Build a stronger information security program with a clear starting point.
The InfoPathways ISO 27001 Readiness Assessment provides a straightforward look at your organization's information security practices against ISO/IEC 27001:2022 Annex A. Assess key areas of your security program, identify gaps, and gain a clearer understanding of where improvements can strengthen your overall readiness.
Section 1 of 6
ISO 27001 Readiness Assessment
This assessment will evaluate your organization's information security practices across control categories based on ISO/IEC 27001:2022 Annex A.
You will be asked a series of questions about your security governance, people practices, physical security, and technical controls.
Estimated time: 10-15 minutes
A.5 — Organizational Controls
1. Has your organization established and obtained management approval for information security policies?
2. Are information security roles and responsibilities clearly defined and documented for all relevant personnel?
3. Does your organization enforce segregation of duties for conflicting tasks to prevent unauthorized activity?
4. Does your organization actively collect and analyze threat intelligence to inform security decisions?
5. Does your organization manage information security requirements in supplier and third-party relationships?
6. Does your organization have a defined and documented incident management process?
7. Has your organization identified and documented all applicable legal, statutory, regulatory, and contractual requirements?
8. Does your organization conduct independent reviews of its information security program?
A.6 — People Controls
9. Does your organization perform background verification checks prior to employment or granting system access?
10. Do employment agreements and conditions of employment address information security responsibilities and obligations?
11. Does your organization provide security awareness, education, and training to all personnel?
12. Does your organization have a documented disciplinary process for security policy violations?
13. Does your organization have a defined process for handling responsibilities when employees terminate or change roles?
14. Does your organization use confidentiality or non-disclosure agreements with employees and relevant third parties?
A.7 — Physical Controls
15. Does your organization establish and enforce physical security perimeters to protect areas with sensitive information?
16. Does your organization implement physical access controls to restrict entry to secure areas?
17. Does your organization protect equipment from environmental threats and unauthorized physical access?
18. Does your organization securely dispose of or reuse equipment before it leaves your organization's control?
19. Does your organization enforce a clear desk and clear screen policy across the organization?
A.8 — Technological Controls (Part 1)
20. Does your organization protect user endpoint devices with encryption and malware protection?
21. Does your organization restrict and regularly review privileged access rights?
22. Does your organization restrict access to information and systems based on documented access control policies?
23. Does your organization implement multi-factor authentication (MFA) for system access?
24. Does your organization perform capacity management to ensure adequate system resources and performance?
25. Does your organization implement protection against malware across all systems?
26. Does your organization identify and manage technical vulnerabilities in a timely manner?
A.8 — Technological Controls (Part 2)
27. Does your organization establish and enforce secure baseline configurations for systems?
28. Does your organization implement logging that captures security-relevant events and is protected from tampering?
29. Does your organization implement network security controls such as segmentation and firewalls?
30. Does your organization use cryptography to protect the confidentiality, integrity, and authenticity of information?
31. Does your organization follow secure development lifecycle practices in software development?
32. Does your organization implement data leakage prevention measures?
33. Does your organization perform backups of information, software, and systems and regularly test them?
Almost Done!
Please enter your information below to receive your results via email.
Assessment Complete
Your detailed results and gap remediation recommendations have been sent to . Check your inbox for your full results report.