rules that prevent obviously inaccurate data from being storedCorrections are applied manually on an ad hoc basis without a tracked processNone of the above

Self-service correction capability alongside a formal rectification request process provides the strongest coverage. Corrections must propagate to all systems (primary database, downstream systems, backups where applicable) to be effective.

DAT-021Customer-Managed Encryption Keys
boolean

Can a customer supply and hold the encryption key that protects its own tenant data?

Answer yes only where the key material sits under the customer's control and the customer can withdraw the service's use of it without the provider acting. A provider-held key that is dedicated to one tenant is not a customer-managed key; that is DAT-005.

multi

Which of the following does the key ownership statement give to customers?

Which keys the provider holds and which the customer holdsHow a customer supplies, rotates and withdraws its keyWhat happens to the tenant data when a customer key is withdrawnThe period within which withdrawal takes effectNone of the above

A customer reads the statement before deciding whether to use its own key, so each element is tested against the live key configuration rather than against the sales material. Publishing it in a trust centre or annexing it to the data processing agreement both count.

select

How is the effect of withdrawing a customer key verified?

Tested at defined intervals on a tenant configured with a customer key, with the result recordedTested once when the capability was built, with the result recordedDescribed in documentation but not testedNeither tested nor described

Options run from strongest to weakest. The test that matters is whether the service loses access within the period the statement gives, including access through caches and read replicas. A capability that has never been exercised is an assertion, not a control.

DAT-022Data Residency and Location Transparency
boolean

Is there a current record of the countries and cloud regions in which customer data is stored, processed and backed up?

The record has to cover processing and backup as well as primary storage, since those are the locations that surprise buyers. A sub-processor list without locations does not answer this question.

multi

Which of the following does the location record cover?

Primary storage locationsProcessing locations, including support and analytics accessBackup and disaster recovery locationsThe locations each sub-processor usesThe countries each service is operated, supported and engineered fromThe country of each sub-processor's parent undertakingThe jurisdiction whose law the infrastructure running each service is subject toThe record is published where a prospective customer can read it without an accountNone of the above

Support tooling and analytics are the usual source of a location the record misses, because data is read from a region it is not stored in. The operating, support and engineering countries are a second set again: they answer where the people and the pipelines are, not where the bytes are. Jurisdiction is a legal answer and can differ from every geographic answer above it. Published means readable without an account, not supplied on request.

select

How is the permitted set of regions enforced?

Enforced by platform policy that blocks resource creation outside the permitted set, with exemptions recorded and expiringEnforced by platform policy that blocks resource creation outside the permitted setDetected after the fact by a periodic scan for resources outside the permitted setSet out in a standard that engineers are expected to followNot restricted

Options run from strongest to weakest. Preventive enforcement at the account or organisation level is the difference between a location record that describes the estate and one that constrains it.

DAT-023Customer Data Export and Portability
boolean

Can a customer retrieve the data it holds in the service through a documented interface or API?

A support ticket that produces a manual database dump is not a documented interface. Answer yes where the customer can start and complete the retrieval itself against published documentation.

multi

Which of the following does the export documentation state?

The scope of data an export includesThe format of each exported data typeThe standard or open interoperability specification each format conforms toThe categories held back from the export and the ground for eachThe period after termination during which retrieval stays availableThe point at which customer data is deleted after terminationThe arrangement that keeps retrieval available if the organisation stops running the serviceNone of the above

Count only what the published documentation states. The termination window and the deletion point are the two a customer needs before it signs and the two most often missing. A conformance claim counts where it names a specification a second system could be built against, not where it names a file type. The last item is the one an export API cannot answer for itself: insolvency, resolution and discontinuation all remove the interface the other items describe.

select

In what form is customer data exported?

A structured, commonly used, machine-readable format documented for every data typeA structured machine-readable format for most data types, with the remainder as documents or reportsA report or document format onlyProduced manually on request with no defined format

Options run from strongest to weakest. Commonly used means a format another system can read without bespoke work, such as CSV, JSON or a documented archive of those. A PDF of the same content is not portable.

DAT-024Special Category and Criminal Conviction Data
boolean

Is every processing activity screened for special category personal data?

Every activity means human resources, recruitment, support and marketing as well as the product. Answer no if screening has been done for the product only.

multi

Which of the following are recorded against an activity that involves special category or criminal conviction data?

The screening result for special category dataThe screening result for criminal conviction and offence dataThe Article 9(2) condition relied onThe necessity assessment supporting that conditionThe authority or law that permits the conviction data processing, with its safeguardsNone of the above

The screening result is recorded whether it is positive or negative, so that an unscreened activity is distinguishable from a clean one. Conviction data is treated separately from the Article 9 categories because a different test applies to it.

select

When is an activity screened?

Before the activity starts and again whenever its data or purpose changesBefore the activity startsAt the periodic review of the records of processingWhen a question is raised about a particular activityScreening is not scheduled

Options run from strongest to weakest. The change trigger is what catches the new free-text field or the new data source that turns a screened-clean activity into a flagged one.

DAT-025Automated Decision-Making and Profiling Rights
boolean

Is there a register of decisions taken solely by automated processing that produce a legal or similarly significant effect on an individual?

Solely automated means no meaningful human involvement in the decision itself; a person who rubber-stamps an output does not change the answer. Answer no if such decisions are made but are not listed anywhere.

multi

Which of the following are available to an individual subject to such a decision?

Notice that the decision was made solely by automated processingAn explanation of the logic involved and its significance and envisaged consequencesA route to obtain human interventionA route to express a point of view and to contest the decisionA recorded outcome for each request made through that routeNone of the above

Available means reachable by the individual from the decision, not obtainable by writing to a privacy mailbox and waiting. The explanation is of the logic and its consequences, not of the model architecture.

select

How is the condition that permits each automated decision recorded?

Recorded against each decision and reviewed whenever the decision or its inputs changeRecorded against each decisionRecorded for some decisionsNo condition is recorded

Options run from strongest to weakest. The condition is explicit consent, necessity for a contract or authorisation in law. A general lawful basis for the product is not the same thing and will not carry the decision.

DAT-026Customer Transition and Switching Execution
boolean

Is a switching record kept for every customer that leaves the service?

One record per departing customer, whether it moved to another provider, moved to its own infrastructure or asked for erasure. A closed support ticket counts only where it holds the elements the control lists.

multi

What does the switching record capture?

The date the switching request was receivedThe destination the customer electedAssistance given to the customer and to third parties it authorisedContinuity risks disclosed to the customer during the transitionEvidence that the service level and support entitlement were unchanged through the transitionThe date the transition completedThe date the data was erasedAny notification that the contractual transitional period could not be met, with the ground and the alternative offeredNone of the above

Answer on the records for customers that have actually left. An element the runbook says will be captured but that no record holds does not count.

select

How is the transition runbook exercised?

At a defined interval against a scenario in which the organisation cannot continue operating, with the result recordedAt a defined interval against a customer-initiated migration, with the result recordedOnly during a real customer migrationDocumented but not exercisedNo runbook exists

Options run from the strongest exercise to the weakest. The first two differ in the scenario, not in the discipline: a scenario the organisation runs while it is still operating cannot test the handover a successor would receive if it were not.

DAT-027Switching Interfaces and Functional Equivalence Support
boolean

Can a customer on the lowest paid or self-service plan retrieve its data through the same interface as a customer on the highest plan?

The question is about entitlement, not about rate limits applied equally to every plan. An interface reachable only after a support request, a partner agreement or an upgrade is a no.

multi

Which of the following does the organisation supply to a customer moving to another service?

Documented retrieval interfaces reachable without contacting supportA route for the customer to authorise a third party to call themThe configuration needed to reconstruct the service elsewhereDocumentation of the service's behaviour beyond the data modelTechnical support during the moveTooling that performs part of the moveNone of the above

Tick an item only where a customer can obtain it without a negotiation. Documentation of behaviour beyond the data model means defaults, limits, scheduling and what each setting does, not the schema.

select

What do the documented export formats state about interoperability specifications?

The specification each format conforms to and the date compatibility was reachedThe specification each format conforms toThe format names onlyThe formats are not documentedNo interoperability specification has been published for this service type

Options run from the most complete statement to the least, with the last reserved for a service type no specification covers yet. Where no specification exists, the last option is the accurate answer rather than the third.

GOV-001Information Security Policy
boolean

Does your organisation have a documented information security policy that has been approved by senior management?

The policy should carry a named approver (e.g. CISO or CEO), an approval date within the last 12 months, and a defined scope statement.

select

How frequently is your information security policy formally reviewed and re-approved?

At least annuallyEvery 2 yearsOnly when significant changes occurAd hoc / no fixed scheduleNever formally reviewed

ISO 27001 and SOC 2 expect at minimum an annual review. Look for a review record (meeting minutes or a workflow ticket) dated within the required interval.

GOV-002Information Security Roles and Responsibilities
boolean

Are information security roles and responsibilities formally documented and assigned to named individuals or functions?

Look for a roles-and-responsibilities document or RACI that names a security programme owner and assigns asset ownership for critical information assets.

multi

Which of the following security ownership roles are formally defined and filled in your organisation?

Named CISO or security programme ownerInformation asset owners for critical assetsData protection / privacy leadSecurity team with documented responsibilitiesNone of the above

At a minimum, a named security programme owner and asset owners for critical systems should be documented and verifiable against the org chart.

GOV-003Management Commitment and Accountability
boolean

Is your information security programme sponsored by a named executive who is accountable for its direction and resources?

The sponsor should be a C-level executive or equivalent who is named in the security programme documents and receives regular programme status updates.

select

How frequently does senior management formally review the status of the information security programme?

Quarterly or more frequentlySemi-annuallyAnnuallyOnly when a significant incident occursNo formal management review takes place

Management review meetings should produce documented minutes with security agenda items, attendance records, and action items. Annual is the typical minimum.

boolean

Does a board or an equivalent body independent of management review the information security programme at a defined interval?

Independence means the body sits outside the management line that runs the programme. Where there is no board, the equivalent body is the group holding the owners' interest, such as an investor committee or an audit committee. Minutes recording what was reviewed and decided are the evidence; an agenda listing the item is not.

GOV-004Information Security Programme
boolean

Does a documented information security programme plan exist?

The programme plan should be a living document approved by management, listing all security domains in scope and referencing budget or headcount allocation.

select

How is progress against the information security programme plan reported to management?

Regular written status reports reviewed by a named executiveVerbal updates at management meetings with no formal reportOnly on requestProgress is not formally reported

A documented status report (quarterly or annually) addressed to or acknowledged by a named executive is the expected evidence.

multi

Which of the following does the information security programme plan define?

Its scopeIts objectivesThe security domains it coversThe resources allocated to it, such as budget or headcountIts alignment to the assessed business riskNone of the above

Options run from the most commonly defined to the least. Resource allocation is the limb most often absent. A plan with objectives and no resources behind them is a statement of intent.

GOV-005Risk Assessment
boolean

Does your organisation conduct formal information security risk assessments on a defined schedule?

A risk assessment should document threats, vulnerabilities, likelihood, impact, current controls, and treatment decisions, produced by a named assessor.

select

How often is a full information security risk assessment conducted?

At least annually and when significant changes occurAnnually on a fixed schedule onlyEvery 2 yearsOnly when triggered by an incident or audit findingNo formal risk assessment process exists

Most frameworks require annual assessment at minimum, plus ad hoc assessment on significant system or business changes.

multi

Which of the following does your risk register record for each identified risk?

A likelihood ratingAn impact ratingThe treatment decision takenA named ownerThe current treatment statusThe date the entry was last reviewedNone of the above

Options run from the most commonly held to the least. A register carrying ratings but no owner cannot be worked. One carrying no review date cannot be shown to reflect the risks as they stand rather than as they stood at the last assessment.

GOV-006Risk Management Programme
boolean

Does your organisation have a formal enterprise risk management programme?

The ERM programme should be governed by an approved policy that states risk appetite, assigns ownership of risks to named roles, and defines the review cadence.

select

How are risk acceptance decisions documented and authorised in your organisation?

Formal risk acceptance records with a named approver and expiry dateDocumented in the risk register with a named owner but no formal acceptance recordVerbal agreement recorded in meeting minutesRisk acceptance is not formally documented

Each accepted risk should have a signed or digitally approved acceptance record that names the approver and states the rationale and review date.

multi

Which of the following does the risk management programme document?

A risk tolerance statementThe treatment options available: accept, mitigate, transfer, avoidOwnership of each risk assigned to a named roleA defined interval for reviewing risk statusEach risk decision traceable to the person who approved itNone of the above

Options run from the most commonly documented to the least. Without a stated tolerance, treatment decisions cannot be tested against anything and two people assessing the same risk reach different answers.

GOV-007Risk Treatment and Remediation Tracking
boolean

Does your organisation maintain a tracked plan of action for open risk findings and control deficiencies?

This may be a plan of action and milestones (POA&M), a remediation tracker, or equivalent. Findings from risk assessments and audits should appear in it with current status.

select

How often is remediation progress against open risk findings reported to management?

MonthlyQuarterlySemi-annuallyAnnuallyOnly when escalatedProgress is not formally reported to management

Regular management-level reporting (monthly or quarterly) with aging, closure rates, and overdue items is the expected practice.

multi

What does each entry in the remediation tracker record?

A named ownerA target remediation dateThe current statusThe source of the finding, such as a risk assessment, an audit or an incidentThe date the entry was closedNone of the above

Options run from the most commonly held to the least. An entry with no target date cannot age. A tracker where nothing ages reports the same picture every period.

GOV-008Fraud Risk Assessment
boolean

Does a documented fraud risk assessment exist?

A fraud risk assessment should document insider threat and access-misuse scenarios with likelihood and impact ratings and link findings to detective and preventive controls.

multi

Which of the following controls has your organisation implemented in direct response to identified fraud risk?

Access logging and anomaly detectionSegregation of duties controlsMandatory leave / dual-approval for high-risk transactionsBackground screening for high-risk rolesConfidential incident reporting channelNone of the above

The link between the fraud risk assessment findings and the controls designed in response should be documented.

multi

Which of the following does the fraud risk assessment record?

The fraud scenarios the organisation is exposed toMisuse of system access and other insider scenariosA likelihood and impact rating for each scenarioThe preventive or detective control that addresses each scenarioA recorded treatment decision where no control addresses a scenarioA review date within the defined intervalNone of the above

Options run from the most commonly recorded to the least. Insider scenarios are the ones a fraud assessment written from a financial-controls template tends to miss, because the loss path runs through system access rather than through a payment.

GOV-009Segregation of Duties
boolean

Has your organisation recorded the conflicting role combinations that must not be held by one account?

A segregation of duties (SoD) matrix or conflict register should list role pairs that must not be combined, with compensating controls for any necessary exceptions.

select

How does your organisation verify that SoD conflicts are not present in the live IAM environment?

Automated IAM controls prevent conflicting role assignmentsRegular automated reports cross-reference role assignments against the SoD matrixManual periodic review of user-role assignments against the SoD matrixAd hoc review only when access changes are requestedSoD enforcement is not currently verified

An IAM export cross-referenced against the SoD conflict matrix, showing no user holds both sides of a conflict, is the expected evidence.

boolean

Where full separation of a conflicting pair is not feasible, is a compensating control documented for it?

Answer yes only where each conflict left in place carries a named compensating control and the person who accepted it. A small organisation will have such pairs; what fails the control is leaving them unrecorded.

GOV-010Legal, Regulatory and Contractual Compliance Inventory
boolean

Does your organisation maintain an inventory of applicable legal, regulatory and contractual information security obligations?

The inventory should cover obligations across all operating jurisdictions and be reviewed at least annually, with additions made when new contracts or regulations apply.

select

How frequently is the compliance obligations inventory reviewed and updated?

At least annually, with ad hoc updates on new contracts or regulatory changesAnnually on a fixed schedule onlyOnly when triggered by an audit or regulatory inquiryNo formal review cadence is defined

An annual review that produces a dated record with a named reviewer is the minimum. Updates should be visible whenever new obligations arise mid-year.

multi

What does each entry in the obligations inventory record?

The obligation itselfThe instrument or contract it arises fromThe systems or processes it bindsThe person accountable for meeting itThe date the obligation was addedWhere the obligation arrives through a customer contract, that contract, the instrument behind it and the authority supervising the customerNone of the above

Options run from the most commonly recorded to the least. The date an obligation was added is what makes an obligation that arose mid-cycle visible without waiting for the next review. The last item is the one an inventory built from a jurisdictional analysis never returns, because the duty exists in a signed schedule rather than in a law that binds the organisation directly.

GOV-011Compliance Monitoring and Internal Audit
boolean

Does your organisation conduct internal audits or compliance checks of information security controls at a defined interval?

An internal audit report should state scope, list findings by severity, include a management response with owners and target dates, and be produced by someone independent of the function audited.

select

How frequently does your organisation conduct information security internal audits?

Annually or more frequentlyEvery 2 yearsOnly when required by a customer or regulatorNo formal internal audit cadence exists

Most frameworks expect at least annual internal audit activity. Findings should feed directly into the remediation tracker.

multi

Which of the following does each internal audit or compliance check report carry?

Its scopeThe work performedEach finding with a severityA named owner for each findingA management responseA closure date recorded in a findings registerNone of the above

Options run from the most commonly present to the least. A report with findings and no management response records an opinion rather than a commitment. Findings with no register behind them close by being forgotten.

GOV-012Continuous Monitoring Strategy
boolean

Does your organisation have a documented continuous monitoring strategy?

The strategy should be documented, management-approved, and reference how monitoring outputs feed into risk register updates, not rely solely on annual audits.

multi

Which of the following continuous monitoring activities are currently operational in your organisation?

Automated vulnerability scanning on a defined scheduleSIEM or log aggregation with alert reviewCloud security posture management (CSPM) toolCompliance platform with automated control checks (e.g. Vanta, Drata)Scheduled manual control spot-checks between formal auditsNone of the above

Evidence should show monitoring outputs (dashboards, scan reports, alert logs) generated at the frequencies defined in the strategy.

multi

Which of the following does the continuous monitoring strategy record?

The metrics monitored for control effectivenessThe frequency of eachThe role accountable for reviewing eachWho a deviation is escalated toA link from each deviation to a risk register entry or a remediation recordNone of the above

Options run from the most commonly recorded to the least. Monitoring that produces output nobody is named to read is the common failure. A deviation with no link onward to a risk entry leaves the strategy reporting problems it never resolves.

GOV-013Exception and Requirement Determination Register
boolean

Does your organisation have a formal process for requesting, approving, and tracking exceptions to information security policies?

The process should require a business justification, named approver, risk acceptance rationale, and a defined maximum exception duration.

select

How are active policy exceptions tracked and managed?

A formal exception register with approver, expiry date, and periodic reviewTracked in the risk register as accepted risks with no separate exception recordDocumented on an ad hoc basis with no central registerPolicy exceptions are not formally tracked

An exception register should show that no exceptions are past their expiry date without renewal or remediation, and that each carries a named approver.

multi

Which of the following does each determination against an external requirement record?

The specific requirement it answersThe assessment of why the named measure is not reasonable and appropriate in this environmentThe alternative measure implemented, or a finding that none isThe approverThe trigger that brings it back for re-assessmentNone of the above

This covers a regime that permits an alternative measure, not a requirement the organisation has failed to meet: an unmet requirement is a finding, not a determination. The assessment is the item most often thin, because restating the requirement is easier than saying what about this environment makes the named measure unreasonable. A determination that only expires on a date behaves like a policy exception and gets renewed rather than re-assessed.

GOV-014Asset Inventory
boolean

Does your organisation maintain a documented inventory of information assets and processing systems, with designated owners for each asset?

The inventory should include all production systems and critical data stores, show a named owner per asset, and have a last-reviewed date within the defined interval.

select

How does your organisation keep the asset inventory current as assets are added, modified, or decommissioned?

Automated discovery (e.g. CSPM, CMDB sync) with regular reconciliationMandatory update process triggered by change management ticketsPeriodic manual review on a defined scheduleAd hoc updates with no defined processThe inventory is not actively maintained

An automated discovery cross-reference or change-management trigger is the most reliable control. The inventory should match live cloud infrastructure within 30 days.

boolean

Does each asset in your inventory carry a criticality rating derived from the services that depend on it?

Ownership says who decides about an asset; criticality says how much is lost if it fails. Recovery prioritisation, assurance depth and incident triage all need the second and none of them can derive it from an owner name. Answer yes only where every asset carries a rating, not only the ones someone thought to rate.

GOV-015Intellectual Property Rights Management
boolean

Does your organisation maintain an inventory of the licensed software in use?

The inventory should show that usage does not exceed entitlement and that no licences are operating past expiry.

multi

Which of the following does the software licence inventory record for each licensed product?

The entitlement count heldThe number of installations or users in active useThe renewal or expiry dateThe owner accountable for the licenceThe evidence of entitlement, such as the purchase or subscription recordNone of the above

Options run from the most commonly recorded to the least. An inventory holding entitlements but no usage count cannot show that use stays within them, which is the condition the control tests.

boolean

Does a documented procedure define how licensing non-compliance is identified and remediated?

The procedure should name the prohibited actions, the route by which a violation is flagged and the remediation expected. An acknowledgement requirement on personnel belongs with it.

GOV-016Records and Information Governance
boolean

Does your organisation have a documented records retention schedule?

The schedule should cover audit logs, contracts, incident records, and training records at minimum, with specific retention periods aligned to legal and regulatory obligations.

select

How are retention policies enforced for your primary storage and logging systems?

Automated retention rules configured in storage / logging platforms (e.g. S3 lifecycle, CloudWatch Logs retention)Scheduled manual processes to archive or delete records per the scheduleRetention is managed informally with no automated or scheduled enforcementNo retention enforcement mechanism is in place

Automated retention configuration (e.g. S3 lifecycle policies, Google Vault rules) aligned to the retention schedule is the strongest evidence. Immutability should be enabled for audit logs.

multi

Which of the following does the retention schedule define for each category of compliance-relevant record?

The retention periodWhere the record is storedHow the record is protected from unauthorised access, alteration or lossThe destruction method applied at the end of the periodThe legal or regulatory obligation the period derives fromThe point the period is measured from, where an obligation measures it from something other than creationNone of the above

Options run from the most commonly defined to the least. A period with no obligation behind it cannot be defended when it is challenged. A schedule with no destruction method leaves records alive past the period it sets. The last item is the one that changes the answer most: an obligation running from the date a document last was in effect keeps a long-lived policy for years past the period its number suggests.

GOV-018Threat Intelligence Programme
boolean

Does your organisation have a defined threat intelligence programme that collects, analyses, and disseminates threat intelligence to relevant internal stakeholders?

The programme should produce documented intelligence outputs (reports or briefings) on a defined cadence, referencing at least two sources and showing distribution to security, engineering, or risk stakeholders.

select

How does your organisation act on threat intelligence findings to update risk posture or controls?

Threat intelligence findings are systematically traced to risk register updates or control change ticketsFindings are reviewed and discussed in security meetings but not formally tracked to the risk registerIntelligence is collected but dissemination and action are ad hocNo formal process for acting on threat intelligence exists

A traceable link between an intelligence finding and a risk register entry or change ticket is the expected evidence, demonstrating closed-loop action.

multi

Which external threat intelligence and special interest group relationships does your organisation actively maintain?

ISAC or sector-specific threat sharing group membershipNational CERT or CISA alert subscriptionVendor or MSSP threat intelligence feedSecurity industry association or professional forum membershipNone of the above

Active membership or subscription, not registration alone, with a named internal owner. Regulatory authority and law enforcement contacts are INC-010.

GOV-019Information Security in Project Management
boolean

Does your organisation have a documented process for integrating information security requirements throughout the project lifecycle, including mandatory security reviews before go-live?

The process should define required security activities per project phase and require that findings are resolved or risk-accepted before deployment.

multi

At which stages of a project are security activities formally required?

Security requirements defined at project initiation / designThreat modelling conducted before build beginsSecurity review or penetration test before go-liveRisk acceptance from a named approver required before deploymentPost-launch security retrospective or reviewNone of the above

Pre-launch security sign-off is the minimum. Look for completed review checklists with a named security reviewer and documented disposition of findings.

GOV-020Independent Security Review
boolean

Does your organisation undergo independent security assessments (internal audit teams independent of the security function, or external third-party assessors) at defined intervals?

The assessor must be independent of the function being assessed. Reports should be dated within the defined interval and addressed to management.

select

What form does your most recent independent security assessment take?

Third-party SOC 2 Type II auditISO 27001 certification auditExternal penetration testThird-party security risk assessmentInternal audit by a team independent of the security functionNo independent assessment has been conducted

A SOC 2 Type II report or ISO 27001 audit provides the strongest third-party assurance for enterprise customers. All options above should include a management response to findings.

GOV-021Audit and Assurance Policy
boolean

Does your organisation have a documented audit and assurance policy?

The policy should explicitly state that auditors cannot audit their own function, define the reporting line (e.g. to CISO or Audit Committee), and be approved within the last 12 months.

multi

Which of the following does the audit and assurance policy define?

The scope of the internal audit functionThe frequency of audit cyclesThe independence requirements placed on auditorsThe reporting line and reporting responsibilitiesAn annual audit plan approved before the audit year beginsCompletion status tracked against that planNone of the above

Options run from the most commonly defined to the least. Independence is the limb that decides what the audit is worth: a policy that lets a function audit itself produces a report nobody outside the organisation can rely on.

GOV-022Privacy Programme and Data Protection Policy
boolean

Does your organisation have a documented data protection policy approved by management?

The policy should cover lawful basis for processing, data subject rights, breach notification, and applicable regulations (e.g. GDPR, CCPA), and be approved within the last 12 months.

multi

Which of the following does your privacy programme maintain?

A named privacy lead accountable for the programmeRecords of processing activities covering the key data flowsData protection impact assessments for high-risk processingA privacy notice for data subjectsA documented procedure for handling data subject rights requestsA breach notification procedure with defined regulatory reporting timelinesNone of the above

Options run from the most commonly held to the least. A policy on its own is not a programme. The records of processing and the breach notification procedure are the two operational artefacts an assessor asks for first.

GOV-023Security Measures Performance Measurement
boolean

Is a security metrics report produced at a defined cadence?

Metrics should be compared against defined targets and show trend data. Reports should be addressed to or acknowledged by a named executive or security committee.

multi

Which of the following security metrics does your organisation actively track and report?

Security awareness training completion rateMean time to remediate (MTTR) for open vulnerabilities or findingsSecurity incident count and trendAudit finding closure ratePhishing simulation click rateRisk register aging (open risks past target date)None of the above

A good metrics programme covers at least training completion, vulnerability remediation SLA, and incident rates, with results compared to defined targets each reporting period.

multi

Which of the following does the security metrics report carry?

A defined target for each metricThe current value against that targetThe trend across prior reporting periodsThe executive or committee it is delivered to, namedA record of that recipient's acknowledgementNone of the above

Options run from the most commonly present to the least. A value with no target is a number. A report with no named recipient has no reader accountable for acting on it.

GOV-024Documented Operating Procedures
boolean

Are operating procedures documented for the critical information processing activities?

Each procedure should carry a version number, a named owner, and a last-reviewed date within the defined interval (typically 12 months).

multi

Which of the following critical process areas have documented operating procedures that are actively maintained?

Access provisioning and deprovisioningPatch and vulnerability managementIncident responseBackup and recoveryChange managementSecure software development lifecycle (SDLC)None of the above

Select all that apply and be prepared to provide the procedure documents with version history. Fewer than three covered areas would be considered a material gap.

multi

Which of the following apply to your documented operating procedures?

Each carries a version numberEach names an ownerEach carries a last-reviewed date within the defined intervalThey are available to the personnel who need them without having to request themThey are updated when the process changesNone of the above

Options run from the most commonly in place to the least. A procedure nobody can reach at the moment they need it is not available, whatever the document management system says about permissions.

GOV-028Regulatory Cooperation and Supervisory Access
boolean

Is a named role accountable for requests from the authorities that supervise the organisation's customers?

Answer for the authority that supervises a customer, not for the organisation's own regulator and not for a law enforcement demand, which is the vendor data request control. A role named in a procedure nobody has routed a request through is still a yes; a request handled ad hoc by whoever received it is a no.

multi

Which of the following does the procedure cover?

Verification of the authority and the mandate it acts underA committed period to respond inAccess to data relating to the customer's serviceAccess to the premises the service is provided fromA register of the requests received and answeredA recorded review that no customer agreement term or practice obstructs that accessNone of the above

Options follow the order a request moves through, from arrival to the record left behind. The last item is the one most often missing: a contract that grants access and an operating practice that makes it impossible are a common pairing, and only a review that reads both together finds it.

select

What access to premises is committed to an authority supervising a customer?

Any site the service is provided from, including sites a subcontractor operatesSites the organisation operates itselfAccess negotiated case by case when a request arrivesRemote evidence only, with no premises accessNo commitment is made

Options run from the widest commitment to the narrowest. Answer on what the published terms actually commit, not on what would probably be agreed. A commitment that stops at the organisation's own sites is the second option even where every site it operates is covered.

HRS-001Personnel Security Policy
boolean

Does your organisation have a documented personnel security policy?

The policy should span the full employment lifecycle, from background screening before hire through to offboarding obligations, and be approved and communicated to all staff.

select

How do you confirm all personnel have received and acknowledged the personnel security policy?

Digital acknowledgement tracked in HRIS or training platform with a completion reportAcknowledgement captured in signed employment agreementCommunicated but acknowledgement is not formally trackedPolicy has not been formally communicated to all staff

An acknowledgement export showing all active employees with a recorded acknowledgement date at or before their first day of system access is the expected evidence.

multi

Which of the following does the personnel security policy cover?

Pre-employment screeningTerms and conditions of employmentInformation security obligations during employmentRequirements on terminationA named owner and a defined review intervalNone of the above

Options run from the most commonly covered to the least. A policy covering hiring and nothing else leaves the two points of highest risk, role change and departure, without a stated obligation.

HRS-002Pre-Employment Background Screening
boolean

Does your organisation conduct background screening on all candidates before system access is granted, proportional to the sensitivity of the role?

Screening should be completed before access is provisioned. The scope of the check should match the role risk band the screening standard defines, covering identity, employment history and any criminal record check the band requires.

multi

Which of the following personnel categories are subject to pre-employment background screening in your organisation?

All permanent employeesContractors with access to production systemsThird-party personnel with privileged accessContractors with access to sensitive or personal data onlyNone of the above

ISO 27001 and most enterprise customer requirements expect screening for contractors and third parties with privileged access, not just direct employees.

multi

Which of the following does your screening and identity proofing record hold for each person, dated before their first system access?

The checks completed for the person's role bandThe identity evidence presented at registrationThe method used to validate and verify that evidenceAn out-of-band confirmation delivered to the person's address of recordNone of the above

Options run from the most commonly held to the least. Every element has to be dated before the individual's first system access, which is the part that most often fails under hiring pressure. Screening and proofing answer different questions: screening asks what is known about this person, proofing asks whether the person in front of you is that person.

HRS-003Employment Agreements and Security Obligations
boolean

Do your employment agreements state explicit information security obligations?

Obligations should be stated in the agreement itself, not just referenced by pointer. Signed copies should be on file and the agreement should be signed before or on the first day of employment.

select

When security obligations in employment agreements change materially, how does your organisation ensure affected personnel acknowledge the updated terms?

Formal re-acknowledgement process tracked to 100% completion in the HRIS or policy platformCommunication sent to all staff but re-acknowledgement is not formally trackedUpdated agreements are issued only to new hires; existing staff are not re-acknowledgedMaterial changes to security obligations have not occurred, and no process exists for this scenario

A change notification record and re-acknowledgement log showing all affected employees confirmed updated terms within a defined period is the expected evidence.

multi

Which of the following do your employment agreements contain?

Confidentiality requirementsAcknowledgement of the organisation's security policiesObligations stated in the agreement itself rather than referenced by pointerA signature recorded before system access is grantedNone of the above

Options run from the most commonly present to the least. An agreement that points at a policy the person has never read transfers no obligation they can be held to.

HRS-004Security Awareness Training
boolean

Do all personnel complete a security awareness training programme at onboarding and at defined intervals thereafter?

Training records from the LMS or awareness platform should show completion rates at or above the defined target (typically 95%+), with new hires completing within 30 days of their start date.

multi

Which of the following topics are included in your annual security awareness training curriculum?

Phishing and social engineering recognitionAcceptable use of organisational systems and dataIncident and suspicious activity reportingPassword and authentication hygienePrivacy obligations and data handlingRecognising and reporting potential insider threat indicatorsAI tool usage risks and acceptable useNone of the above

Options run from the most commonly covered to the least. Phishing awareness, acceptable use, incident reporting and privacy obligations are the minimum. Insider threat indicators are behavioural, not technical. The colleagues best placed to notice them are not on the security team, and the reporting route is usually not the one used for a suspicious email, so the topic has to be taught.

boolean

Does your organisation evaluate the effectiveness of its security awareness programme (e.g. through phishing simulations, quiz scores, or click rate trends)?

Phishing simulation results showing click rate trends over the year, with curriculum changes triggered by high-risk cohorts, demonstrate programme effectiveness.

HRS-005Role-Based Security Training
boolean

Do personnel in elevated-privilege or security-critical roles (e.g. sysadmins, developers, incident responders) receive role-specific security training before gaining production access and at defined intervals thereafter?

Role-based training records should show completion before or within 30 days of production access being granted, with annual renewal records on file.

multi

Which of the following role-specific security training tracks does your organisation deliver?

Secure coding / application security for developersCloud or infrastructure security for system administratorsIncident response procedures for the security teamData handling and privacy for data engineers or analystsCybersecurity for the members of the management body, against a competence standard of their ownAI system governance or responsible AI for ML or AI rolesNone of the above

At least three distinct role tracks covering different privilege tiers are expected. Training is matched to the systems and data each role can reach. The management body track is the one most often absent, because the programme is usually built around who holds production access and the board holds none.

select

How is the effect of role-based training measured?

Assessed against the role's competence standard, with the result feeding the next revision of the programmeAssessed against the role's competence standardChecked by a test at the end of the moduleCompletion recorded, with no measure of effectNeither completion nor effect is recorded

Options run from strongest to weakest. A test at the end of a module measures recall of the module, not competence in the role, which is why it sits below an assessment against the standard. Answer on what happened at the last delivery rather than on what the procedure describes.

HRS-006Disciplinary Process for Security Violations
boolean

Does your organisation have a documented disciplinary process covering information security policy violations?

The process should define tiered consequences proportionate to severity, require investigation before sanctions are applied, and include an appeal mechanism.

multi

Which of the following apply to your disciplinary process for security violations?

It is communicated to all personnelIt defines consequences proportionate to the severity of the violationIt requires an investigation before a sanction is appliedIt provides an appeal routeEach case is recorded, with the investigation and the outcomeNone of the above

Options run from the most commonly in place to the least. Answer on the process as written and operated, not on whether evidence of a past case could be produced. A process that has never been invoked can still meet every item here.

HRS-007Termination and Access Revocation
boolean

Are all logical access rights revoked within a defined timeframe on termination or role change?

Completed offboarding checklists should show access revocation dates and confirm the SLA was met (typically same-day for involuntary terminations).

select

What is your defined maximum timeframe for revoking all logical access after an involuntary termination?

Immediately / same dayWithin 4 hoursWithin 24 hoursWithin 3 business daysNo defined SLA: access is revoked when IT processes the request

Same-day revocation for involuntary terminations is the expected standard. IAM export cross-referenced against the HR termination log is the verification evidence.

multi

Which of the following does your offboarding process cover?

Contractors and third-party personnel on the same terms as employeesDisabling of every authentication credential the individual heldRetrieval of physical assets, with the return obligation written into the agreementReview of ongoing confidentiality obligationsRe-owning or disabling service accounts the individual heldAccounts and sessions disabled within a defined period where an insider risk indicator against the individual is confirmedNone of the above

Options run from the most commonly covered to the least. Contractor access is the gap that outlives the engagement, because the trigger for offboarding sits with the engaging team rather than with human resources. The last item runs on its own trigger and does not wait for a termination.

HRS-008Remote Working Security
boolean

Does your organisation have documented security requirements for remote working?

The policy should specify MDM enrolment or equivalent device controls, VPN or zero-trust network access requirements, and a process for reporting lost or stolen devices.

select

How are remote working security requirements communicated to and acknowledged by remote workers?

Dedicated remote working agreement signed or digitally acknowledged before remote access is enabledCovered within the general acceptable use policy acknowledgementCovered in security awareness training but not separately acknowledgedRequirements are communicated informally with no formal acknowledgement

All employees with a remote or hybrid arrangement should have a current acknowledgement on file, pre-dating or concurrent with the start of their remote working arrangement.

multi

Which of the following do the remote working requirements cover?

Device security controls, such as enrolment in device managementNetwork access requirementsHandling of organisational information outside the officeReporting of a lost or stolen deviceReporting of security incidentsNone of the above

Options run from the most commonly covered to the least. The lost device route is the one people need at the worst moment and the one most often missing from a policy written around network access.

HRS-009Security Event Reporting Channel
boolean

Do all personnel have access to a documented mechanism for reporting observed or suspected security events?

At least two reporting channels should be defined (e.g. email alias, Slack channel, ticketing form) and included in security awareness training. A non-retaliation statement should be present.

select

How frequently are the security event reporting channels tested to confirm they are operational?

At least annually with a documented test recordTested only when a real report is receivedAd hoc / not on a defined scheduleChannels have not been formally tested

Channel testing (e.g. a test submission verified to have been received and acknowledged) should produce a dated test record. Reports received via the channel should be acknowledged within a defined SLA.

multi

Which of the following apply to your security event reporting channels?

At least two channels are defined and publishedPersonnel are trained on when and how to use themReports are acknowledged within a defined periodReports are tracked to a recorded outcomeThe mechanism is reachable by suppliers and customers and is communicated to themThe channel accepts a good-faith report that the organisation has broken the law or poses a risk to public safety, including one taken to a competent authorityA published protection statement names the detrimental actions the organisation will not take against a good-faith reporterNone of the above

Options run from the most commonly in place to the least. An unacknowledged report teaches the reporter not to send the next one, which is the failure mode the control exists to prevent. The external item asks about a suspicious event rather than a vulnerability report, which is a narrower channel held elsewhere. The last two items are the whistleblower case: a report about the organisation itself rather than about a security event, plus the protection that lets a person make it.

HRS-010Personnel Roles and Security Responsibilities
boolean

Are information security responsibilities defined for every position?

Job descriptions or role definition documents should include a security responsibilities section covering systems in scope, data access entitlements, and asset accountability for elevated-access roles.

multi

Which of the following does your role definition process do?

Records the data each position may accessRecords the security obligations that attach to the roleRecords who is accountable for the information assets the role touchesUpdates the definition when the role changesInforms the affected person of the updated obligationsNone of the above

Options run from the most commonly in place to the least. A role definition written once at hiring and never revisited describes the job somebody used to do. The last item is what turns the definition into an obligation the person knows they hold.

HRS-011Acceptable Use of Information Assets
boolean

Are the acceptable use rules acknowledged by each person before access to organisational systems is granted?

The acknowledgement before access is what makes the rules enforceable later. Rules published on an intranet with no record of who has read them do not meet the control; Q2 captures how the acknowledgement is recorded.

select

How is acknowledgement of the acceptable use policy captured and tracked for all personnel?

Digital acknowledgement recorded in HRIS or training platform with completion reportWet or e-signature on employment contract or onboarding documentationVerbal acknowledgement during onboarding with no formal recordAcknowledgement is not formally captured

A digital acknowledgement export showing 100% (or near-100%) completion for all active staff, with acknowledgement dates, is the standard evidence.

multi

Which of the following does your acceptable use policy address?

Prohibited activitiesLimits on personal useObligations to protect organisational informationUse of social media, external sites and applicationsPosting organisational information on public sitesUse of organisational email addresses or authentication secrets to open accounts elsewhereClear desk and clear screen rulesConditions for processing organisational information on a system the organisation does not controlNone of the above

The last five items are the ones most often missing from a policy written for a single office and a managed laptop. The external systems item is the one that governs contractor and bring-your-own-device working; the control also asks for a recorded verification of that system's controls or an approved connection or processing agreement for each such use.

HRS-012Insider Threat Programme
boolean

Does your organisation have a documented insider threat programme with a named owner?

The procedure is the artefact and the owner is the part most often missing. A collection of detection tooling with no procedure, no escalation path and nobody accountable for the programme does not meet the control; Q2 captures which capabilities are in place.

multi

Which of the following insider threat capabilities are in place?

Behavioural analytics or data loss alertingPrivileged access monitoring for high-risk accountsA documented escalation path from security to human resources and legalA confidential reporting channel available to personnelA cross-functional review recorded at defined intervalsA documented investigation procedure covering the handling of evidenceNone of the above

A detection capability without the escalation path and the investigation procedure produces alerts nobody can act on. The last item is what decides whether the evidence gathered survives a disciplinary or legal process.

HRS-013AI Literacy and Role-Based AI Training
boolean

Is there a training standard that names the groups of people who operate, build, procure or decide with AI systems?

Answer yes only where the standard distinguishes groups and sets different content for them. A single all-staff AI module, or an AI slide inside general security awareness training, is a no here.

multi

Which of the following does your AI training cover?

What the AI systems in use can and cannot doThe ways their outputs go wrongThe rules for acceptable use of AI systemsHow to report a problem with an AI systemFor oversight persons, the specific system's performance characteristics and limitsFor oversight persons, the effect of automation bias on their own judgementThe technical standards relevant to the roleNone of the above

The first four items apply to every group; the next two apply only to people assigned oversight of a specific system. Tick an item only where it is in the delivered content, not only in the standard.

select

Who does the AI training reach?

Employees and contractors operating AI on your behalf, on the same terms, with completion recorded for bothEmployees and contractors, with completion recorded for employees onlyEmployees only, with completion recordedEmployees only, with no completion recordNo AI training is delivered

Options run from the widest reach with the strongest record to the narrowest. Contractors here means anyone operating or using AI systems on your behalf, including agency staff and outsourced operations teams.

IAM-001Access Control Policy
boolean

Does your organisation have a documented access control policy that defines rules for granting, reviewing, and revoking access?

The policy should be version-controlled, have a named owner, and include explicit least-privilege and need-to-know requirements. An undocumented or informal approach does not satisfy this control.

select

How frequently is the access control policy reviewed and re-approved?

Every 6 months or more frequentlyAnnuallyEvery 2 yearsNo defined review cadence / ad hoc

Annual review is the minimum acceptable cadence. The policy must be re-approved by a named owner after each review.

IAM-002Identity Inventory and Unique Identifiers
boolean

Is a centralised inventory of all identities, including human users, service accounts, and other non-human identities, maintained?

The inventory should be sourced from the IdP or IAM platform (e.g. Okta, Azure AD, AWS IAM), not maintained only in a spreadsheet. It must include both human and non-human identities.

select

Are shared or generic accounts in use in any of your production systems?

No: shared or generic accounts are prohibited with no active exceptionsYes, but each has a documented business justification and named ownerYes, without documented justificationUnknown

Shared accounts undermine audit trail integrity. Any active shared accounts must have a documented justification and a named individual accountable for activity on that account.

boolean

Where a shared account is permitted, does each user authenticate as themselves before being given access to it?

Answer yes only where the individual authentication is enforced by a broker, a privileged access tool or a jump host rather than being a convention. Without it, the justification records why the shared account exists and the log still cannot say who used it. Answer yes as well if no shared accounts are permitted at all.

IAM-003User Account Lifecycle Management
boolean

Are formal, documented processes in place for provisioning and deprovisioning user accounts, including required approvals before access is granted?

Provisioning should require at minimum one named approver distinct from the requester. Approvals must be recorded in a ticketing or workflow system.

select

When an employee leaves or changes role, within what timeframe are their accounts disabled or access updated?

Same day as the HR effective dateWithin 24 hoursWithin 3 business daysWithin 1 weekNo defined SLA / ad hoc

Same-day or next-business-day deprovisioning is best practice. Delays beyond 3 days create significant orphaned-access risk. The timeframe should be defined in policy and verifiable from logs.

multi

Which of the following are managed through your central identity provider?

Workforce user accountsAdministrative and privileged accountsService and other non-person identitiesDevices that authenticate to productionDocumented exceptions, each with a named owner and a review dateAccount usage conditions such as permitted hours or permitted source networksNone of the above

Options run from the most commonly covered to the least. An identity that lives outside the identity provider without being a recorded exception is invisible to joiner and leaver processing. Usage conditions set only in an access request cannot deny a login, which is why the question asks where they are set rather than whether they are agreed.

IAM-004Access Review and Recertification
boolean

Are access rights for all users formally reviewed and revalidated on a defined periodic schedule?

Reviews must be documented, include a named reviewer per access entry, and result in revocation of any access no longer required. Ad hoc or informal reviews do not satisfy this control.

select

How frequently are access reviews (recertification campaigns) conducted?

Quarterly or more frequentlyEvery 6 monthsAnnuallyLess than annually / no defined schedule

Annual is the minimum; more frequent reviews are expected for privileged accounts and sensitive systems. Reviews should be triggered in addition to scheduled cycles when users change roles.

IAM-005Least Privilege and Need-to-Know Enforcement
boolean

Is the principle of least privilege enforced so that users and services are granted only the minimum access needed for their current function?

Enforcement requires that roles are scoped tightly and that access is actively reviewed when responsibilities change, not merely that a policy document states the principle.

multi

How is least-privilege enforcement implemented in your environment?

Roles are defined with minimum required permissions and reviewed periodicallyPrivileged role requests require documented business justificationAccess rights are automatically revoked when an employee changes roleSensitive data access requires explicit approvalIAM policy analysis tooling (e.g. AWS IAM Access Analyzer, Prisma Cloud) is used to detect overly broad permissionsNone of the above

Multiple mechanisms in combination indicate a mature least-privilege posture. Relying solely on a written policy without technical enforcement is insufficient.

IAM-007Privileged Access Management
boolean

Is an inventory of all privileged accounts maintained?

Every privileged account must map to a named individual with a documented business justification. Shared admin accounts are not acceptable.

multi

Which controls are applied specifically to privileged accounts in your environment?

MFA enforced on all privileged accountsJust-in-time (JIT) or time-limited privileged accessPrivileged actions are fully logged and auditablePrivileged roles are segregated from standard user rolesAdministration operations run on accounts used for that purpose only, separate from the holder's standard accountPrivileged sessions are recorded and privileged activity is reviewed for behaviourUtility programs able to override application or system controls are inventoried and restricted to named rolesCustomer approval is required before a high-risk privileged role reaches that customer's tenant dataPrivileged access reviewed more frequently than standard accessNone of the above

Options run from the most commonly held to the least. MFA and full action logging are the minimum. A separate account for administration is a different thing from segregating the roles: one person can hold both roles on one account and satisfy segregation on paper. Session recording with a behavioural review answers what the action log cannot, which is whether a legitimate action was part of a pattern that was not. Utility and break-glass tooling is the gap most often missed: a tool that bypasses application logic leaves an application audit trail that looks normal. Product names belong in an implementation note, not here.

IAM-008Multi-Factor Authentication
boolean

Is MFA enforced for all user access to externally-facing systems, administrative interfaces, and systems holding sensitive or regulated data?

MFA must be enforced at the system or IdP level, not left to user discretion. Enforcement means no in-scope access path can be completed with a password alone.

multi

Which of the following are true of the multi-factor authentication enforced on in-scope systems?

The enforced mechanism combines at least two distinct factors drawn from knowledge, possession and inherenceOne factor is provided by a device separate from the system being accessedNo in-scope access path can be completed with a single factorEnrolment is enforced rather than left to the user to opt intoNone of the above

The control constrains the properties of the mechanism, not the product. Phishing-resistant methods such as a hardware security key are stronger than a one-time code sent over a message channel. That choice belongs in the implementation note rather than here. The third item is the one that fails in practice: a legacy client or a recovery route that still accepts a password alone.

multi

Which conditions trigger a supplemental authentication challenge on your systems?

First use of a deviceSign-in from an unrecognised location or networkChange to authentication or account recovery settingsElevation to a privileged roleA sensitive operation such as a bulk data export or a payment detail changeNone of the above

Options run from the most commonly configured to the least. The conditions should be written down rather than left to a vendor default, because the default set is what an attacker can look up. Elevation and sensitive-operation triggers are the two most often absent.

IAM-009Authentication Information Management
boolean

Is a documented credential management policy enforced at system level?

The policy must be enforced at the system level, not just documented. Key settings to confirm: minimum length ≥12 characters, reuse prohibition, and approved hashing/storage for secrets.

select

How are API keys, tokens, and service credentials stored?

Centralised secrets management vault (e.g. HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, Azure Key Vault)Environment variables injected at runtime via a secrets platformEncrypted configuration files committed to version controlPlaintext in configuration files or environment variable files (.env) committed to version controlNo defined approach / ad hoc

A dedicated secrets vault with access control and audit logging is the expected approach. Credentials committed to version control, even encrypted, represent a significant risk. Plaintext storage in version control is a critical finding.

boolean

Is there a maintained list of the external authenticators your service accepts, with the assurance level each is accepted at?

External authenticators are the sign-ins your organisation does not issue: a customer or partner identity provider, a social login, a federated enterprise directory. Answer yes only where the list exists, each entry states an assurance level, and an authenticator outside the list is actually refused by the service rather than merely undocumented.

IAM-010Service Account and Non-Human Identity Management
boolean

Are service accounts, API keys and other non-human identities recorded in an inventory?

Every non-human identity should have a named team or individual as owner. Unowned or undocumented service accounts are a significant risk. The inventory must be kept current, not just created once.

select

How frequently are API keys and service account credentials rotated?

Automatically rotated on a schedule (e.g. every 30–90 days)Rotated manually on a defined schedule (at least annually)Rotated only upon suspected compromiseNo defined rotation schedule

Automated rotation is strongly preferred. Long-lived, non-rotating credentials significantly increase the impact of a credential exposure. Rotation should also occur immediately upon any suspected compromise.

multi

What does each non-human identity entry record?

A named ownerThe defined scope of its accessA rotation or expiry policyThe date it was last usedConfirmation that it is not shared across services or environmentsNone of the above

Options run from the most commonly recorded to the least. An unowned service account is the one nobody revokes. A shared one turns every compromise into a compromise of every service that uses it.

IAM-011Remote Access Controls
boolean

Is remote access to internal systems and infrastructure limited to approved, documented access paths (e.g. VPN or zero-trust network access)?

Direct SSH, RDP, or API access from the internet to internal resources without a sanctioned gateway should be blocked. All remote access paths must be reviewed and reauthorised periodically.

select

What remote access technology is in use for accessing internal systems?

Identity-aware access proxy that authorises each connection against the user, the device and the resourceEncrypted tunnel requiring multi-factor authenticationBastion or jump host requiring multi-factor authentication at the gatewayEncrypted tunnel or bastion with single-factor authenticationInternal systems reachable directly from the public internetNo defined remote access path

Options run from the strongest path to the weakest. An identity-aware proxy decides each connection on its own terms, so one stolen credential does not open the internal network the way a tunnel credential does; Cloudflare Access, Zscaler Private Access and BeyondCorp are examples of the category. A tunnel with multi-factor authentication is the floor this control expects. An internal system reachable directly from the public internet is a critical finding. Record the capability in use rather than the product name.

IAM-012Session Management
boolean

Are session management controls enforced at system level?

Controls must be enforced at the system level, not left to the end user to configure. Session identifiers must not appear in URLs and must be invalidated upon logout.

select

What is the maximum idle session timeout configured for users accessing production systems?

15 minutes or less16–30 minutes31–60 minutesMore than 60 minutesNo idle timeout configured

Options run from strongest to weakest. Fifteen to thirty minutes is the expected range for production and administrative systems. A timeout above 60 minutes, or none at all, is a finding wherever the session reaches sensitive data.

multi

Which session management controls are enforced on production systems?

An idle timeout after a defined periodAn absolute session lifetime limitSession identifiers invalidated on logoutSession identifiers kept out of URLsRe-authentication required after a sensitive operationConcurrent session limits where the system warrants themNone of the above

Options run from the most commonly enforced to the least. An idle timeout with no absolute lifetime behind it leaves a session that is kept alive by activity running indefinitely.

IAM-013Logon Failure and Account Lockout
boolean

Are authentication systems configured to lock out or rate-limit accounts after a defined number of consecutive failed login attempts?

The mechanism must be enforced at the system level. The lockout threshold, duration, and recovery process should be defined in policy and verifiable in system configuration.

multi

What mechanism is used to respond to repeated failed authentication attempts?

Account lockout after a defined number of failuresProgressive delay (exponential back-off)CAPTCHA challenge after failed attemptsIP-based rate limiting or blockingAlerting to the security team on high failure ratesNone of the above

At least one technical mechanism should be in place at the system or gateway level. Layering multiple mechanisms (e.g. lockout plus IP rate-limiting plus alerting) provides stronger defence against credential stuffing.

IAM-014Access to Source Code and Development Assets
boolean

Is access to source code repositories, build pipelines and deployment tooling restricted to authorised personnel?

Access to production branches should be restricted with branch protection rules. Write or admin access must require explicit approval and be regularly reviewed.

multi

Which controls are enforced on your production or main branch in source control?

Direct push to the production/main branch is disabledAt least one required reviewer is enforced on all pull requestsRequired status checks (e.g. CI, SAST) must pass before mergeBranch protection settings are locked to prevent override by repository adminsAccess to the repository is reviewed and revalidated periodicallyNone of the above

Disabling direct push and requiring at least one reviewer are baseline expectations. Locking branch protection to prevent admin override is a strong additional control.

IAM-015Role-Based Access Control
boolean

Is access to systems and data assigned through defined roles rather than granted directly to individual users?

Role-based assignment must be the default. Direct individual-level grants should be exceptions with documented justification, not the norm.

multi

Which of the following describe your role-based access model?

A role catalogue lists every role with the permissions it carriesEach role has a named ownerRole definitions are reviewed at defined intervalsAccess granted outside the role model is recorded as an exception with a justification and an expiry dateNone of the above

Direct grants to individual accounts are exceptions, not the norm; each one needs a recorded justification and expiry date. The role catalogue export is the evidence.

IAM-016Dedicated Administration Systems
boolean

Are the systems from which administrative access to production is exercised recorded in an inventory?

Answer against the machines, not the accounts. A list of privileged users is the privileged access control. A convention that administrators use a particular laptop, with nothing recording which laptops those are, is a no.

multi

Which of the following apply to a designated administration system?

It appears in an inventory with an owner and a stated scope of administrationIt runs no application software or general-purpose workload outside that scopeIt is logically separated from the systems used for other workAccess to it is authenticated and the session encryptedAdministration accounts are used only to reach systems in the designated setThe systems used to administer the security tooling are inside the designated setNone of the above

Options run from the cheapest to hold to the most demanding. The scope is what makes single-purpose testable: without it, nothing says which software counts as outside the purpose. The last item is the one most often overlooked, because a security administration console tends to be treated as a security tool rather than as an administration system.

select

How is administrative access attempted from a system outside the designated set handled?

Blocked at the enforcement point and recordedDetected and recorded after the factNeither blocked nor detectedNo designated set exists

Options run from strongest to weakest. Answer on what the enforcement point actually did the last time it happened, or on the result of a test if it has not happened. A policy that forbids it with nothing enforcing or watching is the third option.

INC-001Incident Response Plan
boolean

Does your organisation have a documented incident response plan?

The IRP should be approved by the CISO or equivalent senior owner, version-controlled, and updated following significant incidents. A plan that has not been reviewed in over 12 months is considered stale.

multi

Which functions are explicitly covered in your Incident Response Plan?

Technical incident response (identification, containment, eradication, recovery)Legal counsel escalation pathPR and external communicationsRegulatory notification process (including GDPR timelines)Customer notification processExecutive and board-level escalationNone of the above

All six are expected in a mature IRP. Missing legal or regulatory escalation paths are a common gap that creates exposure during actual incidents.

multi

Which of the following does your incident tooling do?

Records each handling step against the incident as a caseGenerates and routes the notifications the plan requiresMakes the plan, runbooks and contact list available to responders during an incidentRuns independently of the production systems a responder may have to isolateNone of the above

Options run from the most commonly in place to the least. Independence from the estate under investigation decides whether the tooling is available in the incident it was bought for, and it is the item most often taken for granted.

INC-002Incident Detection and Triage
boolean

Are processes and technical controls in place to detect potential security incidents?

Detection capability should not rely solely on automated alerting. Internal reporting channels and mechanisms to receive third-party notifications are also required.

multi

Which incident detection sources are covered by your triage process?

Automated SIEM or monitoring platform alertsEDR or endpoint security tool alertsInternal employee or team reports (e.g. phishing reports, suspicious behaviour observations)Third-party security researcher or bug bounty notificationsThreat intelligence feedsCloud provider security notifications (e.g. AWS GuardDuty, GCP Security Command Center)Customer-reported incidentsNone of the above

Automated alerts alone are insufficient. A robust detection process includes internal reporting channels and the ability to receive and triage external notifications.

INC-003Incident Classification and Escalation
boolean

Are incidents classified by severity and type using a defined taxonomy?

The classification matrix should explicitly include criteria for identifying a personal data breach (triggering GDPR notification obligations) and should be referenced in all incident triage processes.

select

How many severity levels are defined in your incident classification taxonomy?

4 or more levels (e.g. P1 Critical / P2 High / P3 Medium / P4 Low) with distinct criteria and SLAs for each3 levels (e.g. High / Medium / Low) with distinct criteria and SLAs2 levels (e.g. Major / Minor)No defined severity taxonomy: incidents are assessed on a case-by-case basis

Options run from the most granular taxonomy to the least. The control sets no number of levels. It requires each level to carry distinct criteria with a defined escalation path, a notification requirement and a response service level. The criteria for a personal data breach have to be among them.

multi

Which of the following does the incident classification taxonomy carry?

The external notification thresholds and criteria that bind the service, each as a measurable quantity or an observable conditionThe population each proportional threshold is measured against and the system of record it is read fromA record per classified incident of which external thresholds were tested and which were crossedA band for an attempted event that changed nothingA test at a defined interval of closed sub-threshold incidents grouped by apparent root causeClassification of such a group as one incident where it crosses a threshold collectivelyNone of the above

Internal severity levels are not external thresholds: answer on the regulatory and contractual triggers, not on the priority scale. The population item is the one that decides whether the rest is usable, because a threshold set as a percentage of users is unanswerable until the denominator is defined and can be produced. The last two items look backwards across closed incidents and are the part most programmes have never built.

INC-004Incident Containment and Eradication
boolean

Do documented containment procedures exist for common incident types?

Containment procedures should be specific and actionable, not generic guidance. At minimum, runbooks should exist for account compromise, malware, and data exfiltration incident types.

multi

Which incident types have documented containment and eradication runbooks?

Account compromise or credential theftRansomware or destructive malwareData exfiltration or unauthorised data accessInformation spillage, where data reaches a system or a person outside its authorised boundaryDenial of service or availability attackInsider threatThird-party or supply chain compromiseAI system misuse or manipulation such as prompt injection or model evasionNone of the above

Options run from the most commonly documented to the least. Account compromise, malware and exfiltration are the minimum. Spillage is handled badly by a generic exfiltration playbook: the data is inside the organisation and in the wrong place, the recipients are colleagues rather than attackers, and alerting through the contaminated channel copies the spill to everyone reading it. AI-specific runbooks are expected where AI systems run in production.

INC-005Incident Reporting and Regulatory Notification
boolean

Are internal incident reporting requirements and timelines defined for every severity level?

The breach notification procedure must explicitly state the 72-hour GDPR Art.33 obligation and include GDPR Art.33(3) content requirements as a checklist. The procedure should be approved by the DPO or legal team.

multi

Which elements are included in your breach notification procedure?

Defined internal reporting timelines by severity levelExplicit reference to the 72-hour supervisory authority notification obligationA content checklist covering nature, affected data subjects, likely consequences and remedial measuresData subject notification trigger criteria for high-risk breachesCurrent contact details for the relevant supervisory authorityA named data protection or legal function responsible for notification decisionsNotification to the provider of a supplied product, component or service involved in the incidentA register of every statutory reporting obligation an incident can trigger, with the trigger, the recipient, the clock and the required content of eachThe time of awareness recorded per incident, with each submission recorded against its deadlineNone of the above

Options run from the most commonly present to the least. A missing content checklist and an undefined trigger for notifying individuals are the usual gaps. Supply chain notification is the direction most often missed: organisations notify upwards to regulators and outwards to customers while the supplier whose component was involved hears nothing. The last two items are what make the procedure survive a second regime: one named clock inside an incident response plan is not a register, and a deadline cannot be tested against an awareness time nobody wrote down.

multi

What does your internal breach register capture for each personal data incident?

Date of incident and date of discoveryData categories and estimated number of data subjects affectedRisk assessment outcome and notification decisionDate of supervisory authority notification (where applicable)Date of data subject notification (where applicable)Remediation actions taken and their completion statusNone of the above

A complete breach register is required for GDPR accountability. All incidents should be logged regardless of notification threshold. The register must capture the notification decision with documented justification.

INC-006Customer Incident and Cyber Threat Notification
boolean

Does your organisation have a documented process for notifying affected customers of security incidents?

Customer notification timelines are often defined in enterprise contracts at shorter intervals than regulatory requirements. The procedure should reference contractual obligations and include approved communication templates.

select

What is the standard customer notification timeline for a confirmed high-severity security incident affecting customer data?

Within 24 hours of confirmationWithin 48 hours of confirmationWithin 72 hours of confirmationWithin 5 business daysAs required by individual contract, no standard timelineNo defined customer notification timeline

Many enterprise contracts specify 24–72 hour notification timelines. A defined standard timeline shorter than or equal to the contractual obligation is the expected answer.

multi

Which of the following does the customer communication process cover?

The notification triggers owed to each customer commitment or regulationThe period owed for each trigger, measured from the organisation becoming awareTriggers wider than an effect on the customer's data or service, such as an attempt that changed nothingAn advisory on a cyber threat before any incident has occurredThe measures or remedies the recipient can take, stated in the advisoryThe assistance available to a customer during that customer's own responseThe basis on which that assistance is charged, fixed before an incidentNone of the above

Options follow the process from the trigger to the help offered afterwards. Tick an item only where the process states it; a practice followed by the incident team but written down nowhere does not count here. The last two are the ones a customer in a regulated sector asks about first, because its own regulator gives it a clock it cannot meet without facts the provider holds.

INC-007Evidence Collection and Preservation
boolean

Are there documented procedures for identifying, collecting and preserving digital evidence from security incidents?

Evidence collection procedures should specify approved tools, chain of custody requirements, storage location, access controls, and retention period aligned to legal and regulatory requirements.

multi

Which elements are included in your evidence collection and preservation procedure?

Defined chain of custody process with a named custodian roleApproved collection tools and methods specifiedSecure evidence storage with restricted access and access loggingDefined evidence retention period aligned to regulatory requirementsCoverage of cloud-based evidence (e.g. log exports, API call records, cloud resource snapshots)Coverage of endpoint evidence (e.g. memory capture, disk imaging)None of the above

Chain of custody and secure storage are the minimum requirements. Cloud-based evidence collection procedures are essential where the service runs on cloud infrastructure.

INC-008Post-Incident Review
boolean

Is a post-incident review conducted after every significant incident?

Post-incident reviews should be conducted within a defined timeframe after the incident is closed (e.g. within 5 business days for high-severity incidents). Corrective actions must be assigned to named owners with due dates.

select

What is the defined timeframe for completing a post-incident review following a high-severity security incident?

Within 2 business days of incident closureWithin 5 business days of incident closureWithin 10 business days of incident closureWithin 30 days of incident closureNo defined timeframe for post-incident reviews

5 business days is a widely accepted target for high-severity incidents. Reviews conducted more than 30 days after closure risk losing context and reducing the quality of root cause analysis.

multi

Which of the following does the post-incident review process produce?

A documented root causeAn assessment of how the response performedRecommendations with named owners and due datesCorrective actions tracked to completionAn update to the incident response plan or the affected control where the review found a gapA check at planned intervals that incidents meeting the trigger actually produced reviewsNone of the above

Options run from the most commonly produced to the least. A review that names a cause and changes nothing is a record of the incident rather than a control, which is what the fifth item separates. The last item is not produced by any one review: it reads the incident register against the review set and is what catches the process lapsing under load.

INC-009Incident Response Training and Testing
boolean

Do personnel with incident response roles receive training at onboarding and at a defined interval thereafter?

Training completion should be tracked in an LMS or equivalent system. Exercise results should be used to update IRP procedures. A plan that generates no updates after an exercise likely was not tested meaningfully.

select

How frequently is incident response training conducted for personnel with defined IR roles?

At onboarding and annually thereafterAt onboarding and every 6 months thereafterAt onboarding onlyAnnually but not tied to onboardingNo structured IR training programme

At onboarding plus annual refresher training is the minimum expectation. Six-monthly training is considered a strong practice for teams with active response responsibilities.

multi

Which of the following apply to your incident response exercises and training?

Exercises are scheduled with the owners of the continuity and disaster recovery plansThe exercise record names the plans represented and the handover points testedTraining material is drawn from the current plan and its runbooksPersonnel who may handle spilled information are trained on the spillage procedureThe plan is exercised at least annually through a tabletop exercise or a simulationNone of the above

Options run from the most commonly in place to the least. Coordinating the exercise tests the seam rather than the plan: a real incident invokes several plans at once and the handover between them is where they come apart. Spillage training reaches a wider group than the response team, because the people who first see spilled information are usually the ones who received it.

INC-010External Contact and Communication Points
boolean

Is a contact list maintained for the external parties the incident response team may need to reach?

The contact list must be accessible without requiring access to primary production systems: it should be stored out-of-band (e.g. printed copy, offline document, or separate communications platform).

multi

Which external contact categories are included in your maintained IR contact list?

Relevant data protection supervisory authority (e.g. ICO, CNIL)National or sector CERT (e.g. CERT-EU, NCSC)Primary cloud provider security contactExternal legal counsel with cyber incident experienceLaw enforcement contact (e.g. national cybercrime unit)Cyber insurance provider incident response hotlineExternal incident response retainer (e.g. DFIR firm)The list is verified within the last 12 monthsThe list is reachable without access to primary production systemsNone of the above

Supervisory authority, national CERT, cloud provider security contact, and legal counsel are the minimum required categories. Insurance and DFIR retainer contacts are expected for mature IR programmes.

INF-002Configuration Baseline and Hardening
boolean

Are all production systems deployed against a documented hardening baseline?

The baseline should reference a named benchmark (e.g. CIS Level 1/2, DISA STIG) and apply to all production workload types, not just servers.

select

Which approach is used to enforce the hardening baseline and detect deviations?

Policy-as-code or IaC enforced at build time with CSPM drift detection in productionCSPM tool only (e.g. AWS Config Rules, Wiz, Orca) with alerting on deviationsPeriodic compliance scan (e.g. CIS-CAT, Lynis, InSpec) reviewed on a defined scheduleManual review without automated tooling

Automated enforcement at build time combined with runtime drift detection provides the strongest assurance. Periodic scans are a minimum acceptable approach.

boolean

Are previous versions of each hardening baseline retained so a system can be returned to an earlier known-good configuration?

Answer yes only where a defined number of complete prior versions is kept and retention is enforced by the repository rather than left to convention. Drift detection tells you the estate no longer matches the baseline; without the prior version there is nothing to return it to.

INF-003System Component Inventory
boolean

Is an accurate, maintained inventory of all production system components kept, capturing component type, owner, environment, and version?

The inventory should cover servers, containers, virtual machines, cloud resources, and network devices. Cloud-native discovery tools or a CMDB are the expected mechanisms.

select

How frequently is the production asset inventory reconciled against actual deployed resources?

Continuously: automated discovery feeds the inventory in real timeWeekly or more frequently via scheduled scan or pipeline outputMonthlyQuarterlyLess frequently than quarterly or on an ad hoc basis

Continuous or weekly automated reconciliation is preferred. Quarterly is the minimum acceptable frequency for a controlled environment.

multi

What happens when a component is found in the environment that is not in the inventory?

Its network access is disabled automaticallyIt is isolated automaticallyThe named owner is notified automaticallyA ticket is raised and tracked to closureIt is picked up only by the periodic reconciliationNone of the above

Options run from the strongest response to the weakest. A detection with nothing bound to it produces a monthly list that nobody is accountable for closing. Automatic isolation suits environments where an unknown component is never legitimate.

INF-004Network Segmentation
boolean

Are production systems isolated from development, test and administrative networks at the network layer?

Isolation should be enforced via VPC boundaries, security groups, network ACLs, or equivalent cloud-native controls, not only by naming convention or access policy.

multi

Which mechanisms are used to enforce network segmentation between environments and between tenants?

Separate VPCs or virtual networks per environmentSecurity groups or network ACLs restricting inter-environment trafficSeparate cloud accounts or projects per environmentService mesh with mutual TLS for inter-service isolationNamespace-level isolation in KubernetesTenant-specific VPC or account per customerNone of the above

Multiple enforcement layers are expected for a strong segmentation posture. At minimum, expect separate network boundaries and explicit deny rules for cross-environment traffic.

INF-005Secure Network Architecture and Defence
boolean

Is your production network architecture documented?

Documentation should include current data flow diagrams and a network diagram showing trust zones. Defence controls should include at minimum a firewall or WAF and egress filtering.

multi

Which network defence controls are deployed at production network boundaries?

Web Application Firewall (WAF)Cloud-native firewall or security group policyIntrusion Detection System (IDS)Intrusion Prevention System (IPS)DDoS protection service (e.g. AWS Shield, Cloudflare)Egress filtering / DNS-based outbound filteringNone of the above

A WAF and egress filtering are baseline expectations at an internet-facing boundary. IDS/IPS and DDoS protection indicate a more mature defence-in-depth posture.

boolean

Is outbound web access from production systems and corporate devices filtered to restrict access to malicious or unauthorised external destinations?

Web filtering should block known malicious categories and command-and-control infrastructure. Egress filtering policies should be documented and applied to both production and corporate traffic.

INF-007Vulnerability Management
boolean

Is authenticated vulnerability scanning of production systems and applications performed at a defined frequency of at least monthly?

The programme should cover both infrastructure and application layers. Scan credentials should be verified. Unauthenticated scans miss a significant portion of findings.

select

What is the defined SLA for remediating critical severity vulnerabilities (CVSS 9.0 and above) in production systems?

Within 24 hours (emergency patching window)Within 7 daysWithin 14 daysWithin 30 daysNo defined SLA for critical vulnerabilities

Industry expectation for critical vulnerabilities is 7–14 days. 30 days is the acceptable outer limit only when compensating controls are documented for the gap period.

multi

Which of the following does your vulnerability management programme cover?

Authenticated scanning of every production system and applicationContainer and image scanning in the build pipelineModel artefacts scanned for unsafe calls before they are loadedInformation about the service discoverable from outside, including exposed hosts, leaked credentials and published codeFindings fed back into the component inventory where they resolve to an unknown assetFindings prioritised with an industry-standard scoring method and tracked to a remediation deadlineNone of the above

Options run from the most commonly covered to the least. Scanning covers the systems you know about; external discovery covers the ones you do not, which is where a forgotten subdomain, a stale cloud account or a credential in a public repository sits. A model artefact is scanned by neither unless it is named: a serialised model is an executable file that most tooling reads as data.

INF-008Patch Management
boolean

Are security patches applied to production systems within defined timelines based on severity?

A formal patch management policy should define timelines per severity band (critical, high, medium, low) and include an emergency patching process for zero-day or actively exploited vulnerabilities.

select

What is the defined patching SLA for high severity patches (CVSS 7.0–8.9) in production systems?

Within 7 daysWithin 14 daysWithin 30 daysWithin 60 daysNo defined SLA for high severity patches

30 days is the widely accepted baseline for high severity patches. 14 days is considered strong practice. Anything beyond 30 days requires documented compensating controls.

multi

Which of the following does your patch management process do?

Defines a timeline for each severity bandDefines an emergency window for an actively exploited vulnerabilityTracks patch status and reports it to a named ownerDocuments compensating controls for a system that cannot be patched within the timelineRecords an expiry or review date against each such compensating controlNone of the above

Options run from the most commonly in place to the least. A compensating control with no expiry becomes the permanent answer to a patch nobody applied.

INF-009Malware and Endpoint Protection
boolean

Are managed endpoints and production workloads protected by anti-malware or endpoint detection and response tooling?

EDR deployment should cover all managed endpoints and, where applicable, production compute workloads. Behavioural detection (EDR) is preferred over signature-only anti-malware.

multi

Which endpoint and workload protection tooling is deployed across production systems and managed endpoints?

Endpoint detection and response agents on managed endpoints and production workloadsAnti-malware with signature updates, without behavioural detectionHost-based firewall enforced through device management or policySoftware allowlisting or application control policyDevice compliance checks enforced through device managementSpam and phishing filtering on inbound email with automatic detection content updatesNone of the above

Options run from the strongest coverage to the weakest. A modern detection and response agent across all managed endpoints plus host-based firewall enforcement is the minimum for a service provider. Email filtering belongs here because it is the route most malicious code arrives by, and its value collapses fastest without current detection content. Name capabilities rather than products when recording what is deployed.

INF-012Capacity and Performance Management
boolean

Is current and projected resource utilisation monitored against defined thresholds?

Monitoring should cover all critical resource types. Alerts should fire with enough lead time to allow scaling decisions before service is impacted.

select

How frequently is capacity planning reviewed to ensure production infrastructure can meet operational demands?

Continuously: automated scaling with no manual capacity review neededMonthly capacity review with documented projected vs actual utilisationQuarterly capacity reviewAnnually or less frequentlyNo formal capacity planning process

Auto-scaling removes much of the risk but does not eliminate the need for capacity planning at the service limit level. Quarterly reviews are a minimum for services with defined availability SLAs.

multi

Which of the following are monitored against a defined threshold with an alert configured before exhaustion?

ComputeStorageNetwork throughputAPI throughputLog storage against its required retention periodNone of the above

Options run from the most commonly monitored to the least. Log storage is the one that fails quietly: the store fills, the oldest events roll off and the retention the organisation believes it holds is gone before anyone looks.

INF-013Infrastructure Redundancy
boolean

Is production infrastructure deployed with redundancy for the components whose failure would stop the service?

Where the service runs in a cloud region, multi-zone deployment of compute, database and load balancing is the minimum expected redundancy posture.

select

What level of infrastructure redundancy is implemented for production services?

Multi-region active-active (workloads running simultaneously across two or more regions)Multi-region active-passive (failover to a secondary region with automated or manual activation)Multi-AZ within a single region (standard cloud provider availability zone redundancy)Single AZ with backup and restore as the recovery mechanismNo documented redundancy architecture

Multi-AZ within a single region is the baseline expectation. Multi-region is expected where SLAs commit to recovery times that a single-region failure would breach.

multi

Which of the following apply to your availability architecture?

It is documentedIt is aligned to the defined recovery time and recovery point objectivesRedundancy configurations are tested at defined intervalsThe test result is recorded against the architectureNone of the above

Options run from the most commonly in place to the least. Redundancy that has never been exercised is a design rather than a capability. The failover most likely to fail is the one that has only ever been drawn.

INF-014Clock Synchronisation
boolean

Do all production systems synchronise their clocks from approved, authoritative time sources?

Cloud-native environments should use the cloud provider's time sync service (e.g. Amazon Time Sync Service, Google Time Servers). Drift monitoring should alert on offsets exceeding a defined threshold.

select

How is NTP synchronisation and clock drift monitored across production systems?

Automated monitoring with alerting on clock drift exceeding a defined threshold (e.g. >1 second)Cloud provider time sync configured by default: no explicit monitoring beyond provider guaranteesPeriodic manual check of NTP configuration on a sample of systemsNo monitoring of clock synchronisation

Automated drift monitoring with alerts is expected for environments where log correlation accuracy is required for compliance or incident response. Cloud provider defaults alone are insufficient.

INF-015Multi-Tenant and Workload Isolation
boolean

Is tenant data isolated so that one tenant cannot read another tenant's data?

Answer yes only where a mechanism enforces the boundary. An application convention that every query includes a tenant identifier is not enforcement; a platform that refuses the query without one is.

multi

At which layers is isolation between tenants or between workloads enforced?

Data layer, through per-tenant stores or policies the database enforcesStorage layer, through per-tenant paths, buckets or encryption keysCompute layer, through separate execution domains per workloadMemory and shared resources, cleared or re-keyed before reuseDerived stores such as a vector index or embedding store, scoped by tenant and segregated by trust tierManagement functions served from a separate execution domain from user functionsNone of the above

Isolation usually fails at a layer nobody drew: a shared cache, a search index, an export path or a vector index built from several tenants' documents. Count a layer only where the enforcement is in the platform rather than in the calling code.

select

How is cross-tenant access tested?

An automated test suite runs on every change and asserts a denial for each isolation caseAn automated test suite runs on a defined scheduleIsolation cases are included in the scope of periodic penetration testingIsolation is reviewed at design time onlyCross-tenant access is not tested

Options run from strongest to weakest. A design review records an intention; a test that asserts a denial records the current behaviour of the deployed system.

INF-016Domain, DNS and Routing Security
boolean

Is there an inventory of every public domain and DNS zone used by the service with a named owner for each?

Marketing sites, regional domains and defensive registrations count. A domain nobody owns is the one that expires.

multi

Which of the following protect your domains and name resolution?

Transfer lock set at the registrarMulti-factor authentication on registrar and DNS provider accountsAuthoritative zones signed, with the delegation published at the parentResolvers used by production systems validate signaturesAuthoritative name service spread across independent nodes or providersAuthoritative service separated from recursive resolutionRecords checked for targets that are no longer heldRouting origin registered and authorised for address space the service announces, or the operator's equivalent recorded where it announces noneNone of the above

Signing and validation are separate settings and one without the other protects nothing. The check for records pointing at released cloud resources is what closes subdomain takeover. The routing item is answerable by a provider that owns no address space: what is recorded there is whose measure applies and the statement it comes from.

select

How often are DNS records checked for targets the organisation no longer holds?

Continuously, with an alert on each new findingOn a schedule of a month or shorterOn a schedule longer than a monthOnly when a record is changedNot checked

Options run from strongest to weakest. The exposure window is the gap between releasing a cloud resource and removing the record that points at it, so the interval is the control.

INF-017Managed Endpoint Baseline
boolean

Is every endpoint used to access organisational or customer data enrolled in centralised device management?

Enrolment is what makes the rest of this control testable from one export. Personal devices used for work count; if they are permitted without enrolment, the answer is no.

multi

Which of the following are enforced on managed endpoints by the management platform?

Storage encryptionAutomatic screen lock that conceals displayed contentInstallation limited to an approved application list or approved sourcesOperating system and application updates delivered through change managementRemovable media and peripheral connections restrictedRemote locateRemote wipeVerified sanitisation before disposal or reissueNone of the above

Count a setting only where the platform enforces it and reports compliance. A rule written in the endpoint standard and left to the user is not enforcement.

select

How is the endpoint inventory kept accurate?

The platform enrols devices automatically and the inventory is reconciled against the workforce list on a defined cycleThe inventory is reconciled against the workforce list on a defined cycleThe inventory is updated when a device is issued or returnedThe inventory is compiled when it is asked forThere is no endpoint inventory

Options run from strongest to weakest. The failure this measures is the device nobody removed when its user left, which only a reconciliation against the workforce list finds.

INF-018Physical Access and Environmental Protection
boolean

Is physical access to each office the organisation occupies restricted to an approved access list?

A serviced or shared office still has an access list; it is held by the building operator and the organisation approves who is on it. Answer for the space the organisation controls.

multi

Which of the following are in place at the premises the organisation occupies?

An approved access list that is reviewed and revoked on departureAn auditable access control system that records entry and exitA visitor register with escortingIntrusion detection or surveillance covering entry pointsReview of access records and alarms at defined intervalsFire detection and suppressionEnvironmental protection appropriate to the facilityA maintenance record for repairs and modifications to the physical security componentsNone of the above

Answer for the space the organisation occupies, not for the cloud data centre. What the infrastructure operator does is covered by the attestation question. The maintenance record covers the doors, locks, walls, barriers and access hardware that enforce the boundary; a general facilities ticket queue counts only where the security work can be identified inside it.

select

How are the physical controls of the infrastructure operator evidenced?

A current attestation is obtained and reviewed on a defined cycle, with the controls inherited from it recorded against the requirements they satisfyA current attestation is obtained and reviewed on a defined cycleAn attestation is held on fileThe operator's public compliance page is relied onThe operator's physical controls are not evidenced

Options run from strongest to weakest. The step most often missed is the last one in the strongest option: writing down which of your requirements each inherited control answers, so that a gap is visible when the report changes.

MON-001Audit Log Scope and Generation
boolean

Is there a documented log scope naming the security-relevant events captured across production systems, applications and cloud services?

Log scope should be documented in a formal policy or standard. Gaps in event categories (e.g. no data access logging) are a common audit finding.

multi

Which event categories are captured in your production audit logs?

Authentication successes and failuresPrivilege use and role/permission changesAdministrative and configuration changesData access and data export eventsAPI requests (at least for sensitive endpoints)System and application errorsNetwork connection events (e.g. VPC flow logs)None of the above

All seven categories are expected for a complete audit logging posture. Missing data access or configuration change logging are the most common gaps in enterprise environments.

MON-002Log Integrity and Protection
boolean

Are audit logs stored in a tamper-resistant or write-once store?

Log storage should be in a separate account, project, or cloud resource from the systems generating logs. Object Lock (Compliance mode) or equivalent immutability should be enforced.

multi

Which mechanisms are used to protect audit log integrity?

Write-once or immutable storage for the log storeCryptographic signing or hashing of audit records on writeIndependent verification of those values, with the key or anchor held outside the producing systemSignature or hash verification of the audit tools themselvesLog storage in a separate account or project from production systemsAccess controls restricting modification and deletion to a named privileged roleAlerting on any modification or deletion attempt against the log storeNone of the above

Options run from the most commonly held to the least. Storage controls and cryptographic protection answer different attacks: immutable storage stops deletion by someone who reached the store, signing stops undetected alteration before the record arrived, including by whoever runs the store. Covering the tools closes the case where the reader is changed rather than the data.

MON-003Log Retention
boolean

Are audit logs retained for a documented minimum period?

The minimum expected retention is 12 months online and up to 24 months in cold storage. Retention policies should be automated, not dependent on manual archiving.

select

What is the current minimum retention period for audit logs in your environment?

24 months or more (online or tiered storage)12 months online, with additional cold storage beyond 12 months12 months online only6 monthsLess than 6 months or no defined retention period

12 months online with extended cold storage is the standard expectation. For organisations subject to the EU AI Act or GDPR enforcement, ensure retention aligns to applicable regulatory timelines.

boolean

Is the retention period enforced by an automated policy on the log store rather than by a manual archiving process?

Answer yes only where the lifecycle or retention rule is set on the store itself, so a log ages out or is preserved without anyone acting. A calendar reminder to archive is not enforcement.

MON-004Centralised Log Management
boolean

Is log data from production systems, applications, cloud services and network devices aggregated into a centralised log management platform?

Centralised collection is a prerequisite for effective threat detection. Siloed logs that cannot be correlated across systems leave blind spots in incident investigation.

multi

Which of the following log sources are ingested into your centralised platform?

Production application logsOperating system and container logsCloud provider control plane and audit logsNetwork device and flow logsIdentity provider and authentication logsSecurity tooling alertsNone of the above

Options run from the most commonly ingested to the least. The control is about coverage and correlation, not about which platform is in use. A source that is collected but lands somewhere the platform cannot search does not count.

select

How are logging pipeline failures and log storage capacity issues detected and responded to?

Automated alerting on storage threshold breaches and pipeline failures, with a defined response SLA and runbook, plus platform availability monitored from outside the platformAutomated alerting on storage threshold breaches and pipeline failures, with a defined response SLA and documented runbookAutomated alerting configured but no defined response SLA or runbookPeriodic manual review of storage utilisation and pipeline statusNo monitoring of log pipeline health or storage capacity

Options run from strongest to weakest. Automated alerting with a defined response SLA and runbook is the working standard. The strongest option adds the part that is almost always missing: a check on the platform that runs somewhere else, because a health dashboard inside the platform goes dark with the outage it exists to report.

MON-005Security Monitoring and Alerting
boolean

Are production systems monitored for anomalous behaviour and indicators of compromise?

Active monitoring requires both configured detection rules and a team responsible for reviewing and responding to alerts. Logs without active review provide no detection capability. Answer yes only where the periodic review of the record sets themselves also happens: alert triage reads what crossed a threshold, which is a different act from reading the audit logs, the access reports and the incident tracking records at a stated interval.

multi

Which threat scenarios are covered by active detection rules in your SIEM or monitoring platform?

Brute force and credential stuffing attacksPrivilege escalation or unusual privilege useImpossible travel or authentication from anomalous locationsIndicators of data exfiltration (e.g. large data exports, unusual API query volumes)Configuration changes to security controlsMalware or suspicious process execution on endpointsLateral movement indicatorsNone of the above

The first four categories are the minimum expected coverage. All seven indicate a mature detection programme.

select

What is the defined SLA for acknowledging and triaging high severity security monitoring alerts?

Within 15 minutes (24/7 on-call coverage)Within 1 hour (24/7 on-call coverage)Within 4 hours (business hours coverage)Within 24 hoursNo defined SLA for alert triage

24/7 coverage with a 1-hour or faster acknowledgement SLA is the expectation for high severity alerts in a production environment.

MON-008Detection Content Lifecycle
boolean

Is the detection rule set mapped to a threat model or a recognised technique catalogue?

Mapped means each rule points at the behaviour it is there to catch and the coverage of the model can be read off the mapping. A rule set built from vendor defaults with no reference back to a threat model does not meet this.

multi

Which of the following does the detection rule set record for each rule?

The behaviour the rule detectsIts reference in the threat model or technique catalogueA named ownerThe date it was last reviewedThe reason and the revisit date for any suppression or disablementNone of the above

The suppression fields are the ones that decay fastest, because a rule silenced during an incident is rarely re-examined. Answer against what the platform holds, not against what the runbook says should be held.

select

How often are detection rules tuned using the outcomes of the alerts they raised?

On a defined cycle of a month or shorter, with true-positive and false-positive outcomes recorded per ruleOn a defined quarterly cycle, with true-positive and false-positive outcomes recorded per ruleOn a defined annual cycleOnly when a rule is reported as noisyRules are not tuned after they are written

Options run from strongest to weakest. Tuning means changing the rule on evidence from the queue. Disabling a noisy rule without a revisit date is suppression, which the previous question covers.

MON-009Log Access Control and Sensitive Data in Logs
boolean

Is read access to production logs restricted to named roles?

Answer no where every engineer inherits log read access from a general production role. The question is about the log platform, not about the systems that produce the logs.

multi

Which of the following apply to your logging pipeline and log store?

Secrets, credentials and tokens are filtered before a record reaches the storePersonal data beyond the entry's purpose is filtered or tokenised before a record reaches the storeThe store is scanned for values that got past the filterReads of the log store are themselves loggedChanges to logging configuration are restricted to a smaller set of roles than log readsNone of the above

Filtering before the record reaches the store is different from masking it in a query or a dashboard, which leaves the value in the store. Answer against the pipeline as it runs, not against the logging standard.

select

How often are log platform access grants reviewed?

At least quarterly, with removals actioned before the next reviewAt least annually, with removals actioned before the next reviewWhen someone raises a concernGrants are not reviewed after they are made

Options run from strongest to weakest. A review that produces findings nobody actions is not a review; the removals are the test.

MON-010Availability and SLO Monitoring with Status Communication
boolean

Does every customer-facing service have a defined availability objective?

An objective is a target with a measurement window, not a phrase in a sales contract. Answer no where availability is watched but no target is written down.

multi

Which of the following are in place for availability monitoring?

An objective with a defined measurement window for each serviceAn error budget derived from that objectiveA latency objective for the principal operationsAt least one qualitative target per service alongside the availability and latency objectivesMeasurement from signals that represent what a customer experiencesAn alert to a named team on breach or projected breachA recorded corrective action on every missed target, inside a stated periodA status channel customers can read without an accountNotice to the customers a published service level binds before a revision to it takes effectNotice of a development that puts a committed service level at risk, through a channel other than the status channelNone of the above

Measurement from the customer's side means a probe or a request-level metric from the path a customer uses. Host uptime and container health checks answer a different question and a service can pass both while customers see errors. A qualitative target counts only where a threshold decides the miss. The last item is the one no status page carries: a change of control, a lost certification, a failing subcontractor or a retirement decision all threaten a service level before any event opens.

select

How are customers told about a degradation in progress?

A status channel is updated within a defined time of detection and through to resolutionA status channel is updated, with no defined time to the first entryCustomers are told individually by the support or account teamCustomers find out by raising a support ticket

Options run from strongest to weakest. The defined time is measured from detection, not from the point the cause is understood, because a customer needs to know the service is affected before anyone knows why.

VND-001Vendor Risk Assessment and Due Diligence
boolean

Is a documented risk assessment conducted for each third-party vendor before engagement?

The assessment should be completed before the vendor is engaged and produce a documented risk rating and engagement decision signed off by an appropriate authority (e.g. CISO, DPO). Critical vendors should be reassessed at least annually.

multi

What does the vendor risk assessment and supplier register cover?

Information security posture (e.g. certifications, security questionnaire or scorecard)Privacy practices and GDPR compliance (DPA status, data handling practices)Regulatory compliance and applicable certifications (SOC 2, ISO 27001)Incident history and breach notification track recordFinancial stability and operational resilienceSub-processor or supply chain riskA register entry per supplier carrying a contact point and the ICT products, services and processes it providesAssessment is limited to contract review onlyNone of the above

A comprehensive pre-engagement assessment should cover at minimum: security posture, privacy compliance, certifications and incident history. Financial and operational resilience assessment is important for critical suppliers.

boolean

Is there a named cross-functional group that owns supply chain risk activity, with its members and their responsibilities recorded?

Answer yes only where the membership and the activities the group leads are written down rather than understood informally. A standing meeting with no terms of reference, or a group that exists on a slide and has not met, does not count.

VND-002Security Requirements in Vendor Contracts
boolean

Do contracts with all vendors who access, process, store or transmit organisational data include binding security and privacy obligations?

Contracts should include at minimum: information security obligations, incident notification timelines (72 hours or less), audit rights, data handling and deletion requirements, sub-processor controls, and exit provisions.

multi

Which of the following clauses are included as standard in your vendor contracts?

Binding information security obligationsIncident notification timeline (72 hours or less)Data handling and deletion obligations on terminationAudit rights (direct audit or acceptance of third-party certification)Sub-processor approval requirementApplicable law and jurisdictionData Processing Agreement (DPA) satisfying GDPR Art.28.3Exit provisions and data portabilityNone of the above

All eight clauses are expected in contracts with vendors processing personal or sensitive data. Absence of a DPA for any personal data processor is a direct GDPR compliance gap.

multi

Which of the following do your contracts for supplied components and external services require?

A description of the functional properties of the security controls the component or service implementsDesign and implementation information for those controls at an agreed level of detailA declaration of the functions, ports, protocols and services the component or service usesPriority-of-service provisions set against the recovery time objective, in alternate processing agreementsNone of the above

Options run from the most commonly required to the least. A receiving organisation cannot secure what it cannot describe: a component whose ports and protocols are undeclared cannot be fitted to a hardening baseline, and a control whose functional properties are unstated cannot be relied on or tested. Priority of service decides whether alternate capacity is there when everyone else is invoking theirs too.

VND-003Sub-Processor Management
boolean

Does your organisation maintain a current register of all sub-processors?

The sub-processor register should be publicly accessible or available to customers on request. Customer notification of sub-processor changes must occur with sufficient notice for the customer to object.

select

How does your organisation manage changes to the sub-processor list?

Customers are notified of sub-processor changes in advance (e.g. 30 days) and have a right to objectCustomers are notified of changes but with no formal objection right or notice periodThe sub-processor list is published and updated, but customers are not proactively notified of changesNo formal customer notification process for sub-processor changes

Advance notification with a right to object is the standard expected by enterprise customers and is required under GDPR Art.28.2. A published list without proactive notification is a weaker but common approach. The customer should confirm whether this satisfies their contractual requirements.

boolean

Are sub-processors bound by data protection obligations equivalent to those you owe the controller?

Answer yes only where the flow-down is in the executed agreement with each sub-processor rather than asserted in your own privacy documentation. A sub-processor engaged on its own standard terms usually is not so bound.

VND-004Cloud Service Provider Security Management
boolean

Is there a documented process governing the selection, security assessment, configuration, monitoring and exit of cloud service providers?

The process should include security baseline configuration standards (e.g. CIS Benchmarks), documented shared responsibility boundaries, and contractual data portability and exit provisions. Misconfiguration of cloud services is a leading cause of security incidents.

multi

Which elements of cloud service provider security management are formally documented in your organisation?

Shared responsibility matrix for the primary CSPBaseline security configuration standard referencing the CSP (e.g. CIS Benchmarks for AWS, GCP, Azure)Regular review of CSP configurations against the baselineContractual data portability and exit provisionsCSP exit planning and data migration procedureNone of the above

A shared responsibility matrix and documented configuration baseline are the minimum expected artefacts. Exit planning is critical to ensure data can be recovered or migrated if the CSP relationship ends.

VND-006Vendor Monitoring and Performance Review
boolean

Are vendor security posture and contractual performance reviewed at defined intervals of at least annually?

Reviews should include: updated security certifications or questionnaire responses, incident history check, SLA performance, and any open findings from the previous review. Material deficiencies should be escalated and tracked to resolution.

multi

What triggers a vendor security review outside of the regular annual cycle?

Vendor security incident or disclosed breachSignificant change to vendor service scope, ownership, or infrastructureCustomer complaint or audit finding relating to a vendorVendor certification lapses or is downgradedMaterial change to the volume or sensitivity of data processed by the vendorNone of the above

Event-triggered reviews are critical because vendor risk does not change on a fixed annual schedule. Vendor breaches and significant service changes should always trigger an unscheduled reassessment.

multi

Which of the following does each vendor review record?

The vendor's current certifications or questionnaire responsesIncident history since the last reviewService delivery against the agreed levelsThe status of findings raised at the previous reviewEscalation of any material deficiency, with the escalation recordedNone of the above

Options run from the most commonly recorded to the least. A review that reads the current certificate and nothing else repeats the pre-engagement assessment rather than testing the relationship since.

VND-007Vendor Access Controls
boolean

Is every vendor and third-party access grant formally authorised before access is enabled?

Vendor accounts must enforce MFA, have scoped permissions (no broad administrative access), and be time-bounded. Privileged vendor sessions should be logged and, where possible, recorded.

multi

Which controls are applied specifically to privileged vendor access (e.g. remote support, admin credentials)?

Multi-factor authentication enforced for all vendor accountsJust-in-time (JIT) access provisioning: access is granted only for the duration of the support activitySession recording for all privileged vendor sessionsPrivileged Access Management (PAM) solution mediating all vendor privileged accessAccess review conducted each time a vendor engagement is renewed or modifiedVendor accounts reviewed and deprovisioned when the engagement endsNone of the above

JIT provisioning, MFA, and session recording are the expected standard for privileged vendor access. Standing, unmonitored vendor accounts with broad access are a high-risk exposure.

VND-008Vendor Offboarding
boolean

Does your organisation follow a documented offboarding procedure when a vendor relationship ends?

All vendor access credentials (SSO, API keys, service accounts, VPN) must be revoked on or before the termination date. The vendor must provide written confirmation of data deletion or return. Contractual documents including the DPA must be archived.

multi

What does your vendor offboarding checklist include?

Revocation of all SSO accounts, API keys, service accounts and VPN credentialsWritten confirmation from the vendor of data deletion or returnVerification that deletion satisfies the DPA clause obligationsArchive of contractual records including MSA and DPANotification to affected internal teams of the vendor changeFormal sign-off by IT Security and Legal or equivalentNone of the above

All six elements of a complete offboarding should be present. Absence of written vendor confirmation of data deletion is a common gap that creates ongoing liability.

VND-010Third-Party Data Disclosure Controls
boolean

Are disclosures of personal or sensitive data to third parties recorded in a disclosure register?

Every standing third-party disclosure relationship should appear in the data inventory or a dedicated disclosure register. Recipients must be restricted to the minimum data required for the stated purpose, and disclosures must be consistent with what is stated in the privacy notice.

multi

What controls govern the disclosure of personal or sensitive data to third parties?

A data sharing agreement or equivalent contractual provision governs every disclosure relationshipEach disclosure is logged with recipient, data categories, purpose and legal basisDisclosures are limited to the minimum data necessary for the stated purposeOnward sharing by recipients is prohibited or requires approvalThird-party disclosures are listed in the public-facing privacy noticeDisclosures are reviewed periodically to confirm they remain necessary and proportionateNone of the above

All six active controls indicate a mature third-party disclosure programme. Absence of a disclosure register makes it impossible to fulfil data subject requests or demonstrate accountability to a supervisory authority.

VND-011Shared Responsibility Model and Customer Security Communication
boolean

Is the shared responsibility matrix published where a prospective customer can read it without an account?

The test is publication, not existence. A matrix supplied on request, behind a customer login or under a non-disclosure agreement does not meet this, because a customer scoping its own controls before it signs cannot reach it.

multi

What does the customer-facing security documentation cover?

Which controls the organisation operates, which the customer operates and which are sharedThe control set the matrix is expressed againstThe system boundary of each serviceWhat is committed for the availability, integrity, confidentiality and authenticity of customer dataResponsibilities that pass to a sub-processor or infrastructure operatorHow changes affecting a customer environment are authorised or notifiedThe measures that resist access by an authority outside the organisation's jurisdictionNone of the above

Naming the control set is what makes the matrix usable: a customer scoping its own audit needs to know which framework the rows correspond to. Authenticity is the commitment most often absent, because it is the one no encryption setting produces on its own. The last item is a statement about what is in place, not about how a request is handled once it lands.

select

When is the shared responsibility documentation reviewed?

On a defined cycle and after every change to the service boundaryOn a defined cycleWhen a customer or an auditor asks for itWhen the service changes materially, without a cycleIt has not been reviewed since it was written

Options run from strongest to weakest. A new service or a new sub-processor is what makes the matrix wrong, so the trigger matters as much as the cycle.

VND-012Government and Law Enforcement Data Request Handling
boolean

Is there a documented procedure for handling government and law enforcement requests for customer data?

This is separate from the disclosure controls that govern sharing you choose to do. The question is what happens when a demand arrives that you cannot decline on contract grounds.

multi

What does the procedure require before data is released?

Legal review of the authority the request relies onFor an instrument issued outside the jurisdictions the organisation is established in, a recorded recognition testNarrowing of the response to the data the request compelsApproval by a named roleA record of the request, the release and the decisionCustomer notification before the response is produced, unless notification is prohibitedA record of any prohibition on notification and when it lapsesA route to an external legal authority for an opinion, with the ground of any refusal recordedNone of the above

Narrowing is the step most often missed: an overbroad demand answered in full is a disclosure the organisation chose to make. The recognition test is the step before that one and is missed more often still, because a review that satisfies itself the order is valid where it was issued has answered a different question. Notification counts here only where it runs before the response leaves.

select

How are requests reported to customers?

A periodic report of requests received and actioned is published, alongside a description of the procedureA periodic report is provided to customers on requestThe procedure is described to customers with no reporting of volumesRequests are discussed only when a customer asksNeither the procedure nor the volumes are communicated

Options run from strongest to weakest. Reporting counts of requests is possible even where an individual request is under a non-disclosure order.

VND-013Regulatory and Exit Terms in Customer Agreements
boolean

Is there a register of the customer agreements in force and the terms each is required to carry?

The register is about terms the organisation accepts from a customer, not terms it imposes on a supplier; those are in the vendor contract control. Answer yes only where the register exists and lists the agreements, not merely the regulations.

multi

Which of the following does the customer agreement state?

A maximum notice period for initiating a switch away from the serviceA maximum transitional period during which the contract remains in forceA minimum retrieval period starting at the end of the transitional periodErasure of the customer's data and digital assets after the retrieval periodAn exhaustive list of the categories the customer can take with it and of the provider-internal categories excluded, with a ground for each exclusionA customer election between moving to another provider, moving to its own infrastructure and erasure, with a right to extend the transitional period onceThe grounds and notice periods on which either party may terminate, including a subcontracting change made without the customer's approvalThe basis of any charge raised for a switch or for moving data outThe terms a regulation makes compulsory for the data the customer entrustsNone of the above

Count only what the executed agreement or the terms it incorporates say. A commitment made in product documentation, a support article or a trust centre page is not a term of the agreement. Options follow the order a switching schedule is normally drafted in, not an order of importance.

select

How is the agreement set kept current when the terms a regulation requires change?

Every affected agreement is amended, or carries a recorded decision that none was needed, inside a defined periodEvery affected agreement is amended at its next renewalThe change is noted and actioned case by caseThe change is not tracked against the agreement set

Options run strongest to weakest. Answer on what happened the last time a required term changed, not on what the contract management procedure says would happen.

VND-014Customer and Regulator Audit and Inspection Rights
boolean

Is there a published procedure stating the audit and inspection rights granted to customers?

Published means a customer or a prospective customer can read it rather than negotiate it. An audit clause in a signed contract with no published procedure behind it is a no, as is a procedure that exists only as an internal playbook.

multi

Which of the following does the procedure state?

Rights granted to a third party the customer appointsRights granted to an authority supervising the customerAn on-site inspection route and the evidence that may be copied on siteAccess to the premises the service is provided fromAn alternative assurance route where access would reach another customer's dataA pooled audit route for customers of the same serviceA customer route to ask for the scope of an offered report or certification to be changedThe reports the organisation produces for a customer on a standing basisNone of the above

Tick an element only where the published procedure states it. A right the organisation would grant on request but has not written down does not count here. The premises option is about physical sites, including sites operated by a subcontractor, not about remote access to systems.

select

How often may a customer exercise an audit under the published terms?

At the customer's discretionAt an agreed frequency stated in the contractOnce a yearOnly where a material finding or an incident triggers itNo audit right is granted

Options run from the widest right to the narrowest. Answer on the terms as published, not on how often customers have actually asked.

VND-015Subcontractor Disclosure and Change Approval
boolean

Is a record of the subcontractors underpinning each customer-facing service made available to customers?

This is the ICT supply chain behind the service, whether or not personal data is involved. A sub-processor list covering only parties that process personal data is a no unless it also reaches the rest of the chain.

multi

Which of the following does the subcontractor change process provide?

Advance notice of a material change to the affected customersA stated notice period during which a customer may objectImplementation held until the period closes or the customer approvesImplementation held while an objection is openFlow-down of the customer's audit access rights into the subcontractFlow-down of the monitoring, reporting, continuity and security terms the customer contract requiresRequirements on the subcontractor's personnel for training, certification and background verificationNone of the above

Answer on what the process does rather than on what a contract template offers. The third and fourth options differ: a change can be held until the notice period closes and still go ahead over an objection raised inside it.

select

What identifies each subcontractor in the record?

A legal entity identifier, the operating country, a contact point and the products and services it providesA legal entity identifier and the operating countryA legal entity name and the operating countryA legal entity name onlyA service category without naming the party

Options run from the most complete entry to the least. Answer on the record as published, not on what the internal supplier register holds.