Cybersecurity GRC 17 items
Ransomware Readiness Assessment
Assesses organizational readiness to prevent, detect, and recover from ransomware using the CISA #StopRansomware guide and NIST controls, covering prevention, detection, and recovery.
CISA #StopRansomwareNIST 800-53CIS v8
Free PDF · enter your email to download.
Prevention & Hardening
- Is phishing-resistant or strong MFA enforced on all remote access and email? *
- Are RDP and remote services restricted, patched, and not exposed to the internet? *
- Is application allowlisting or macro blocking enforced on endpoints?
- Is network segmentation implemented to limit lateral movement? *
- Are internet-facing vulnerabilities prioritized and remediated on a defined SLA? *
Detection & Response
- Is EDR deployed with detections for ransomware precursor behaviors? *
- Are common precursor malware families (e.g., loaders, C2 frameworks) alerted on? *
- Is there a ransomware-specific incident response playbook? *
- Is the isolation and containment procedure for infected hosts documented? *
Backup & Recovery
- Are backups maintained following the 3-2-1 rule with at least one offline/immutable copy? *
- Are backups isolated from production credentials and networks? *
- Are restoration procedures tested on a defined schedule? *
- Is a recovery time objective (RTO) defined for critical systems?
Governance & Decision-Making
- Is there a documented ransom-payment decision process involving legal and leadership? *
- Are OFAC sanctions considerations documented for any potential payment?
- Are law-enforcement and CISA reporting contacts documented in advance? *
- Has a ransomware tabletop exercise been conducted in the past 12 months?
Download the full Ransomware Readiness Assessment checklist
Get it as a clean, printable PDF — free.
