-Has the agency conducted risk assessments for cyber threats?
- Is there a security policy and/or framework that consider cyber threats?
-Are controls in place to effectively detect and manage cyber intrusions?
-Are incident response plans and recovery processes in place?