S2W AUDIT S2W Client / Organization S2W SISTEMAS E SERVIÇOS WEB Scope Test Objectives Teste Assets Teste Physical Safety / Continuity Are fire detection and prevention systems (alarms, sprinklers, extinguishers) installed and regularly tested? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Legacy Systems Are legacy systems monitored and maintained according to a documented schedule, with clear intervention procedures? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Physical Security Are physical access controls (locks) implemented for offices, storefront, and warehouses? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Is CCTV surveillance in place and functioning to monitor critical physical areas? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Privacy Management Are privacy policies, procedures, and processes documented and enforced for handling personal data? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Backup and Recovery Are regular backups performed for critical systems and data, and are restoration tests conducted? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Asset Management Does the organization maintain an up-to-date inventory of all IT assets (hardware, software, data, and network components)? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Network Security Is an intrusion detection or intrusion prevention system (IDS/IPS) deployed and monitored? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Endpoint Security Is antivirus or endpoint protection software installed, updated, and centrally monitored on all relevant devices? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Access Control Is separation of duties implemented for critical business and IT processes? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Is the principle of least privilege enforced for all user accounts and system access? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Password Management Is there a centralized password or credential management system in place? Yes No Partially N/A Comments / Evidence 0% Attach Evidence Business Continuity / DRP Is there a documented and tested disaster recovery plan (DRP) in place? Yes No Partially N/A Comments / Evidence 0% Attach Evidence SAVE ANSWERS Powered by Cyber Audit Manager