Answer 17 questions and get your SPRS score instantly. Takes 5 minutes.
Limit system access to authorised users
Only authorised employees can access your company systems (computers, email, cloud tools).
Limit system access to authorised functions
Users can only access data and functions their role requires — not everything.
Control information flow on external connections
Your network has a firewall or router that controls what traffic comes in and out.
Separate duties of individuals
No single person has unrestricted access to all critical systems (e.g., approve and pay invoices).
Identify users before allowing access
Every user has a unique username — no shared accounts used.
Authenticate users before allowing access
Users must provide a password (or better — MFA) to access systems.
Sanitise or destroy media before disposal
Old hard drives, USB sticks, and phones are wiped before disposal or reuse.
Limit physical access to authorised individuals
Only authorised people can physically enter your office / server room.
Escort visitors and monitor activity
Visitors to your premises are escorted or supervised while on-site.
Maintain audit logs of physical access
You keep a record (even a sign-in sheet) of who visits your physical locations.
Monitor communications at system boundaries
You have tools that detect unusual network activity (e.g., firewall logs, router alerts).
Implement subnetworks for publicly accessible systems
Your public-facing website/app is separated from your internal business network.
Identify, report, and correct information system flaws
You apply software updates and security patches in a timely manner.
Provide protection from malicious code
All computers and servers have anti-malware / antivirus software installed and updated.
Update malicious code protection mechanisms
Anti-malware definitions are updated automatically or at least weekly.
Perform periodic scans and real-time scanning
You run regular malware scans and have real-time protection enabled.
Monitor information systems to detect attacks
You have some form of monitoring or alerting for potential cyber attacks.