12) How do we educate our employees on cyber and information security
practices?
13) Do we encourage relevant staff members to share cyber security
knowledge and experience with staff members from other organizations?
14) When did we last test the effectiveness of our crisis management?
15) Do we regularly carry out internal controls, audits or revisions within
cyber and information security?
16) How do we ensure that business partners and suppliers protect data and
information that we share with them?
The answers to these questions will enable the top management to identify areas that
need increased focus and efforts. In this way, the questions work as a tool to help the
top management oversee cyber and information security in the organization.
You can find further guidance on understanding and
answering these questions at the website sikkerdigital.dk,
where a number of guides and templates, etc. are freely
available to public authorities, private companies and
citizens.
6