Fill out the questionnaire and assess your compliance with NIS2 and strengthen your company's cybersecurity, with our support at every stage of the process.
Assess compliance with NIS2 and strengthen your company's cybersecurity with our support at every stage of the process.
1. Do management bodies actively participate in, control, monitor, and approve information and communication technology policies and processes?
2. Do management bodies regularly participate in training on information security, cybersecurity, major ICT threats and risks, among other topics?
3. Does the organization have Information Security and Cybersecurity Policies and Processes?
4. Does the organization have a dedicated officer (CISO) or an Information Security and Cybersecurity Committee?
5. Does the organization conduct periodic reviews of ICT policies, processes, and procedures?
6. Does the organization conduct Independent Assessments (External Audits) focused on identifying improvements in ICT policies, processes, and procedures?
7. Does the organization have key performance indicators (KPIs) that are reported to management bodies on a regular basis and focused on continuous improvement of the ICT ecosystem?
8. Does the organization already have certifications in the area of Security or Cybersecurity (e.g., ISO27001, ISO22301, Digital Seal, QNRCS, etc.)?
9. Does the organization have a Technology Asset Management Policy and Processes?
10. Does the organization have a Policy and Processes for Managing Entities and Physical, Logical, and Remote Access, as well as Teleworking?
11. Does the organization have Communications Security Policies and Processes?
12. Does the organization have Multi-Factor Authentication (2FA, MFA) procedures for employees and ICT suppliers?
13. Does the organization have ICT Risk Management Policies and Processes?
14. Does the organization have an ICT Risk Management Framework?
15. Does the organization have a Technology Vulnerability Management Policy and Processes?
16. Does the organization have ICT Secure Configuration Policies and Processes?
17. Does the organization have Encryption Management and Password Management Policies and Processes?
18. Does the organization have a Data Privacy Policy and Processes?
19. Does the organization have an Information Classification Policy and Processes?
20. Does the organization have an Information Transfer Policy and Processes?
21. Does the organization have Training and Awareness Procedures and Controls for employees and ICT suppliers?
22. Does the organization have Human Resources Policies and Processes?
23. Does the organization have Secure Development and Change Management Policies and Procedures?
24. Does the organization have Acceptable Use and User Acknowledgment Policies and Procedures?
25. Does the organization have mechanisms in place to detect, report, and record suspicious or anomalous activities, failures, and errors related to critical ICT networks, devices, and systems?
26. Does the organization have Information Security and Cybersecurity Incident Management Policies and Processes?
27. Does the organization have defined procedures for reporting critical information security and cybersecurity incidents?
28. Does the organization have Processes and Procedures for Recording Lessons Learned?
29. Does the organization have ICT Change Management Policies and Processes?
30. Does the organization participate (or have plans to participate) in mechanisms for sharing information about cyber threats and ICT vulnerabilities?
31. Does the organization have a Business Continuity Management Policy and Processes?
32. Does the organization have Backup Management Policies and Processes?
33. Does the organization perform Penetration Tests (Pentests) on Critical ICT Systems and/or Applications?
34. Does the organization periodically conduct ICT operational resilience tests?
35. Does the organization have a Policy and Processes for Managing Suppliers and Technology Service Providers?
36. Are security risk assessments conducted on critical ICT service providers/suppliers prior to contracting and on a regular basis?
For more information on the processing of personal data, please refer to MEO's Personal Data Protection Policy.