OT Cybersecurity Posture Assessment Framework
85%
Questions marked with a
*
are required
Please select your Industry Vertical
-- Select --
Transportation
Industrial Products
Hitech & Telecommunication
FMCG / Chemicals
Healthcare
Oil & Gas
Other
Rate your organization's capabilities around
# Assets refer to data, personnel, devices, systems, and facilities that enable the organization to achieve business purposes
# Operational Cybersecurity Strategy refers to an organization's priorities, constraints, risk tolerances, and assumptions
Very Poor
Very Good
1
2
3
4
5
Assets inventoried and monitored
1
Very Poor
2
3
4
5
Very Good
Comprehensiveness of Information Security policy
1
Very Poor
2
3
4
5
Very Good
Identify and document asset vulnerabilities
1
Very Poor
2
3
4
5
Very Good
Operational Cybersecurity Strategy is established and used to support operational risk decisions
1
Very Poor
2
3
4
5
Very Good
Identities and credentials are managed for authorized assets
1
Very Poor
2
3
4
5
Very Good
Rate your organization's capabilities around
#IC - Industrial control systems
#IT - Information Technology Systems
Very Poor
Very Good
1
2
3
4
5
Access to important assets and associated facilities are restricted
1
Very Poor
2
3
4
5
Very Good
Cybersecurity awareness education of personnel and partners
1
Very Poor
2
3
4
5
Very Good
Cybersecurity management policies of Information and records (data)
1
Very Poor
2
3
4
5
Very Good
Comprehensive and Periodic Backup of all IC and IT systems
1
Very Poor
2
3
4
5
Very Good
Policies/ Procedures for IC & IT components
1
Very Poor
2
3
4
5
Very Good
Audit/log records are determined, documented, implemented, and reviewed
1
Very Poor
2
3
4
5
Very Good
Rate your organization's capabilities
Very Poor
Very Good
1
2
3
4
5
Detected events are analyzed to understand attack targets and methods
1
Very Poor
2
3
4
5
Very Good
The networks are monitored to detect potential cybersecurity events
1
Very Poor
2
3
4
5
Very Good
Roles and responsibilities for detection are well defined to ensure accountability
1
Very Poor
2
3
4
5
Very Good
Rate your organization's capabilities
1
2
3
4
5
Response processes and procedures are executed and maintained, to ensure timely response
1
2
3
4
5
Personnel know their roles and order of operations when a response is needed
1
2
3
4
5
Analysis is conducted to ensure adequate response and support recovery activities
1
2
3
4
5
In case of an event, activities are performed to prevent expansion, ensure eradication, and drive mitigation effects
1
2
3
4
5
Rate your organization's capabilities around
Very Poor
Very Good
1
2
3
4
5
Recovery processes and procedures are executed and maintained to ensure timely restoration
1
Very Poor
2
3
4
5
Very Good
Recovery planning and processes are improved by incorporating lessons learned
1
Very Poor
2
3
4
5
Very Good
Next
Powered by
QuestionPro
Loading...
close
drag_indicator
close
Yes
Cancel
Continue
Answer Question
Continue Without Answering
Keep Data
Discard
close