Section 13.115 Performing an Internal Assessment Flashcards
Objective 5.5 Explain types and purposes of audits and assessments
Internal Assessment
■ Proactive evaluation of an organisations security posture
■ Helps to identify and address potential risks and vulnerabilities in information systems
Sample Checklist
■ The specific checklists and procedures for an internal assessment may vary based on the following
● Organization’s governance
● Risk
● Compliance practices
EXAMPLE
Minnesota Counties Intergovernmental Trust (MCIT)
MCIT Cybersecurity Self-Assessment
● MCIT’s Cybersecurity Self-Assessment checklist is designed to help organisations minimise data and cybersecurity-related exposures
● It assists in identifying areas where data security may need strengthening
● The checklist comprises yes-or-no questions with sections for comments
and action items
● Action items are assigned to specific individuals or groups responsible for
implementing corrective actions
Collaborative Approach
■ To maximize the checklists effectiveness, involve a diverse group of participants
from across the organisation
● Administration team
● Information technology staff
● Cybersecurity professionals
Overview of the Checklist
Overview of the Checklist
■ The checklist is broad and aims to provide a quick overview of the organisations current risk posture
■ Organisations may use different checklists or variations with distinct questions
■ The general format and purpose of self-assessments are consistent across most organisations