UpCISO
← All free tools

Free tool · Built on UpCISO’s product logic

Security readiness checklist

A focused starting point for CMMC and NIST SP 800-171 readiness. Eight questions, not a complete assessment. Answers remain self-reported.

01 Do you have formal procedures for establishing, activating, modifying, reviewing, disabling, and removing user accounts?

Account management ensures that access is granted based on valid authorization, least privilege principles, and organizational need. This includes periodic review of accounts.

02 Are user privileges limited to the minimum necessary to perform assigned tasks (principle of least privilege)?

Least privilege reduces the attack surface by ensuring users only have access to resources needed for their job functions. This includes limiting administrative privileges.

03 Do you require multifactor authentication for local and network access to privileged accounts, and for network access to non-privileged accounts?

IA.L2-3.5.3 has three parts: privileged accounts need MFA both when logging on locally (at the console) and over the network; non-privileged accounts need MFA for network access, which includes remote access, VPN and cloud services.

04 Do you create and retain audit logs sufficient to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity?

Audit logs must capture security-relevant events including user actions, system events, and access to sensitive data. Logs should be retained for at least 90 days (1 year recommended).

05 Do you have documented procedures for incident handling including preparation, detection, analysis, containment, eradication, and recovery?

Incident response plan should define roles, procedures, communication protocols, and tools for each phase of incident handling.

06 Do you test your incident response capability through exercises and simulations?

Regular testing (at least annually) through tabletop exercises, simulations, or full-scale drills ensures the incident response plan is effective and personnel are prepared.

07 Do you scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting systems are identified?

Vulnerability scanning should occur at least quarterly (monthly recommended). Scan results should be reviewed, prioritized, and remediated based on risk.

08 Do you identify, report, and correct system flaws in a timely manner?

System flaws include software bugs and vulnerabilities. Establish processes for receiving security advisories, testing patches, and deploying them according to risk-based timelines.

Adapted from Inventive HQ’s free-tool workflows, using UpCISO’s shared question bank, policy generator and product knowledge.