TLP WHITE - FINAL
techniques in combination minimizes the risk of over-reliance on single methods of
assessment.
To aid the matching of assessment tool or technique against defined objectives, a process for
tool selection is recommended. As a minimum, this selection process uses factors such as the
importance and inherent risk of entities to the wider sector; the specific nature and scope of
the assessment; the resource and time to be expended on the assessment; and the level of
assurance being sought. To assess the effectiveness of cybersecurity practices, assessors are
recommended to select tools that actively demonstrate capabilities, going beyond a review of
policies and procedures.
Assessment toolkits are evaluated regularly to ensure that they remain fit for purpose. The
applicability of individual tools is regularly monitored and adapted in line with changes in the
threat and business landscape, and the resources at hand.
Component 4: Report clear findings and concrete remedial actions.
Effective cybersecurity assessments deliver meaningful output to drive decisions and actions.
This means developing clear conclusions and identifying concrete remedial measures and/or
thematic findings that can lead to future action.
When drawing a key conclusion, assessors summarize observed practices and achievements,
and identify gaps or shortcomings against expectations as they emerge from the facts
gathered. Assessors describe any associated risks or other issues and the implications therein.
Overall, the output of assessments provides value, supports decision making, and generates
feedback that leads to significant and sustained improvement.
Component 5: Ensure assessments are reliable and fair.
Robust assessment methodologies can ensure reasonable parity between the judgments of
different assessors and an overall consistency in approach. Proportionality further ensures
that assessments performed are practical and realistic.
Assessments are carried out by competent individual(s) with defined skill sets and knowledge
levels. Given the complex and diverse nature of cyber risk, a sound background in IT or
cybersecurity is desirable, together with a deep understanding of the relevant business or
sector. It can be useful to call on assessors that individually or collectively cover multiple
disciplines. Moreover, to keep pace with the evolving landscape, assessors are recommended
to continuously update the required skill sets, through training or other professional activities.
The overall quality of the assessment process is maintained through independent reviews (i.e.
assessing the assessor) of assessments performed and methodologies adopted; knowledge
sharing between assessors; and individual assessor evaluations. To promote fairness and
freedom from bias, entities under assessment are afforded process transparency, whilst being
assured confidentiality of assessment scope, methodology, and findings.
5