Asset & risk management depth
How this is scored
The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.
0 — No ISMS substance; "information security" is a chapter in the marketing site.
3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.
5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.
8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.
10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.
The Lead Auditor
The asset-risk-treatment chain is real: protection needs follow the IT-Grundschutz method (damage-scenario matrix, maximum principle, accumulation across linked systems, inheritance information updated on release), the risk methodology is freely definable, risks link directly to the measures that reduce them, and consciously accepted residual risks are tracked as accepted and taken out of the fulfilment metric. Incidents carry categories, severity, reporting-duty assessment with automatically monitored deadlines, and nine ready report templates for BSI early warning, NIS2 and KRITIS filings. I found no public information on continuity planning, which is what keeps this short of the top. 8 2 12 13 14 17