Product Name
CIS CSAT Pro - SecureSuite CIS Controls Self-Assessment Tool
Product Version
v1.12.0
Date
Problem
Reading through the CSAT Pro User Guide, it seems as if the Scoring could potentially be problematic in certain use cases. From page 24,
Note that the “Not Applicable” and “Not Available” options will be treated, from a scoring perspective, the same as if the “1 (0-20%)” option were selected, which will yield a percentage score of 0 for that Sub-Control.
Solution
selecting “Not Applicable” or Not “Available” will still count against your score, you can use the Applicable toggle to scope individual Safeguards out of the assessment entirely. The blue toggle says “Applicable” to the upper right of the Safeguard View for each Safeguard (near the IG indicator for that Safeguard). For any Safeguards that you toggle off, those Safeguards are not in the scope of the assessment and will not count against you in scoring that assessment.
Highlight important information
Add Comment