Conducting a quick risk assessment
A quick risk assessment aims to provide a high-level overview of your organization’s information security status. It is not intended to replace a more detailed risk assessment but can be helpful as a preliminary evaluation. You can use the results of this assessment to provide a pulse check to your management and give them an idea of what to expect regarding information security risk.
To use this assessment, answer each question with a yes, unsure, or no response, and assign 5 points for yes, 5 for unsure, and 0 for no. The following are the questions that you should consider when conducting this quick risk assessment:
- Does your organization use an internal unsecured guest wireless network?
- Does your organization allow the use of personal devices on the organizational network?
- Does your organization enable high-risk information systems connected to the internet?
- Is your organization unable to securely dispose of sensitive...