ASSESSMENT / 15 CONTROLS / LOCAL ONLY

Is your incident communication resilient?

Assess five control domains. The result prioritises concrete next steps—without an account, tracking or transmitting your answers.

0/15
01

Governance

01Owners, deputies and escalation authority for critical communication are documented.
02Permitted data classes, retention and deletion are governed per channel.
03Security-relevant changes require approval, evidence and rollback.
02

Identity & devices

01Person, device and session are distinguishable and individually revocable.
02Privileged access uses phishing-resistant sign-in or an equivalent strong factor.
03Roles follow least privilege and temporary access expires automatically.
03

Resilience

01An independent fallback channel with activation criteria is known and exercised.
02Weak connectivity, service interruption and device loss have been workflow-tested.
03Recovery and re-establishment of trust have verifiable states.
04

Evidence

01Security claims are tied to architecture, tests or primary sources.
02Administrative actions and critical state transitions are traceably recorded.
03Pilots separate expectation, observation, impact and decision.
05

Operational workflow

01Critical workflows have bounded rooms, roles and closure criteria.
02Situation, decision, task and acknowledgement are distinguishable in the timeline.
03The communication process is exercised regularly with realistic roles and time pressure.

The assessment stays in this browser. No answers are transmitted or stored.