Please refer to this guide if you are unsure which answer to select in the Scope of Work questionnaire.
- Q1. Incident Escalation Contacts
- Q2. Confidentiality Agreement
- Q3. Threat Intelligence Sharing
- Q4. Safe Email Handling
- Q5. Incident Reporting Obligations
- Q6. Physical Office Security
- Q7. Important Information Storage
- Q8. Information Disposal
- Q9. Data Backup
- Q10. Malware Protection
- Q11. Patch Management
- Q12. Authentication and Password Management
- Q13. Data Sharing and Access Control
- Q14. Web Usage and Upload Restrictions
Q1. Incident Escalation Contacts
Question
Do you have established contact points, response procedures, and communication routes for security incidents (such as theft, loss, or misdirected emails)?
Answer Options
- ◯ Established and regularly reviewed
- △ Established
- ✕ Not established
Answer Guide
|
Employees are informed of what
|
→ No → | ✕ Not established |
| ↓ Yes | ||
|
Contact information is regularly
|
→ No → | △ Established |
| ↓ Yes | ||
|
◯ Established and regularly reviewed
|
Q2. Confidentiality Agreement
Question
Do you obtain confidentiality agreements from employees and temporary staff?
Answer Options
- ◯ Operational rules and templates prepared, consent obtained
- △ No rules/templates but consent obtained
- ✕ Consent not obtained
Answer Guide
|
Written agreements are obtained
|
→ No → | ✕ Consent not obtained |
| ↓ Yes | ||
|
The company has a template
|
→ No → | △ No rules/templates but consent obtained |
| ↓ Yes | ||
|
◯ Operational rules and templates prepared,
|
Q3. Threat Intelligence Sharing
Question
Do you collect and share information about security incidents and latest trends? (e.g., cases of damage at other companies, information on the latest attack methods, news and recent cases related to cyberattacks)
Answer Options
- ◯ Regularly collected and shared
- △ Irregularly collected and shared
- ✕ Not collected or shared
Answer Guide
|
|
→ All apply → | ◯ Regularly collected and shared |
| ↓ No | ||
|
|
→ Any applies → | △ Irregularly collected and shared |
| ↓ None apply | ||
|
✕ Not collected or shared
|
Q4. Safe Email Handling
Question
Do you warn others to handle email attachments and URLs with caution, being aware of the risk of malware infection?
Answer Options
- ◯ Warning others
- ✕ Not warning others
Answer Guide
|
|
→ No → | ✕ Not warning others |
| ↓ All apply | ||
|
◯ Warning others
|
Q5. Incident Reporting Obligations
Question
Do you have agreements with vendors for prompt reporting of security incidents?
Answer Options
- ◯ Required for all vendors
- △ Required for some vendors
- ✕ Not required
- - No external subcontractors are used
Answer Guide
|
External subcontractors are used
|
→ No → | - No external subcontractors are used |
| ↓ Yes | ||
|
|
→ All apply → | ◯ Required for all vendors |
| ↓ No | ||
|
|
→ Any applies → | △ Required for some vendors |
| ↓ None apply | ||
|
✕ Not required
|
Q6. Physical Office Security
Question
Do you implement security measures such as access control and locking?
Answer Options
- ◯ Rules established and implemented
- △ No rules but implemented
- ✕ Not implemented
Answer Guide
|
Entries and exits are always recorded,
|
→ No → | ✕ Not implemented |
| ↓ Yes | ||
|
Both entry/exit recording and locking
|
→ No → | △ No rules but implemented |
| ↓ Yes | ||
|
◯ Rules established and implemented
|
Q7. Important Information Storage
Question
Do you store documents and devices containing important information in locked storage?
Answer Options
- ◯ Rules established and implemented
- △ No rules but implemented
- ✕ Not implemented
Answer Guide
|
Your company's important information
|
→ No → | ✕ Not implemented |
| ↓ Yes | ||
|
A clear desk practice is followed
|
→ No → | ✕ Not implemented |
| ↓ Yes | ||
|
A clear desk practice when leaving
|
→ No → | △ No rules but implemented |
| ↓ Yes | ||
|
◯ Rules established and implemented
|
Q8. Information Disposal
Question
Do you have established disposal methods and dispose of documents and media containing important information in a way that prevents third parties from recovering the data (e.g., shredding, dissolution, data erasure)?
Answer Options
- ◯ Disposal method defined, disposed unrecoverably
- △ No disposal method but disposed unrecoverably
- ✕ No disposal method, no special attention
Answer Guide
|
Both paper and electronic media
|
→ No → | ✕ No disposal method, no special attention |
| ↓ Yes | ||
|
Disposal/erasure procedures for both
|
→ No → | △ No disposal method but disposed unrecoverably |
| ↓ Yes | ||
|
◯ Disposal method defined,
|
Q9. Data Backup
Question
Do you regularly back up important information?
Answer Options
- ◯ Regular backups taken and verified
- △ Irregular backups taken and verified
- ✕ No backups
- - No important information has been entrusted
Answer Guide
|
You hold information entrusted
|
→ No → | - No important information has been entrusted |
| ↓ Yes | ||
|
|
→ All apply → | ◯ Regular backups taken and verified |
| ↓ No | ||
|
|
→ Any applies → | △ Irregular backups taken and verified |
| ↓ None apply | ||
|
✕ No backups
|
Q10. Malware Protection
Question
Do you have antivirus software installed on all devices with up-to-date pattern files?
Answer Options
- ◯ Installed
- ✕ Not installed
Answer Guide
|
|
→ No → | ✕ Not installed |
| ↓ All apply | ||
|
◯ Installed
|
Q11. Patch Management
Question
Do you promptly apply security patches and keep all devices up to date?
Answer Options
- ◯ Always up to date
- △ Irregularly updated
- ✕ Not updated
Answer Guide
|
|
→ All apply → | ◯ Always up to date |
| ↓ No | ||
|
|
→ Any applies → | △ Irregularly updated |
| ↓ None apply | ||
|
✕ Not updated
|
Q12. Authentication and Password Management
Question
Do you have password rules regarding length and complexity?
Answer Options
- ◯ Rules established and implemented
- △ No rules but individually implemented
- ✕ Not implemented
Answer Guide
|
|
→ All apply → | ◯ Rules established and implemented |
| ↓ No | ||
|
|
→ Any applies → | △ No rules but individually implemented |
| ↓ None apply | ||
|
✕ Not implemented
|
Q13. Data Sharing and Access Control
Question
Do you properly set access permissions on shared folders?
Answer Options
- ◯ Rules established and configured
- △ No rules but configured
- ✕ Not configured
Answer Guide
|
|
→ All apply → | ◯ Rules established and configured |
| ↓ No | ||
|
|
→ Any applies → | △ No rules but configured |
| ↓ None apply | ||
|
✕ Not configured
|
Q14. Web Usage and Upload Restrictions
Question
Do you restrict access to suspicious sites and inappropriate data uploads?
Answer Options
-
◯ Restricted by rules or technical measures
(e.g., filtering, use of proxy services) - △ No rules but restricted by technical measures
- ✕ Not restricted
Answer Guide
|
Access to suspicious or non-business
|
→ No → | ✕ Not restricted |
| ↓ Yes | ||
|
Rules such as prohibiting access to
|
→ No → | △ No rules but restricted by technical measures |
| ↓ Yes | ||
|
◯ Restricted by rules or technical measures
|