NIS2 Quick Scan
Answer the following 10 questions to measure your NIS2 readiness.
Does your organisation have a formal information security policy that is periodically reviewed?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Does your organisation have a formal incident response plan?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Does your organisation have a business continuity plan (BCP) that includes IT systems and data?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Are security requirements imposed on suppliers who have access to your systems or data?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Are networks segmented to limit the impact of security incidents?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Are regular vulnerability scans conducted on systems and applications?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Is sensitive data encrypted during storage (encryption at rest)?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Do all employees receive regular security awareness training?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Is the principle of least privilege applied (minimum necessary rights)?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Is there an up-to-date inventory of all IT assets (hardware, software, data)?
Choose "Partial" when the measure exists but is not yet fully implemented, documented or applied everywhere.
Answer all 10 questions to continue.
