1. How is access to your facility controlled?






  2. How often do you have visitors at your facilities?






  3. How often do you employ contracted or temporary employees at your facilities?






  4. How many people have physical access to network nodes and links?






  5. How often are personal computers scanned for malware?






  6. How often is your anti-virus scanner updated?






  7. Does your business employ an enterprise level firewall?



  8. Does your business encrypt its data?



  9. What are your password requirements?






  10. How often are users required to change their passwords?






  11. How often do you backup critical data?






  12. How many people have access to backed-up media?






  13. Do access logs exist that record who access data?



  14. Do network assets have access control lists?



  15. Do you safely dispose of all written matter?


Click here for the Javascripted version of this assessment