GRC1Labs

Risk Assessment · ISO 27001 · NIST CSF · CIS · OWASP SAMM

Know where you stand. We'll show you how far there is to go.

A risk assessment that measures maturity per domain, separates what you declare from what the evidence supports, and delivers an action plan with owners, deadlines and order.

How it works

Four steps, and none of them is a questionnaire abandoned halfway.

  1. 01

    You pick the frameworks

    ISO 27001, NIST CSF, CIS Controls, OWASP SAMM, privacy. Pick several: questions that mean the same thing in different frameworks appear once.

  2. 02

    The questionnaire adapts to you

    If you don't build software, you won't see the secure-development block. Asking what doesn't apply is how people decide a questionnaire wasn't made for them.

  3. 03

    We measure maturity, not opinion

    Each domain gets a score from 0 to 5, declared and validated side by side. Unanswered questions stay out of the average instead of counting as zero.

  4. 04

    The gap becomes a plan

    Each finding comes from the distance between where you are and the agreed target, and breaks down into epics, stories and tasks with effort and deadlines.

Request

Five minutes to fill in. The protocol is yours.

When you submit, you receive a protocol number and a tracking password. Keep both: the password appears once, on screen, and is never sent by e-mail.

Open in a new tab(opens in a new tab)