Risk Assessment · ISO 27001 · NIST CSF · CIS · OWASP SAMM
Know where you stand. We'll show you how far there is to go.
A risk assessment that measures maturity per domain, separates what you declare from what the evidence supports, and delivers an action plan with owners, deadlines and order.
How it works
Four steps, and none of them is a questionnaire abandoned halfway.
- 01
You pick the frameworks
ISO 27001, NIST CSF, CIS Controls, OWASP SAMM, privacy. Pick several: questions that mean the same thing in different frameworks appear once.
- 02
The questionnaire adapts to you
If you don't build software, you won't see the secure-development block. Asking what doesn't apply is how people decide a questionnaire wasn't made for them.
- 03
We measure maturity, not opinion
Each domain gets a score from 0 to 5, declared and validated side by side. Unanswered questions stay out of the average instead of counting as zero.
- 04
The gap becomes a plan
Each finding comes from the distance between where you are and the agreed target, and breaks down into epics, stories and tasks with effort and deadlines.
Request
Five minutes to fill in. The protocol is yours.
When you submit, you receive a protocol number and a tracking password. Keep both: the password appears once, on screen, and is never sent by e-mail.
The secure form loads here on www.grc1labs.com.