Documentation
Assessments Module
Test your cybersecurity defenses and find areas for improvement
Why Do I Need Security Assessments?
Think of security assessments like regular health checkups for your business technology:
- Find Problems Early: Discover security weaknesses before hackers do
- Prove You're Protected: Show customers, partners, and insurers that you take security seriously
- Meet Legal Requirements: Many regulations require regular security assessments
- Save Money: Fixing problems early costs much less than dealing with a breach
- Sleep Better: Know exactly how secure your business really is
What You'll Learn
5 Assessment Types
amara provides five distinct assessment frameworks. One assessment can simultaneously satisfy multiple compliance standards.
1. Rapid Assessment
Time needed: 10-15 minutes
Quick cybersecurity health check across 10 domains. Perfect first step for organisations new to GRC.
Start Rapid Assessment2. CIA Classification
Time needed: 15-30 minutes per asset
Evaluate Confidentiality, Integrity, and Availability per asset. 37 security measures across 4 domains with 4-level scoring (1-4).
Start CIA Classification3. ISO 27001:2022
Time needed: 4-8 hours (full assessment)
Full ISO/IEC 27001:2022 assessment with 93 controls across 4 categories (Organisational, People, Physical, Technological). Generates Statement of Applicability.
Start ISO 270014. BSI C5 Cloud
Time needed: 3-6 hours
BSI Cloud Computing Compliance Criteria Catalogue. Specifically for organisations using or providing cloud services.
Start BSI C55. EU AI Act
Time needed: 2-4 hours
EU Artificial Intelligence Act compliance assessment. Evaluate AI systems for risk classification, transparency, and governance requirements.
Start EU AI ActAssessment Integration
All assessment modules share the same database. Assets, risks, and compliance gaps flow automatically between modules. Create Jira tickets directly from individual control gaps to assign remediation work to your team. One assessment can satisfy multiple frameworks simultaneously.
How Assessments Work
Simple 4-Step Process
- Choose Your Assessment: Pick the type that fits your needs and available time
- Answer Questions: Simple yes/no questions about your current security practices
- Get Your Score: Receive an easy-to-understand report with your security rating
- Follow Recommendations: Get specific steps to improve your security
What Questions Will I Be Asked?
All questions are designed for business owners and managers - no technical expertise required. Examples include:
- "Do you have backups of your important data?"
- "Do employees use unique passwords for work accounts?"
- "Is your Wi-Fi network password-protected?"
- "Do you have antivirus software on all computers?"
Getting Started
First Time Assessment
- Start with Quick Assessment: Get familiar with the process
- Gather Basic Information: Have details about your computers, software, and data ready
- Set Aside Time: Find a quiet 15-30 minutes when you won't be interrupted
- Be Honest: Accurate answers give you useful results
Pro Tips for Success
- If you're unsure about an answer, choose "No" or "Partially" - it's better to be safe
- Keep notes about areas where you answered "No" - these are your improvement priorities
- Run assessments regularly (quarterly or after major changes) to track improvement
- Share results with your team to build security awareness
Understanding Your Results
Your Security Score
Needs Immediate Attention
High risk - prioritize security improvementsGood Foundation
Some protection but room for improvementWell Protected
Strong security with minor gaps to addressExcellent
Industry-leading security practicesYour Action Plan
Every assessment provides a prioritized list of improvements:
- Critical (Fix First): Major security gaps that need immediate attention
- Important (Fix Soon): Significant improvements that strengthen your defenses
- Recommended (Fix When Possible): Best practices that enhance your security posture