Cybersecurity is no longer just an IT issue. It’s a strategic imperative for business and government and a core area of risk. Yet many cybersecurity programs aren’t keeping pace with digital transformation, and their budgets aren’t growing as fast as the threats they face.
How much progress has your company made in implementing basic cybersecurity methods, such as the five pillars—Identify, Protect, Detect, Respond, Recover—recommended by the U.S. National Institute of Standards and Technology (NIST) in its cybersecurity framework? Grade yourself from level 1 to 5 in terms of preparation and ongoing vigilance.
RelatedWorkflow Guide: Cyberthreat control and management
Scoring key:
- 1 Undefined: Starting to think about this. No plans in place.
- 2 Ad hoc: Beginning to put plans and processes in place. Taking action but not consistently.
- 3 Defined and repeatable: Using defined processes and plans, and making progress but not yet fully aligned with the business.
- 4 Managed: Continuously monitoring with metrics in place, and seeing considerable benefits.
- 5 Optimized: Fully acted on this activity, ahead of most of our peers, and seeing significant benefits.