Back to Resources
Internal Security Posture Self-Assessment: visual preview
Questionnaire

Internal Security Posture Self-Assessment

Security Maturity Scoring Across 10 Domains

Overview

Knowing where your security program actually stands is the first step toward improving it. This self-assessment helps you score your organization across 10 critical security domains using a consistent maturity scale. It is built for CISOs and security leaders who need an honest internal view of strengths, gaps, and priorities without waiting for an external audit to surface the problems.

Security Domains Covered

  • Governance, risk, and compliance (GRC)
  • Identity and access management (IAM)
  • Endpoint security and device management
  • Network security and segmentation
  • Cloud security posture
  • Data protection and classification
  • Application security (SDLC and AppSec)
  • Security operations and monitoring
  • Incident response and recovery
  • Third-party and supply chain risk management

Maturity Scoring Scale

LevelDescriptionIndicators
1 - InitialAd hoc, reactive, undocumentedNo formal policies, firefighting mode, tribal knowledge
2 - DevelopingSome processes defined but inconsistently appliedPartial documentation, manual workflows, limited metrics
3 - DefinedDocumented policies and repeatable processesWritten procedures, assigned ownership, basic monitoring
4 - ManagedProcesses measured and actively managedKPIs tracked, regular reviews, risk-based decisions
5 - OptimizingContinuous improvement with automation and feedback loopsAutomated controls, advanced analytics, proactive posture

Running the Assessment

Assign a domain owner for each of the 10 areas. Each owner should review their domain independently, score it honestly, and provide supporting evidence for the rating. Bring the group together for a calibration session where scores are discussed and adjusted based on peer input. This prevents both sandbagging and overconfidence. Document the rationale behind each score so you can track progress over time.

Translating Results into Action

After scoring, identify domains where your maturity level creates the most business risk. A level-2 identity program in an organization with remote workers and cloud infrastructure is a bigger concern than a level-2 physical security program in a fully remote company. Prioritize remediation based on business impact, not just low scores. Build a 90-day improvement plan for the top three gaps and assign executive sponsors to ensure accountability.

Benchmarking and Cadence

Repeat this assessment every six months. Track scores over time to measure improvement and demonstrate progress to the board and auditors. Compare your results against industry benchmarks when available. Organizations in regulated industries like financial services or healthcare should aim for level-4 maturity across all domains within 18 to 24 months of starting the program.

Frequently asked questions