AETOS ONE

Common Sense Security Framework  ·  Base Self-Assessment

CSSF Base Self-Assessment

Answer Yes or No on 38 controls across 8 areas of your security program. Get a base readiness score built on the same framework Aetos One uses with clients. This is a starting point, not a full assessment.

Built on the Common Sense Security Framework (CSSF) v2.0. Learn more at commonsenseframework.org.

0 of 38 controls answered

Step 1 · About your organization

Organization details

This information stays in your browser. It populates the header of your exported report only. Nothing is saved or transmitted anywhere.

Step 2 · Answer each control

This base score is a starting point

This tool only asks whether each control exists. It does not measure how much of your environment it covers, how well it was verified, or how the areas of your program interact when one control fails. The full Common Sense Security Framework assessment adds:

info@aetosone.com · aetosone.com

How the score works. Each control is answered Yes or No. Points equal the control's risk weight when the answer is Yes, and zero when No or unanswered. Your score is the sum of earned points divided by the sum of all possible points, shown as a percentage. Controls tagged Tier 1 are load-bearing: any Tier 1 control answered No caps your overall score at 60, regardless of how the other controls score. This mirrors the floor-cap logic in the full CSSF workbook, because a strong score built on a broken foundation is not a strong score.

This is a base assessment, not a full one. A Yes or No answer does not capture coverage, verification, or maturity. Two organizations can both answer Yes to the same control and carry very different risk. The full CSSF assessment measures all of that, plus how your areas interact through weakest-link loss scenarios.

Nothing is saved or transmitted. Every entry stays in memory in this browser tab only and is cleared when you refresh or close the page. Export or print your report before you leave. This tool is provided for informational purposes and does not constitute security, legal, or compliance advice.