Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Free · FRM-RDY-001

Find out what you could prove, before someone asks you to

Eighty questions across ten areas. Every control is asked twice: do you do this, and could you prove it today. The distance between those two answers is the thing that decides how a questionnaire, an insurer or an audit actually goes.

Questions
80, across 10 areas
Time
About 90 minutes
Format
Excel workbook, yours to keep
Cost
Free. No account, no card, no email

Why twice

Doing it and proving it are different questions

Most self-assessments ask whether you have a control. That is the easy question, and almost everyone says yes. The one that decides a questionnaire, an insurance renewal or an audit is whether you could put the evidence in front of someone this afternoon.

What the workbook records

  • Whether you do it: yes, partly, no, or nobody knows.
  • Whether you could prove it: within minutes, with some effort, no, or nobody knows.
  • Whether the control applies to you at all, decided from your business profile.
  • A gap classification and a priority, calculated for every question.

What it deliberately does not do

  • It is not an audit. These are your own answers. An assessor will want the evidence behind them.
  • It is not a certification and it will not satisfy a customer on its own.
  • It does not send anything anywhere. There is no account and nothing phones home. Fill it in offline if you prefer.
  • It does not sell you anything. A large number of people should read their result and do nothing else.

What is in it

Seven sheets, and the arithmetic is already done

About your business

Nine questions about size, sites, card payments, who runs your IT and what data you hold. These switch off the questions that do not apply, so you are not scored against controls you have no reason to have.

The assessment

Eighty questions, each with a line explaining why it matters and what usually goes wrong. Answered with dropdowns, not free text, so the scoring works.

Your results

Calculated, not typed. How many controls you believe are in place, how many you could prove, and the gap between them, which is the number to read first.

Your action list

The twenty highest-priority items, ranked automatically from your answers. Not a list of everything wrong, a list of what to do on Monday.

A worked example

A fictional supermarket chain, filled in, scored, and annotated with what a real assessment found afterwards. Read it first if you want to see where this goes.

A cover you can send on

Document control block, identifier and version, so it reads as a controlled document rather than a spreadsheet somebody made. Board packs and insurers care about that.

The ten areas

What the eighty questions cover

AreaQuestions
1. Who is in charge of security7
2. Your IT provider and suppliers8
3. Knowing what you have7
4. Who can get into your systems11
5. Your people6
6. Protecting your information9
7. Card payments and customer data6
8. Keeping systems protected8
9. Would you notice7
10. If it happened tomorrow11

Mapped to the six NIST CSF 2.0 functions, including Govern. Questions about card payments switch off if you do not take them, and the same is true of several others.

What people find

The gap is almost always bigger than expected

The worked example in the workbook is a fictional six-store supermarket chain. It scores 53 of 80 controls believed in place, 15 that could be proved on the day, and eleven questions where nobody in the room knew the answer. That shape is ordinary. The evidence gap is where an assessment, a questionnaire or an insurer will land, and it is almost never where people expect.

When you have a score

Send it to us and we will go through it, at no charge

Forty-five minutes on the result: what the gap actually means, what we would fix first, and whether any of it needs paying for. If our honest view is that you do not need an engagement yet, we will say so. Plenty of people take the assessment and never speak to us, which is a perfectly good outcome.