Yes-No Questions
Yes-No Questions
IT Governance
Is there a clear set of rules for how IT should work in the company?
Are IT policies written down and available for all employees to read?
2. Access Control
Is there a process to remove user accounts when employees leave the company?
Is multi-factor authentication (like a password plus a code) used for important systems?
3. Data Security
Is there a safe way to dispose of old computers that might have sensitive data?
4. Incident Management
Are all security incidents recorded and reviewed for future improvements?
Does the company follow data privacy laws that apply to its business?
Are there regular checks to ensure the company meets industry security standards?
6. Network Security
7. Software Management
Are all software licenses current and following the rules set by vendors?
8. Physical Security
Are there physical security measures to protect IT equipment (like cameras or locks)?
Is there a written plan for keeping the business running during emergencies?
Is there a team responsible for keeping the business continuity plan updated?
Is there a system in place to monitor and log user activities on critical systems?
Are all software installations reviewed to ensure they comply with licensing agreements?
Does the company conduct regular security assessments or audits to identify vulnerabilities?