Beenet

|  Secure by Design

< Back

Secure by Design Foundation Assessment

Does the capability have a formal process for escalating risks it cannot treat?

No
Yes

Has the capability assessed supply chain risks at every stage in the lifecycle?

No
Yes

Has the capability created and maintained a comprehensive asset list ?

No
Yes

Do assets include conceptual as well as physical?

No
Yes

Have the capability's assets been valued?

No
Yes

Has the capability been given a clear scope for decision making set by the risk owner?

No
Yes

Is the capability scope agreed with other capabilities in your environment (i.e. dependent capabilities and those that work alongside)?

No
Yes

Has the capability identified the classifications that will be stored, processed or transmitted?

No
Yes

Has the capability identified information types that will be stored, processed or transmitted?

No
Yes

Has the capability agreed the information types with the risk owners?

No
Yes