That difference decides how your next customer questionnaire goes, how a board meeting runs, and how much work an audit becomes. 18 questions, none of them about a standard.
Not whether you meet a rule. Whether you can show your own position when somebody asks. That is the question posed in every procurement conversation, every audit and every board meeting, in different words.
Ability to answer, overview, traceability, incidents, suppliers, independence from individuals.
Each answerable without looking anything up. Having to look it up is already the answer.
Green, amber or red per area, plus where it pinches most.
0 of 18 questions answered
Measure 1 of 6 · When someone asks
If a customer sends a security questionnaire today, we can answer it from existing records without asking around the company.
At any time we can say which measures are open and who owns each of them.
Management receives a regular picture of the situation that is not assembled specially for the occasion.
Measure 2 of 6 · What you know
Our risks live in one place everyone involved knows, not scattered across spreadsheets and chat channels.
We know which systems and applications we run, without launching a survey to find out.
Our sites or entities are assessed against the same yardstick and are therefore comparable.
Measure 3 of 6 · What is traceable
For every significant decision it is traceable who made it, when, and who approved it.
We can show when a policy was last reviewed, without digging through file histories.
Changes to assessments and evidence are preserved rather than overwritten.
Measure 4 of 6 · When something happens
If a security incident occurs tomorrow, it is settled who decides and who gets informed.
For our most important processes we have recorded how long an outage is acceptable.
What we planned for that has been rehearsed at least once.
Measure 5 of 6 · Who works for you
We know which of our service providers have access to critical data or systems.
It is defined which evidence we require from them, and we follow up on it.
Measure 6 of 6 · When someone leaves
Somebody here knows governance, and the work continues when that person is unavailable.
What we do is recorded in one place that somebody else can find and understand.
Security work runs alongside day-to-day operations without IT falling behind.
Staff are trained regularly, and for each person we can show when that last happened.
Please answer all 18 questions. Missing: 18.
Then this check is still the right start, but not the end. For the statutory duties there is a second test that walks through the ten areas of § 30 BSIG one by one.
Red does not mean you work insecurely. It means you cannot show it. That is what OdySecure is built for: evidence arises in day-to-day operations instead of being assembled before the audit.