Self-assessment
Also known as: self-evaluation
An organisation checking its own security against a set list of questions or criteria, without an outside inspector.
Draft - this entry has not been reviewed yet.
Formal
A structured review the organisation carries out on itself, using a questionnaire or criteria from a standard, label or law - such as the D-mærket tool - to map its practice, find gaps and pick improvements.
In plain English
Like going through a home safety checklist on a Sunday - you walk round with the list yourself to see what needs fixing, before anyone official ever comes by.
In practice
A family-owned furniture maker answers the D-mærket questions over two afternoons and finds it has no written plan for what to do if its systems go down.
Why it matters
It is a cheap first step for smaller organisations to see where they stand against NIS2 and similar demands before spending money on outside help.
Technical deep dive
A self-assessment is a first-party evaluation: the organisation answers questions about itself, usually against a fixed catalogue, and its value depends almost entirely on how evidence is handled. It sits at the bottom of a hierarchy of assurance. Second-party assessments are made by a customer or partner, for example a supplier audit; third-party assessments are made by an independent body, such as an accredited ISO/IEC 27001 certification audit or an ISAE 3402 or SOC 2 assurance report from an auditor. The same questionnaire can serve all three, so what distinguishes them is independence and the depth of evidence examined, not the questions.
Many established schemes start with self-assessment. The Cloud Security Alliance's STAR programme has a Level 1 self-assessment in which providers publish their answers to the Consensus Assessments Initiative Questionnaire (CAIQ), mapped to the Cloud Controls Matrix; CIS offers a self-assessment tool for the CIS Controls; the NIST CSF is designed around an organisation describing its own current profile; and C2M2 is intended as a facilitated self-evaluation. In Denmark, D-mærket begins with a self-assessment that determines which criteria apply to the company, followed by a review by D-mærket's auditors before the label is granted; the label is awarded for one year at a time, and renewal starts with the self-assessment again.
The typical weaknesses are predictable. Binary yes/no questions reward the existence of a policy rather than its operation; respondents answer for the design of a control, not its operating effectiveness over time (the distinction between Type I and Type II reports in ISAE 3402 and SOC 2); optimism bias inflates scores, especially when the person answering also owns the control; and questions are interpreted differently from year to year, destroying comparability. Mitigations include requiring an evidence reference for every positive answer, sampling a few answers for verification, rotating who answers, and scoring on a graded scale with defined criteria.
Self-assessment is not the same as the internal audit required by ISO/IEC 27001 clause 9.2, which must follow an audit programme and be carried out by auditors selected to ensure objectivity and impartiality; a self-assessment can feed the internal audit and management review but cannot replace it. Under NIS2 no self-assessment replaces supervision either, although Article 21(2)(f) requires procedures to assess the effectiveness of the measures, and a structured, repeated self-assessment is a common and inexpensive way to meet part of that duty.
What to learn first
Everything this builds on, foundations first.
- Compliance
- →Self-assessment
Relationships
- Requires
- Compliance
- Don't confuse with
- Audit
Sources & further reading
Official documentation
- D-mærket - Kriterier og selvevalueringsværktøj
- D-mærket - Sådan får du D-mærket · D-mærket
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 8
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…