Security Awareness Questionnaire
This survey has been designed to gage your security awareness.
Each question has a certain weight and a rating. The questions with an asterix have to be completed in order to provide you with accurate results. Each question, has an option of not sure.
Once you have completed the survey, the results will be tabulated and emailed to you. All responses will be kept in confidence.
*
1.
Does your company currently have a written security policy?
Yes
No
Not Sure
2.
If you answered yes to the question above, does your security policy reflect your business plan?
Yes
No
Not Sure
*
3.
Does your company use a firewall?
Yes
No
Not Sure
*
4.
Does your company have a VPN (Virtual Private Network)
Yes
No
Not Sure
*
5.
Does your company have an IDS?
Yes
No
Not Sure
*
6.
Does your company review security logs on your server
Yes
No
Not Sure
*
7.
If you answered yes, how often are they reviewed
Constant monitoring
Daily
Weekly
Monthly
Whenever the IT department has a chance
Other
*
8.
Does your company have a VLAN?
Yes
No
Not Sure
*
9.
Does your company perform backups?
Yes
No
Not Sure
*
10.
Do you consider the following items to be a critical asset
Fax Machine
Email
File Server
Print Server
Modems
*
11.
Does your company have a secured server room
Yes
No
Not Sure
12.
How many modems does your company use?
*
13.
Does your company have any statements posted around the office about personal use of Office Equipment
Yes
No
Not Sure
*
14.
How do you as a representative of your company perceive password?
Are they a nuisance
A necessary evil
Don't care
*
15.
When negotiating new business or discussing business opportunities with employees or outside people, do you use instant message, email or like technologies, ie. ICQ?
Yes
No
Not Sure
*
16.
Does your company encrypt emails
Yes
No
Not sure
*
17.
Do you sign your emails or word documents using a digital signature (not a scanned image)
Yes
No
Not Sure
*
18.
Do you have your corporate officers or IT staff's name and email posted on your web site
Corporate Officers
IT Staff
No names are used on the web site
Not sure
No Web Site
*
19.
Does your company allow employees to access personal email accounts such as hotmail, yahoo, sympatico etc.
Yes
No
Not sure
*
20.
Does your company collect client information through the corporate web site
Yes
No
Not sure
No Web Site
*
21.
Does your company have a privacy statement on the corporate web site
Yes
No
Not Sure
No Corporate Web Site
*
22.
Do you know what the privacy statement says
Yes
No
*
23.
Does your company do business transactions over the internet
Yes
No
Not Sure
*
24.
What database products does your company utilize
*
25.
On the clients desktops, what is the software
Windows 95/98
Windows NT
Windows XP
Windows 2000
Another Windows product
Other
*
26.
In your opinion would adding or enhancing your security be detrimental or help your companies bottom line?
Deterimental to the bottom line
Help our bottom line
Neither be deterimental or helpful to our bottom line
*
27.
Does your company consider the IT infrastructure to be as important as your physical premises?
As important
Less important
More important
Not sure
28.
What is your position in the company
*
29.
Email Address