Step 1 · About your organization
Organization details
This information stays in your browser. It populates the header of your exported report only. Nothing is saved or transmitted anywhere.
Step 2 · Answer each control
This base score is a starting point
This tool only asks whether each control exists. It does not measure how much of your environment it covers, how well it was verified, or how the areas of your program interact when one control fails. The full Common Sense Security Framework assessment adds:
- Coverage percentage across your enterprise and your most critical assets, not just a Yes or No
- A verification tier for every control, from asserted to independently validated
- Weakest-link loss scenarios that show how one gap concentrates risk even when other scores look strong
- A prioritized remediation plan mapped to cost and effort
How the score works. Each control is answered Yes or No. Points equal the control's risk weight when the answer is Yes, and zero when No or unanswered. Your score is the sum of earned points divided by the sum of all possible points, shown as a percentage. Controls tagged Tier 1 are load-bearing: any Tier 1 control answered No caps your overall score at 60, regardless of how the other controls score. This mirrors the floor-cap logic in the full CSSF workbook, because a strong score built on a broken foundation is not a strong score.
This is a base assessment, not a full one. A Yes or No answer does not capture coverage, verification, or maturity. Two organizations can both answer Yes to the same control and carry very different risk. The full CSSF assessment measures all of that, plus how your areas interact through weakest-link loss scenarios.
Nothing is saved or transmitted. Every entry stays in memory in this browser tab only and is cleared when you refresh or close the page. Export or print your report before you leave. This tool is provided for informational purposes and does not constitute security, legal, or compliance advice.