☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ Incident Handling and Response 81. Do staff know how, when and where to report a breach of company policy and or ☐ ☐ a possible cyber-attack? 82. Do employees know how to isolate and quarantine compromised systems by removing them from the network? ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ ☐ 72. Are employees trained not to store passwords in insecure places such as their 73. 74. 75. 76. 77. 78. 79. 80. wallet, purse, or post-it-note on their computer? Are employees trained/reminded of what type of information handled by the organisation should be regarded as sensitive information? Are employees trained/reminded to save sensitive/critical data to a server where it’s being backed up? Are employees trained to be suspicious of any software that arrives in the mail, even where it appears to be packaged by a trusted vendor? Are employees regularly trained not to download executable code, not to open suspect emails, and not to install personal software on computer systems? Are employees trained not to visit illicit websites including file sharing/downloading websites? Are your employees able to identify and protect classified data, including paper documents, removable media, and electronic documents? Are employees trained on the risk created by installing network links that are undocumented and not authorised even when the link may be requested by a senior manager? Are employees and contractors prevented from accessing file that would advise when their behaviour is being monitored or attracted special attention? Internal Policies for Software Development 83. Does the organisation have a written policy detailing the steps and procedures 84. 85. 86. 87. for the internal development of software? Does the software development cycle follow guidelines based on industry best practices concerning security? Do corporate security policies require all vendor and contractor personnel working on software development to meet minimum security requirements? Does the organisation have a system for tracking exactly which employee or outside contributor wrote each line of code for any software produced internally? Are commentaries maintained on each section code as it is being written, so that other developers and security specialists can rapidly understand what a given section is designed to do? Security Features/ Testing of New Software 88. Is the application being developed designed to encrypt sensitive information that it stores in a file or database or local system registry? 89. Is the software that the organisation has developed subjected to a code review from a security standpoint, regardless of whether it was outsourced or produced in-house, before the final version is readied for deployment? 90. Does the organisation have information security professionals conduct vulnerability tests of the software it has developed, regardless of whether it was outsourced or produced in-house? 91. Does the organisation have information security specialists conduct regular vulnerability testing against applications as they are deployed? Establishing Appropriate Relationships with Vendors 92. Do organisational policies require vendor personnel to sign non-disclosure agreements? 93. Are software vendors required to certify that their code has undergone a rigorous and thorough security inspection before it is delivered for deployment?

Select target paragraph3