The outcomes of the CIS18 self-evaluation serve to:
Facilitate a comparative analysis within the Alliance network groups and across the entire Alliance on how members rank their cyber security efforts, particularly in relation to the implementation and policy coverage of the CIS18 Controls.
Utilize these results in juxtaposition with the outcomes of the Assume Breach and Detection tests to ascertain if the employed controls are having their intended mitigative effect, or if their effectiveness warrants further examination.
How to fill out the evaluation questionnaire:
Accumulating the data necessary to accurately respond to all sections of the CIS18 questionnaire can pose a significant challenge for organizations that do not typically undertake such activities or otherwise maintain this perspective and we are aware that it often involves more partakers. Nevertheless, it is acceptable to offer the best effort responses as the CIS18 evaluation of the C-Level Insight Exercise is built on a self-assessment approach where the strength of evidence is inherently low.
Benefits:
Providing these answers will not only bring benefits to the member due to the enhanced consistency in the overall C-Level Insight Exercise outcomes but also can be advantageous to other members within their network group, and to the Alliance as a whole due to the statistics provided on the basis of this.
Incomplete Questionnaire
Some questions are still unanswered and will be set to Not Implemented on submission. Are you sure you want to submit?