Purpose and boundaries
This is an awareness and decision-support assessment. It is not an audit, certification, legal opinion, or formal compliance determination. The score is designed to help leadership identify where deeper review, evidence, or remediation is warranted.
Scoring model
- Each question is scored from 0–4. The highest score represents a formalized, implemented, tested, and evidenced state.
- Questions are assigned to governance domains. Each domain score is the ratio of earned points to available points in that domain.
- Domain scores are combined into the overall score using the domain weights shown below.
- “Not sure” answers are treated as an uncertainty signal and may apply a modest uncertainty adjustment.
- Some foundational questions have critical rules. If a critical foundation is absent, the overall score can be capped so a high average does not hide material risk.
Domain weights
ISMS scope, stakeholders, and requirements.
Ownership, policy, objectives, and review cadence.
Risk method, assessment, treatment, and Statement of Applicability.
Access, suppliers, incidents, backups, and awareness.
Evidence ownership, internal audit, management review, and corrective actions.
Critical score rules
- No defined ISMS scope is a foundational ISO blocker. (maximum score: 45)
- No current risk assessment prevents credible ISO readiness. (maximum score: 50)
- No risk treatment plan makes control selection hard to defend. (maximum score: 60)
- No Statement of Applicability is a major ISO readiness gap. (maximum score: 65)
- No evidence pack makes audit preparation unreliable. (maximum score: 70)
How to use the result
Review the three lowest domains, critical flags, and evidence checklist together. The objective is not to generate a high score; it is to make missing decisions, owners, and evidence visible. When a major customer, audit, regulatory, or incident deadline exists, the self-assessment should be followed by independent validation.