Cybersecurity GRC 13 items
DDoS Resilience Assessment
Assesses DDoS resilience covering risk assessment, network and application protections, mitigation services, response readiness, and testing.
NIST 800-53CISAISO 27001
Free PDF · enter your email to download.
Risk & Architecture
- Are internet-facing assets and their availability requirements inventoried? *
- Is critical infrastructure designed with redundancy and no single point of failure? *
- Is origin infrastructure hidden behind the mitigation/CDN provider? *
Protection Layers
- Is volumetric (Layer 3/4) DDoS protection in place, typically via an upstream scrubbing service? *
- Is application-layer (Layer 7) protection configured for HTTP floods? *
- Is DNS infrastructure protected and resilient (anycast, redundant providers)? *
- Are rate limiting and connection controls tuned at the edge?
Provider & Capacity
- Does the mitigation provider have capacity exceeding plausible attack sizes? *
- Are always-on vs. on-demand mitigation modes chosen appropriately per asset?
- Are SLAs and escalation contacts with the provider documented? *
Response & Testing
- Is a DDoS response runbook documented with roles and escalation paths? *
- Are monitoring and alerting in place to detect attacks early? *
- Is the DDoS response plan tested or exercised periodically?
Download the full DDoS Resilience Assessment checklist
Get it as a clean, printable PDF — free.
