Skip to content
01. Can you list everything that will be in scope?

The whole organisation unless a sub-set is technically separated. Every site, every home worker, every device and every cloud service that touches organisational data.

02. Have you included personally owned devices used for work?

A personal phone or laptop that accesses work email, files or applications is in scope. A device used only for calls, texts and authentication codes is not.

03. Have you listed every cloud service, not just the obvious ones?

Email and file storage are remembered. The accounting package, the customer relationship system and the tool somebody signed up for on a trial are the ones that get missed.

04. Is there a firewall between your network and the internet, and is it configured deliberately?

Includes the router or firewall at each site, and the software firewall on devices used away from the office.

05. Have default accounts, default passwords and unnecessary software been removed?

Applies to devices, servers, firewalls, network equipment and cloud services alike.

06. Are high and critical security updates applied within 14 days?

Operating systems, applications, browsers, plug-ins and firmware. Every day of the year, not just before assessment.

07. Is everything in scope still receiving vendor security updates?

Software past its support date cannot stay inside the boundary. This is the finding that cannot be fixed in a hurry.

08. Does every user have their own named account?

Shared logins mean no accountability and no way to remove one person's access.

09. Are administrator accounts separate from everyday accounts, everywhere?

This means separate accounts on end user devices, on servers, and on every cloud service you administer. Administrative accounts must not be used for email or web browsing.

10. Are leavers and unused accounts removed promptly?

Including accounts held by former staff, past contractors and suppliers who no longer work with you.

11. Is multi-factor authentication enabled on every cloud service?

Not just email. Every cloud service in scope, and on administrative accounts in particular.

12. Is every in-scope device protected against malware?

The appropriate method depends on the device, and mobile devices may be handled differently from laptops.

13. Can you evidence these answers rather than assert them?

A board member or equivalent has to confirm the answers are true, so they need to be verifiable.

14. Do you know who will answer the technical questions, and by when?

Whether that is you, an internal team or an external provider, and whether a deadline applies.

Use the current requirements

A starting point, not the official questions.

Confirm actual scope and current requirements before completing the official self-assessment.

Read IASME’s scheme guidance →