Asset & risk management depth
How this is scored
The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.
0 — No ISMS substance; "information security" is a chapter in the marketing site.
3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.
5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.
8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.
10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.
The GRC Consultant
The risk backbone is real: protection needs follow the IT-Grundschutz damage-scenario matrix with maximum principle and accumulation across linked assets, releasing an asset creates a revision and updates inheritance information, and incidents carry severity and a reporting-duty assessment with automatic monitoring of reporting deadlines, backed by nine ready templates covering BSI early-warning, notification and final reports plus GDPR Articles 33 and 34. Risks link directly to measures with a freely definable methodology and residual risks can be formally accepted with their own treatment in the degree-of-fulfilment metrics. I found no public information on continuity planning, which is what the highest bar adds. 2 14 17 12 2 13