Exercise

Complete a Readiness Scorecard

Score yourself honestly across six areas and turn the two lowest into a short plan.

Intended audience
Owners and program leads
Difficulty
Beginner
Estimated time
15 minutes
Access
Free
NIST CSF
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Score an organization honestly across six core readiness areas using a defined 0-3 scale.
  • Apply the rule that a score above 1 requires documentation, and a score of 3 requires documentation, evidence, and review.
  • Identify the two lowest-scoring areas as priorities for near-term action.
  • Write a concrete action, owner, and deadline for each priority area.
  • Establish a recurring cadence for re-scoring readiness over time.

Score each area 0–3

  • Identity and access.
  • Devices and updates.
  • Data and backups.
  • People and training.
  • Documentation.
  • Detection and response.

Scale

  • 0 — not started.
  • 1 — partly done, undocumented.
  • 2 — done, documented.
  • 3 — done, documented, evidenced, reviewed.

Key takeaways

  • Self-scoring is only useful when it is honest, and the scale explicitly caps undocumented practices at a score of 1.
  • The two lowest-scoring areas deserve the first and fastest attention, especially when ties favor whichever protects data first.
  • Each improvement action should have a single named owner and a firm deadline, ideally within thirty days.
  • A scorecard exercise is not complete until a future re-scoring date is set, since readiness changes over time.
  • The NIST Cybersecurity Framework's function areas map naturally onto the six scorecard categories used in this exercise.

Practice workspace

  1. Hint: If you cannot show evidence, the score is at most 1.

  2. Hint: Ties go to whichever protects data first.

  3. Hint: Thirty days maximum per action.

  4. Hint: Quarterly works for most small businesses.

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 2
Knowledge check

80% required to pass. Answers are graded on our servers.

1. According to the scoring scale, what is the maximum score an undocumented practice can receive?

2. What does a score of 3 require?

3. When two areas are tied for the lowest score, which should be prioritized first?

4. What three elements should each improvement action include?

5. Why must the exercise end with setting a re-scoring date?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Matched on shared frameworks, topics, and program packs.

Checklist

Cybersecurity Self-Assessment Checklist

A fast, honest look at your current security posture across identity, devices, data, people, and response.

Beginner
25 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Template

Acceptable Use Policy

What employees may and may not do with company systems, data, devices, and AI tools.

Beginner
25 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Exercise

Build Your First Asset Inventory

Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.

Beginner
20 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Guide

Building a Security Program from Scratch

A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.

Beginner
14 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Template

Information Security Policy

The parent policy that states what your organization protects, who is responsible, and how the rest of your documentation hangs together.

Intermediate
45 min
Free
NIST CSF
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Practice Writing Policy Statements

Turn vague intentions into policy statements that are testable and enforceable.

Intermediate
20 min
Free
NIST CSF
ISO 27001

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.