Good questions are important tools
The answers to the following questions can give the top management an indication of
whether, and to what extent, appropriate security measures are in place. The top
management and the rest of the organization should to be able to answer the
questions within each category. The sequence of the questions does not reflect any
prioritization of the questions.
8 questions that top management should ask themselves
1) Have we identified data and information that support critical business
activities?
2) What are the consequences for the business, if data or information that
support critical business activities is unavailable, manipulated or leaked?
3) Are we convinced that there is adequate protection of our information
against known threats?
4) Have we defined the cyber and information security objectives,
strategies, and policies that we are actively prioritizing and pursuing?
5) Do we have a security organization anchored at top management level?
6) Do we receive regular reporting on the status of our cyber and
information security strategies and objectives?
7) Have we considered our organization’s security risk appetite?
8) Do we understand that we as members of the top management are
obvious targets of cyberattacks (for example of CEO fraud and spear
phishing)?
16 questions top management should ask their organizations
1) Which IT systems support our business critical activities?
2) Where do we store our most important data and information?
3) How do we keep ourselves updated on the cyber threat landscape and
on the techniques used, among others, in cyber espionage and
cybercrime?
4) How do we defend against phishing attacks and CEO fraud?
5) Are we obligated to comply with external cyber and information security
requirements (for example standards or technical measures)?
6) Which methods do we use to control access to IT systems, data and
information?
7) Which special precautions do we take when travelling?
8) How do we ensure that IT systems, computers and phones are updated?
9) How do we ensure the use of strong passwords to gain access to IT
systems, computers and phones?
10) How do we supervise the use of user accounts with privileged rights?
11) Do we have the skills and resources needed to implement our strategies
and objectives for cyber and information security?
5