Who manages the maintenance and security of the I.T. infrastructure?
If yes — list outsourced provider names, contact information, and services performed
Which domain names do you own? Who manages the registrations and DNS records?
If other email provider — how is it backed up?
Who maintains the asset inventory? Is it automated?
What is your backup / disaster recovery / business continuity solution?
Who monitors the backups?
Which devices are backed up?
How often are backups performed?
How often are restores tested?
Primary internet provider name
Download speed
Upload speed
If yes — what is the failover solution?
Telecom provider
Telecom system type and manufacturer
If yes — which regulations?
If yes — which audits and when?
Who develops and maintains your web presence? Who is your hosting provider?
If yes — which monitoring platform is deployed and who receives alerts?
If yes — which access control system?
If yes — where are cameras located? Is there a DVR component?
If yes — which platform?
What is your line of business (LOB) application? Who supports it?
What other applications are in use for ERP, production, accounting, HR, etc.?
Schedule for applying critical patches:
If not all current — please describe exceptions:
If yes — which solution?
How often do you review installed software for approved-applications compliance?
If yes — subcontractor names and companies:
If no — which devices have unsupported operating systems?
If yes — how many and which ones?
Number of access points:
Wireless AP make and model:
Wireless encryption in use:
Which Endpoint Protection solution is deployed? Does it qualify as EDR (Endpoint Detection and Response)?
What firewalls do you have in place? Include makes, models, support subscriptions, and firmware status.
Are the MDF(s) and IDF(s) physically secured? How? Climate controlled? Temperature/humidity/water sensors?
If yes — which fire detection/suppression solution?
If yes — which video conferencing solution?
When devices are retired, how are they securely disposed of?
If yes — list providers, services, and datacenter locations:
Who has administrative privileges in Active Directory and for other I.T. assets?
If yes — which MFA solution?
Which systems are protected by MFA?
If yes — what work is performed on personal devices?
Minimum password length
Password complexity requirements
Password aging / expiration
Password re-use restriction
Account lockout policy
Auto-lock workstation after inactivity
For each solution selected above, provide the service provider and description:
If yes — which solution and how often is it required?
If yes — which MDM platform?
If yes — which password manager?
If yes — which SSO solution?
If yes — email archive provider:
If yes — other archive provider:
If yes — please describe the process:
If yes — which DLP solution?
If yes — how often and who performs them?
If yes — how often and who performs them?
If yes — which SIEM, and does it include a 24/7/365 SOC?
If yes — please describe which credentials are shared and with whom:
What is your remote access strategy? How do employees work when out of the office?
If not fully encrypted/MFA — please explain exceptions:
If yes — who are they, and how is access monitored and controlled?
If yes — describe your classification scheme:
If yes — which cloud repositories?
If yes — how and where is PII stored? Is it encrypted?
How do you transmit or share protected information (PII, PHI, confidential data)? Is it encrypted in transit and at rest?
If yes — how often are MFP disks wiped?
Additional notes or information you'd like to share:
Your Name *
Email Address *
Company Name *
Title / Role
Phone Number
Date Completed