1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:03,450
we're going to perform an internal assessment.

3
00:00:03,450 --> 00:00:05,550
Now, the exact checklist and procedures

4
00:00:05,550 --> 00:00:08,220
that you're going to use to perform an internal assessment

5
00:00:08,220 --> 00:00:09,180
are going to vary depending

6
00:00:09,180 --> 00:00:11,490
on your organization's own governance, risk,

7
00:00:11,490 --> 00:00:12,930
and compliance practices.

8
00:00:12,930 --> 00:00:16,110
But for this video, we will be using a sample checklist

9
00:00:16,110 --> 00:00:18,870
from the Minnesota Counties Intergovernmental Trust,

10
00:00:18,870 --> 00:00:20,550
known as the MCIT.

11
00:00:20,550 --> 00:00:22,080
This governmental organization

12
00:00:22,080 --> 00:00:24,660
has created a checklist to assist its members

13
00:00:24,660 --> 00:00:26,940
in minimizing their exposures related

14
00:00:26,940 --> 00:00:29,610
to data and cybersecurity by identifying

15
00:00:29,610 --> 00:00:32,520
and addressing these potential risks and vulnerabilities.

16
00:00:32,520 --> 00:00:34,980
The Cybersecurity Self-Assessment Checklist

17
00:00:34,980 --> 00:00:38,220
that MCIT created is a broad checklist

18
00:00:38,220 --> 00:00:40,680
that an organization can use internally to assist

19
00:00:40,680 --> 00:00:43,320
in the identification of data security areas

20
00:00:43,320 --> 00:00:46,110
that might need to be strengthened by the organization.

21
00:00:46,110 --> 00:00:48,510
To use the Cybersecurity Self-Assessment,

22
00:00:48,510 --> 00:00:50,850
you'll answer a series of yes or no questions

23
00:00:50,850 --> 00:00:53,700
and provide areas for comments and action items

24
00:00:53,700 --> 00:00:56,610
as well as to whom those action items are being assigned to

25
00:00:56,610 --> 00:00:57,840
for completion.

26
00:00:57,840 --> 00:01:00,900
Each action item should be assigned to a specific individual

27
00:01:00,900 --> 00:01:03,480
or group so that someone is going to be responsible

28
00:01:03,480 --> 00:01:06,180
for following up with the designees to make sure

29
00:01:06,180 --> 00:01:08,910
that any correct actions are properly performed

30
00:01:08,910 --> 00:01:10,260
and implemented.

31
00:01:10,260 --> 00:01:11,640
To get the most out of this kind

32
00:01:11,640 --> 00:01:12,960
of self-assessment checklist,

33
00:01:12,960 --> 00:01:15,210
you should have people from across your organization

34
00:01:15,210 --> 00:01:17,160
working on it together as a group,

35
00:01:17,160 --> 00:01:18,900
including your administration team,

36
00:01:18,900 --> 00:01:20,550
your information technology staff,

37
00:01:20,550 --> 00:01:22,200
and your cybersecurity professionals,

38
00:01:22,200 --> 00:01:24,510
to ensure the risks across the organization

39
00:01:24,510 --> 00:01:25,860
are well understood.

40
00:01:25,860 --> 00:01:27,270
So let's take a quick look

41
00:01:27,270 --> 00:01:29,730
at this Cybersecurity Self-Assessment Checklist.

42
00:01:29,730 --> 00:01:30,780
Here is the example

43
00:01:30,780 --> 00:01:33,660
of the Cybersecurity Self-Assessment Checklist.

44
00:01:33,660 --> 00:01:35,640
I'm going to just read through the first five items

45
00:01:35,640 --> 00:01:36,780
just to give you a feel

46
00:01:36,780 --> 00:01:38,790
of what the checklist entails.

47
00:01:38,790 --> 00:01:41,340
Across the top, we see we have the completed by,

48
00:01:41,340 --> 00:01:43,470
title of the assessment, date,

49
00:01:43,470 --> 00:01:44,940
and signature of the individual

50
00:01:44,940 --> 00:01:47,280
performing the self-assessment.

51
00:01:47,280 --> 00:01:50,520
Across the top of the columns, we also see the item,

52
00:01:50,520 --> 00:01:51,390
the yes or no

53
00:01:51,390 --> 00:01:54,150
because every question is going to be a yes or no question,

54
00:01:54,150 --> 00:01:57,000
the department or vendor that's responsible,

55
00:01:57,000 --> 00:02:00,000
the comments, action items to be performed,

56
00:02:00,000 --> 00:02:02,760
and who is this task assigned to.

57
00:02:02,760 --> 00:02:05,917
Now, reading question number one, the question states,

58
00:02:05,917 --> 00:02:07,200
"Has your organization,

59
00:02:07,200 --> 00:02:09,509
at any time during the past 12 months,

60
00:02:09,509 --> 00:02:12,540
experienced a cybersecurity incident like hacking,

61
00:02:12,540 --> 00:02:15,720
intrusion, malware infection, fraud loss,

62
00:02:15,720 --> 00:02:19,020
breach of personal information, extortion, et cetera,

63
00:02:19,020 --> 00:02:22,890
or experienced a lawsuit or other formal dispute

64
00:02:22,890 --> 00:02:26,340
with either a private party or government agency

65
00:02:26,340 --> 00:02:28,410
arising from a cybersecurity incident?"

66
00:02:28,410 --> 00:02:30,450
Now that's the first question.

67
00:02:30,450 --> 00:02:33,997
Next, we see a sub-question to that same number one,

68
00:02:33,997 --> 00:02:37,530
"Have deficiencies been identified and addressed?"

69
00:02:37,530 --> 00:02:40,207
Scrolling down, we see we have number two,

70
00:02:40,207 --> 00:02:42,633
"Do you have a data security incident response plan

71
00:02:42,633 --> 00:02:46,740
that addresses responsibilities, incident identification,

72
00:02:46,740 --> 00:02:49,770
triage, notification, investigation

73
00:02:49,770 --> 00:02:51,570
threat/vulnerability removal,

74
00:02:51,570 --> 00:02:54,270
recovery and business continuity?"

75
00:02:54,270 --> 00:02:55,447
Question number three states,

76
00:02:55,447 --> 00:02:57,630
"Is a business continuity plan established

77
00:02:57,630 --> 00:03:00,480
that includes an inventory of vital operations,"

78
00:03:00,480 --> 00:03:01,807
so that's one,

79
00:03:01,807 --> 00:03:04,800
"inventory of IT hardware and software essential

80
00:03:04,800 --> 00:03:06,900
to those operations,"

81
00:03:06,900 --> 00:03:08,317
that will be the second question,

82
00:03:08,317 --> 00:03:10,980
"identification of third parties, vendors,

83
00:03:10,980 --> 00:03:13,590
or neighboring organizations or agreements made

84
00:03:13,590 --> 00:03:16,380
to carry out those business continuity plans

85
00:03:16,380 --> 00:03:18,720
as well as do we have a well-documented agreement

86
00:03:18,720 --> 00:03:20,880
with clear responsibilities in place

87
00:03:20,880 --> 00:03:23,130
with the noted parties?"

88
00:03:23,130 --> 00:03:25,027
Going to question number four,

89
00:03:25,027 --> 00:03:26,880
"Does every device in your organization

90
00:03:26,880 --> 00:03:29,820
have antivirus and anti-malware software installed

91
00:03:29,820 --> 00:03:32,430
and do you keep this software up to date?"

92
00:03:32,430 --> 00:03:33,277
Question number five,

93
00:03:33,277 --> 00:03:36,870
"Does the organization have a mobile device policy?

94
00:03:36,870 --> 00:03:39,120
Has staff been trained about this policy?

95
00:03:39,120 --> 00:03:42,420
Does the policy outline whether personally owned devices

96
00:03:42,420 --> 00:03:44,340
are permissible for work purposes

97
00:03:44,340 --> 00:03:46,440
and under what requirements?"

98
00:03:46,440 --> 00:03:48,330
So as you can see,

99
00:03:48,330 --> 00:03:50,610
these checklists are going to be very broad

100
00:03:50,610 --> 00:03:52,800
and they're seeking to get a quick overview

101
00:03:52,800 --> 00:03:55,470
of your organization's current risk posture.

102
00:03:55,470 --> 00:03:56,490
As I said earlier,

103
00:03:56,490 --> 00:03:58,890
your organization may use a different checklist

104
00:03:58,890 --> 00:04:00,600
or ones with different questions,

105
00:04:00,600 --> 00:04:01,740
but the general format

106
00:04:01,740 --> 00:04:04,110
and purpose of these self-assessments remain the same

107
00:04:04,110 --> 00:04:05,910
across most organizations.

108
00:04:05,910 --> 00:04:08,880
So remember, cybersecurity and database exposures

109
00:04:08,880 --> 00:04:11,430
are some of the largest potential loss drivers

110
00:04:11,430 --> 00:04:12,870
from most organizations

111
00:04:12,870 --> 00:04:15,150
and you can help prevent these exposures

112
00:04:15,150 --> 00:04:17,970
by identifying and addressing the risk and vulnerabilities

113
00:04:17,970 --> 00:04:19,230
within your organization

114
00:04:19,230 --> 00:04:21,360
so that you are well prepared to mitigate

115
00:04:21,360 --> 00:04:23,313
and remediate these risks over time.

