TLP WHITE - FINAL techniques in combination minimizes the risk of over-reliance on single methods of assessment. To aid the matching of assessment tool or technique against defined objectives, a process for tool selection is recommended. As a minimum, this selection process uses factors such as the importance and inherent risk of entities to the wider sector; the specific nature and scope of the assessment; the resource and time to be expended on the assessment; and the level of assurance being sought. To assess the effectiveness of cybersecurity practices, assessors are recommended to select tools that actively demonstrate capabilities, going beyond a review of policies and procedures. Assessment toolkits are evaluated regularly to ensure that they remain fit for purpose. The applicability of individual tools is regularly monitored and adapted in line with changes in the threat and business landscape, and the resources at hand. Component 4: Report clear findings and concrete remedial actions. Effective cybersecurity assessments deliver meaningful output to drive decisions and actions. This means developing clear conclusions and identifying concrete remedial measures and/or thematic findings that can lead to future action. When drawing a key conclusion, assessors summarize observed practices and achievements, and identify gaps or shortcomings against expectations as they emerge from the facts gathered. Assessors describe any associated risks or other issues and the implications therein. Overall, the output of assessments provides value, supports decision making, and generates feedback that leads to significant and sustained improvement. Component 5: Ensure assessments are reliable and fair. Robust assessment methodologies can ensure reasonable parity between the judgments of different assessors and an overall consistency in approach. Proportionality further ensures that assessments performed are practical and realistic. Assessments are carried out by competent individual(s) with defined skill sets and knowledge levels. Given the complex and diverse nature of cyber risk, a sound background in IT or cybersecurity is desirable, together with a deep understanding of the relevant business or sector. It can be useful to call on assessors that individually or collectively cover multiple disciplines. Moreover, to keep pace with the evolving landscape, assessors are recommended to continuously update the required skill sets, through training or other professional activities. The overall quality of the assessment process is maintained through independent reviews (i.e. assessing the assessor) of assessments performed and methodologies adopted; knowledge sharing between assessors; and individual assessor evaluations. To promote fairness and freedom from bias, entities under assessment are afforded process transparency, whilst being assured confidentiality of assessment scope, methodology, and findings. 5

Select target paragraph3