How to use this checklist
For each statement, record Yes, Partly, No or Unknown. Treat “Unknown” as a finding: it normally means ownership or evidence is unclear. Add an owner and target date for every Partly, No or Unknown response.
1. Governance and accountability
- Leadership has approved the organisation's security objectives and risk appetite.
- Material cyber risks have named business owners, not only technical owners.
- Executive reporting shows decisions, overdue actions, incidents and residual risk.
- Security responsibilities are included in relevant roles, projects and supplier relationships.
- Policies are reviewed, communicated and supported by operating procedures.
2. Assets, data and risk
- Essential services, systems, applications, cloud resources and information assets are inventoried.
- Dependencies and critical suppliers are mapped to important business services.
- Information-security risks use defined likelihood, impact and acceptance criteria.
- Treatment actions have accountable owners, dates and evidence of completion.
- Changes to systems and services trigger security and privacy review.
3. Identity, systems and vulnerability management
- Privileged access is restricted, reviewed and protected with strong authentication.
- Joiner, mover and leaver processes remove unnecessary access promptly.
- Secure configuration standards exist for endpoints, servers, network and cloud services.
- Vulnerabilities are prioritised by exploitability, exposure and business impact.
- Independent security testing is scoped, authorised, remediated and retested.
4. Detection, incidents and continuity
- Logs from priority systems reach an accountable monitoring process.
- Detection use cases reflect likely threats to essential services and sensitive data.
- Incident roles, severity levels, escalation contacts and decision authority are documented.
- Exercises test technical response, leadership decisions, communications and recovery.
- Backups and recovery procedures are protected and tested against defined objectives.
5. ISO 27001 readiness
- The proposed ISMS scope, context and interested parties are documented.
- A repeatable risk assessment and treatment method is approved and used.
- The Statement of Applicability reflects actual risk treatment and control decisions.
- Every applicable control has an owner and current operating evidence.
- Internal audit and management review are planned before certification assessment.
6. DPDPA and privacy operations
- Personal-data categories, purposes, systems, recipients, processors and retention are mapped.
- Notices and consent choices accurately describe the processing that occurs.
- Requests, grievances and withdrawal of consent can be authenticated, assigned and evidenced.
- Processor contracts and oversight address security, assistance, deletion and incidents.
- Privacy incidents connect to the organisation's wider response and decision process.
7. Suppliers and assurance
- Supplier criticality influences due diligence and contractual security requirements.
- Assurance evidence is reviewed rather than collected without evaluation.
- Contracts define incident reporting, access, data handling and exit obligations.
- Material supplier changes and concentration risks reach accountable governance forums.
- Exit plans protect data availability, return, deletion and operational continuity.
Turn answers into a 30-day action plan
- Select the ten gaps with the greatest effect on essential services, sensitive data or regulatory exposure.
- Assign one accountable owner and one measurable completion condition to each gap.
- Separate quick corrections from changes requiring budget, procurement or architecture decisions.
- Collect evidence as work is completed rather than immediately before an audit.
- Review progress with leadership at the end of the month and approve the next risk-based cycle.