☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
Incident Handling and Response
81. Do staff know how, when and where to report a breach of company policy and or
☐
☐
a possible cyber-attack?
82. Do employees know how to isolate and quarantine compromised systems by
removing them from the network?
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
☐
72. Are employees trained not to store passwords in insecure places such as their
73.
74.
75.
76.
77.
78.
79.
80.
wallet, purse, or post-it-note on their computer?
Are employees trained/reminded of what type of information handled by the
organisation should be regarded as sensitive information?
Are employees trained/reminded to save sensitive/critical data to a server where
it’s being backed up?
Are employees trained to be suspicious of any software that arrives in the mail,
even where it appears to be packaged by a trusted vendor?
Are employees regularly trained not to download executable code, not to open
suspect emails, and not to install personal software on computer systems?
Are employees trained not to visit illicit websites including file
sharing/downloading websites?
Are your employees able to identify and protect classified data, including paper
documents, removable media, and electronic documents?
Are employees trained on the risk created by installing network links that are
undocumented and not authorised even when the link may be requested by a
senior manager?
Are employees and contractors prevented from accessing file that would advise
when their behaviour is being monitored or attracted special attention?
Internal Policies for Software Development
83. Does the organisation have a written policy detailing the steps and procedures
84.
85.
86.
87.
for the internal development of software?
Does the software development cycle follow guidelines based on industry best
practices concerning security?
Do corporate security policies require all vendor and contractor personnel
working on software development to meet minimum security requirements?
Does the organisation have a system for tracking exactly which employee or
outside contributor wrote each line of code for any software produced internally?
Are commentaries maintained on each section code as it is being written, so that
other developers and security specialists can rapidly understand what a given
section is designed to do?
Security Features/ Testing of New Software
88. Is the application being developed designed to encrypt sensitive information that
it stores in a file or database or local system registry?
89. Is the software that the organisation has developed subjected to a code review
from a security standpoint, regardless of whether it was outsourced or produced
in-house, before the final version is readied for deployment?
90. Does the organisation have information security professionals conduct
vulnerability tests of the software it has developed, regardless of whether it was
outsourced or produced in-house?
91. Does the organisation have information security specialists conduct regular
vulnerability testing against applications as they are deployed?
Establishing Appropriate Relationships with Vendors
92. Do organisational policies require vendor personnel to sign non-disclosure
agreements?
93. Are software vendors required to certify that their code has undergone a rigorous
and thorough security inspection before it is delivered for deployment?