Assessments Module

Test your cybersecurity defenses and find areas for improvement

Why Do I Need Security Assessments?

Think of security assessments like regular health checkups for your business technology:

  • Find Problems Early: Discover security weaknesses before hackers do
  • Prove You're Protected: Show customers, partners, and insurers that you take security seriously
  • Meet Legal Requirements: Many regulations require regular security assessments
  • Save Money: Fixing problems early costs much less than dealing with a breach
  • Sleep Better: Know exactly how secure your business really is

5 Assessment Types

amara provides five distinct assessment frameworks. One assessment can simultaneously satisfy multiple compliance standards.

1. Rapid Assessment

Time needed: 10-15 minutes

Quick cybersecurity health check across 10 domains. Perfect first step for organisations new to GRC.

Start Rapid Assessment
2. CIA Classification

Time needed: 15-30 minutes per asset

Evaluate Confidentiality, Integrity, and Availability per asset. 37 security measures across 4 domains with 4-level scoring (1-4).

Start CIA Classification
3. ISO 27001:2022

Time needed: 4-8 hours (full assessment)

Full ISO/IEC 27001:2022 assessment with 93 controls across 4 categories (Organisational, People, Physical, Technological). Generates Statement of Applicability.

Start ISO 27001
4. BSI C5 Cloud

Time needed: 3-6 hours

BSI Cloud Computing Compliance Criteria Catalogue. Specifically for organisations using or providing cloud services.

Start BSI C5
5. EU AI Act

Time needed: 2-4 hours

EU Artificial Intelligence Act compliance assessment. Evaluate AI systems for risk classification, transparency, and governance requirements.

Start EU AI Act
Assessment Integration

All assessment modules share the same database. Assets, risks, and compliance gaps flow automatically between modules. Create Jira tickets directly from individual control gaps to assign remediation work to your team. One assessment can satisfy multiple frameworks simultaneously.

How Assessments Work

Simple 4-Step Process
  1. Choose Your Assessment: Pick the type that fits your needs and available time
  2. Answer Questions: Simple yes/no questions about your current security practices
  3. Get Your Score: Receive an easy-to-understand report with your security rating
  4. Follow Recommendations: Get specific steps to improve your security

What Questions Will I Be Asked?

All questions are designed for business owners and managers - no technical expertise required. Examples include:

  • "Do you have backups of your important data?"
  • "Do employees use unique passwords for work accounts?"
  • "Is your Wi-Fi network password-protected?"
  • "Do you have antivirus software on all computers?"

Getting Started

First Time Assessment

  1. Start with Quick Assessment: Get familiar with the process
  2. Gather Basic Information: Have details about your computers, software, and data ready
  3. Set Aside Time: Find a quiet 15-30 minutes when you won't be interrupted
  4. Be Honest: Accurate answers give you useful results
Pro Tips for Success
  • If you're unsure about an answer, choose "No" or "Partially" - it's better to be safe
  • Keep notes about areas where you answered "No" - these are your improvement priorities
  • Run assessments regularly (quarterly or after major changes) to track improvement
  • Share results with your team to build security awareness

Understanding Your Results

Your Security Score

0-40%
Needs Immediate Attention
High risk - prioritize security improvements
41-70%
Good Foundation
Some protection but room for improvement
71-90%
Well Protected
Strong security with minor gaps to address
91-100%
Excellent
Industry-leading security practices

Your Action Plan

Every assessment provides a prioritized list of improvements:

  • Critical (Fix First): Major security gaps that need immediate attention
  • Important (Fix Soon): Significant improvements that strengthen your defenses
  • Recommended (Fix When Possible): Best practices that enhance your security posture