Make cybersecurity priorities easier to explain.
Reflect on ownership, safeguards, detection, response and recovery through questions aligned with NIST CSF 2.0.
Twelve questions. Six perspectives.
Use evidence you can point to. “Not sure” is a useful answer when a practice needs verification.
Answers stay in this page and reset on reload. No email or company details required.
Govern
For example: a current responsibility matrix and an agreed escalation route.
CSF 2.0 alignment: GV.RR-02For example: an approved policy set, communication records and an exception process.
CSF 2.0 alignment: GV.PO-01How the scorecard works and where it comes from
Questions are KAISAN’s educational prompts aligned to selected outcomes in NIST CSF 2.0. See also NIST’s Small Business Quick-Start Guide. Counts describe your two answers in each function; they are not a security percentage or a complete framework assessment.
KAISAN’s example triage order is: reported gaps, unknown practices to verify, partial practices, then maintenance of established practices. Ties follow question order. This ordering is not prescribed by NIST and is not a severity rating. Your business risks can change the priority. The six functions work together; their display order is not an implementation sequence.
Editing an answer removes the previous results until you generate them again. Established practices remain self-reported. The limited questionnaire does not cover every CSF outcome or validate evidence.