AFRISCONBack home

Security assessment quiz

Measure your cybersecurity maturity and ISO 27001 readiness.

Answer a short set of questions to estimate your security maturity, identify weak areas and understand how close your organization is to an ISO 27001-ready baseline.

1. Governance

ISO 27001 clauses 4, 5 and 6

Information security roles, responsibilities and leadership commitment are clearly defined.

2. Risk management

ISO 27001 clause 6.1

Security risks are identified, assessed, treated and reviewed on a regular basis.

3. Policies

ISO 27001 Annex A organizational controls

Security policies and procedures are documented, approved and communicated to relevant teams.

4. Asset management

ISO 27001 Annex A asset and information controls

Critical assets, owners, data types and business applications are inventoried and classified.

5. Identity and access

ISO 27001 Annex A access controls

Access rights are granted, reviewed and removed according to business need and least privilege.

6. Identity and access

ISO 27001 Annex A authentication controls

Multi-factor authentication is enforced for privileged, remote and sensitive access.

7. People security

ISO 27001 clause 7 and Annex A people controls

Employees receive security awareness training and phishing guidance at least annually.

8. Technical security

ISO 27001 Annex A technology controls

Vulnerabilities are tracked, prioritized and remediated through a defined patch process.

9. Monitoring

ISO 27001 Annex A logging and monitoring controls

Security logs are collected, protected and reviewed for suspicious activity.

10. Incident response

ISO 27001 Annex A incident management controls

Incident response roles, escalation paths and playbooks are documented and tested.

11. Continuity

ISO 27001 Annex A business continuity controls

Backups, recovery objectives and crisis procedures are tested against realistic scenarios.

12. Continual improvement

ISO 27001 clauses 9 and 10

Security performance, audits, corrective actions and improvement plans are regularly reviewed.

AFRISCON advisory

Turn the result into a practical ISO 27001 roadmap.

AFRISCON can perform a formal gap assessment, define the ISMS roadmap, prepare documentation and support implementation until internal audit readiness.

Request a maturity assessment