This free survey is powered by QUESTIONPRO.COM
0%
Exit Survey »
 
 
In April 2012, the ICT Board approved the following standards:

Web Server Security Standard
Web Application Security Standard

As part of this process, the Board requires the Office of the Chief Information Officer to provide it with an assurance that these standards are being adopted by agencies.

The first stage in this process is the collection of information about the current level of maturity amongst agencies. The survey below is intended to provide an indication to the Board of the starting position within agencies. The information collected will be provided in a summary form without identifying data from individual agencies.

It will be followed up at a later date with a more detailed survey, addressing the different areas covered by the standards.

To enable a report to be provided to the Board this year, please complete the survey by the 28th June 2013.


Thank you very much for your time. Please start the survey now by clicking on the Continue button below.

 
 
 
How to answer the questions.
 
 
For some questions, you will be given 5 options:

1 Initial
ad hoc and poorly controlled processes
2 Repeatable
some processes are repeatable, but not well managed
3 Defined
includes well-defined processes, consistent with business needs
4 Managed
processes are measurable and controlled
5 Optimising
strong management focus and continuous process improvement

Where a question gives these options, please select the one that best describes the current approach to the activity.
You can view this explanation by clicking on the Help icon next to each question. Further information can be obtained on the ISACA website.

At the end of each section, you can provide any additional comments you care to make.
 
 
 
* Please provide your name:
   
 
 
* and your agency:
   
 
 
 
Identifying the risks.
 
* How would you describe your agency's approach to the use of penetration/vulnerability testing?
 
Initial
 
Repeatable
 
Defined
 
Managed
 
Optimising
 
* What is your agency's approach to undertaking risk assessments of your web systems?
 
Initial
 
Repeatable
 
Defined
 
Managed
 
Optimising
 
* What is your agency's approach to classifying the data accessed by your web systems?
 
Initial
 
Repeatable
 
Defined
 
Managed
 
Optimising
 
* What is the agency's approach to providing the assessments to the Business owners so they can examine and either accept or reject these?
 
Initial
 
Repeatable
 
Defined
 
Managed
 
Optimising
 
* What is the agency's approach to providing the assessments to the Agency Security Executive (or similar role) for endorsement?
 
Initial
 
Repeatable
 
Defined
 
Managed
 
Optimising
 
 
Have you any additional comments about identifying the risks?
   
 
 
Remedial action
 
 
* What stage has the agency reached in preparing an implementation plan to remedy any unacceptable risks arising from the assessments?
 
Haven't started
 
In progress
 
Plan is finished but no action yet to implement
 
Plan completed and partly implemented
 
Completely implemented
 
N/A - no issues identified
 
 
* What has been the involvement of the Business owners in the development of this plan?
 
No involvement - no issues identified
 
None yet - haven't started on the plan
 
Have been advised of progress but no input
 
Have been consulted
 
Have driven the process
 
They have approved the completed plan
 
Other
 

 
 
* Has your Agency Security Executive (or similar role) endorsed the plan?
 
Yes
 
No
 
We haven't yet completed a plan
 
Other
 
 
 
* Has your CIO endorsed the plan?
 
Yes
 
No
 
We haven't yet completed a plan
 
Other
 
 
 
* Please comment on the start date to begin the remedial action contained in the plan?
   
 
 
* Please comment on the finish date for completion of the remedial action contained in the plan?
   
 
 
Have you any additional comments about the remedial action required?
   
 
 
Ongoing activities
 
 
* Has the agency implemented appropriate changes to its ongoing processes to comply with the new standards?
 
Yes
 
No
 
Other
 
 
 
* When will these new processes be fully adopted?
 
Already adopted
 
within 12 months
 
Later than 12 months
 
No plans at this stage to introduce any
 
Other
 
 
* What is your agency's approach to a continuous monitoring regime for your web presence?
 
Initial
 
Repeatable
 
Defined
 
Managed
 
Optimising
 
 
Have you any additional comments about ongoing activities?
   
 
 
 
* Have you discussed these answers with your Agency Security Executive (or similar role)?
 
Yes
 
No
 
I am the ASE
 
 
 
Please add any further comments you may have about the overall process
and any constraints, risks or opportunities you foresee:
   
 
Survey Software Powered by QuestionPro Survey Software