Make cybersecurity priorities easier to explain.

Reflect on ownership, safeguards, detection, response and recovery through questions aligned with NIST CSF 2.0.

EDUCATIONAL SELF-ASSESSMENT

Twelve questions. Six perspectives.

Use evidence you can point to. “Not sure” is a useful answer when a practice needs verification.

Answers stay in this page and reset on reload. No email or company details required.

FUNCTION 1 OF 6

Govern

For example: a current responsibility matrix and an agreed escalation route.

CSF 2.0 alignment: GV.RR-02

For example: an approved policy set, communication records and an exception process.

CSF 2.0 alignment: GV.PO-01
How the scorecard works and where it comes from

Questions are KAISAN’s educational prompts aligned to selected outcomes in NIST CSF 2.0. See also NIST’s Small Business Quick-Start Guide. Counts describe your two answers in each function; they are not a security percentage or a complete framework assessment.

KAISAN’s example triage order is: reported gaps, unknown practices to verify, partial practices, then maintenance of established practices. Ties follow question order. This ordering is not prescribed by NIST and is not a severity rating. Your business risks can change the priority. The six functions work together; their display order is not an implementation sequence.

Editing an answer removes the previous results until you generate them again. Established practices remain self-reported. The limited questionnaire does not cover every CSF outcome or validate evidence.