Our staff understands cybersecurity risks to our organization.
All of our staff receives cybersecurity training.
Our computers, network, and data have not been hacked or compromised in recent memory.
Our website and social media accounts have not been hacked or compromised in recent memory.
We do not share proprietary or sensitive information on our website or on social media.
We do not struggle when asked for internal documents by 3rd parties (such as legal and information requests).
We utilize, maintain, and share security policies with our staff.
We utilize, maintain, and share travel security policies with our staff.
We utilize, maintain, and share data security policies with our staff.
We do not share sensitive information (such as social security or credit card numbers) via email.
Our organization's key data is backed up regularly.
We have a business continuity plan in place if there is a critical, unplanned system outage.
We have an incident response and recovery plan in place.
Our systems are running current software versions and are patched regularly.
Our systems are able to mitigate emerging threats and attacks.
Our email security system quarantines phishing and malware attacks.
Our staff only acquires and uses software through our organization's approved channels.
Our staff does not share their passwords or keep them written down for others to discover.
Our organization uses multi-factor authentication (2FA) to access critical systems including email.
We have a process to control access and data when a staff member leaves the organization.
We know all of the online services and applications used by our team.
We considered cybersecurity when building our website.
We control who has access to our physical office space and systems.
We use a shredder to dispose of printed information and media.