{"calculator":{"slug":"security-compliance-readiness-score","name":"Security & compliance readiness score","url":"https://infikeytechnologies.com/tools/security-compliance-readiness-score"},"inputs":{"framework":"iso27001","policies":"l1","assets":"l1","risk":"l1","access":"l1","encryption":"l1","vulnerabilities":"l1","monitoring":"l1","incidents":"l1","backups":"l1","vendors":"l1","training":"l1","privacy":"l1"},"inputs_readable":{"Framework you are working towards":"ISO 27001","Security policies and ownership":"Informal, no owner","Do you know what systems and personal data you have?":"Partly, in people’s heads","Security risk assessment":"Done once, informally","Access control and multi-factor authentication":"MFA on some systems","Encryption of data":"HTTPS only","Patching and vulnerability management":"Automatic updates on some systems","Logging and monitoring":"Logs exist but nobody reviews them","Incident response":"Know who to call","Backups and business continuity":"Backups, never tested","Vendors and data processors":"A list of vendors","Staff security awareness":"Occasional reminders","Privacy rights and data retention":"Privacy notice only"},"result":{"headline":{"label":"ISO 27001 readiness","value":"33%"},"summary":"Readiness for ISO 27001: 33% (Early stage), with 12 areas needing significant work.","verdict":{"tone":"bad","text":"Early stage: begin with ownership, an inventory of data and a risk assessment, then MFA and backups — the controls that prevent the most common incidents."},"metrics":[{"label":"Level","value":"Early stage"},{"label":"Score","value":"12 of 36"},{"label":"Areas needing significant work","value":"12"},{"label":"Weakest area","value":"Policies & ownership"}],"chart":{"title":"Score by area","items":[{"label":"Policies & ownership","value":"1 / 3"},{"label":"Data & asset inventory","value":"1 / 3"},{"label":"Risk assessment","value":"1 / 3"},{"label":"Access control & MFA","value":"1 / 3"},{"label":"Encryption","value":"1 / 3"},{"label":"Patching & vulnerabilities","value":"1 / 3"},{"label":"Logging & monitoring","value":"1 / 3"},{"label":"Incident response","value":"1 / 3"},{"label":"Backups & continuity","value":"1 / 3"},{"label":"Vendors & processors","value":"1 / 3"},{"label":"Staff awareness","value":"1 / 3"},{"label":"Privacy rights & retention","value":"1 / 3"}]},"table":{"caption":"Gaps and next steps","head":["Area","Today","ISO 27001 reference","Next step"],"rows":[["Policies & ownership","Informal, no owner","A.5.1, A.5.2","Approve an information security policy, name an owner for security and review it every year."],["Data & asset inventory","Partly, in people’s heads","A.5.9, A.5.12","List your systems, devices and the personal data each holds, with an owner for each."],["Risk assessment","Done once, informally","Clause 6.1.2, 8.2","Run a yearly risk assessment and keep a risk register with owners and treatment plans."],["Access control & MFA","MFA on some systems","A.5.15, A.5.18, A.8.5","Enforce MFA everywhere, give least-privilege access and review access every quarter."],["Encryption","HTTPS only","A.8.24","Encrypt data in transit and at rest, including laptops and backups, and manage keys."],["Patching & vulnerabilities","Automatic updates on some systems","A.8.8","Patch on a schedule, scan for vulnerabilities monthly and test critical systems yearly."],["Logging & monitoring","Logs exist but nobody reviews them","A.8.15, A.8.16","Collect logs centrally, alert on suspicious activity and keep logs long enough to investigate."],["Incident response","Know who to call","A.5.24–A.5.28","Write an incident response plan with notification steps and rehearse it at least once a year."],["Backups & continuity","Backups, never tested","A.8.13, A.5.30","Back up automatically, keep an offline or immutable copy and test restores regularly."],["Vendors & processors","A list of vendors","A.5.19–A.5.22","Keep a vendor list, check their security and sign data processing agreements."],["Staff awareness","Occasional reminders","A.6.3","Train everyone at joining and every year, and run phishing simulations."],["Privacy rights & retention","Privacy notice only","A.5.34","Publish a clear privacy notice, handle access and deletion requests, and delete data you no longer need."]]},"notes":["ISO 27001 certification also needs the management system: scope, Statement of Applicability, internal audit and management review."]},"share_url":"https://infikeytechnologies.com/tools/security-compliance-readiness-score?framework=iso27001&policies=l1&assets=l1&risk=l1&access=l1&encryption=l1&vulnerabilities=l1&monitoring=l1&incidents=l1&backups=l1&vendors=l1&training=l1&privacy=l1","disclaimer":"This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.","publisher":{"name":"Infikey Technologies","url":"https://infikeytechnologies.com","contact":"https://infikeytechnologies.com/contact"}}