Performing the assessment
There are three different ways an assessment can be performed; these are first-, second-, and third-party assessments. Each of these is distinct in the way they are performed, but they ultimately all get to the same result. These assessments are meant to discover deficiencies in your program. These deficiencies can then be turned into objectives or projects to improve your cybersecurity posture.
First-party assessments
A first-party assessment can be a fun and exciting way of getting to know your environment. The first-party assessment is performed by either you, your team, or an internal audit department within your organization. An assessment of this kind can highlight many of the things you are doing right but also help identify gaps in your program.
A downside to performing a first-party assessment is that it may not be as acceptable as a third-party assessment. This is because a first-party assessment is performed by you or your organization...