Section 13.115 Performing an Internal Assessment Flashcards

Objective 5.5 Explain types and purposes of audits and assessments

1
Q

Internal Assessment

A

■ Proactive evaluation of an organisations security posture

■ Helps to identify and address potential risks and vulnerabilities in information systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Sample Checklist

A

■ The specific checklists and procedures for an internal assessment may vary based on the following

● Organization’s governance
● Risk
● Compliance practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

EXAMPLE

Minnesota Counties Intergovernmental Trust (MCIT)

A

MCIT Cybersecurity Self-Assessment

● MCIT’s Cybersecurity Self-Assessment checklist is designed to help organisations minimise data and cybersecurity-related exposures

● It assists in identifying areas where data security may need strengthening
● The checklist comprises yes-or-no questions with sections for comments
and action items
● Action items are assigned to specific individuals or groups responsible for
implementing corrective actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Collaborative Approach

A

■ To maximize the checklists effectiveness, involve a diverse group of participants

from across the organisation
● Administration team
● Information technology staff
● Cybersecurity professionals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Overview of the Checklist

Overview of the Checklist

A

■ The checklist is broad and aims to provide a quick overview of the organisations current risk posture

■ Organisations may use different checklists or variations with distinct questions

■ The general format and purpose of self-assessments are consistent across most organisations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly