SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Self-assessment of the level of information security

Self-assessment of the level of information security
01.06.2026

Ruslan Rakhmetov, Security Vision


Ensuring cybersecurity in large corporations involves working with a vast network of business units, organizations within a group of companies or holding structures, and various subsidiaries and dependent companies (SDCs). In such organizationally and geographically dispersed structures, the issue of conducting a self-assessment of the information security level inevitably arises, as the head office's cybersecurity director physically lacks the ability to verify the quality of information security processes implemented in all subsidiary divisions. Various tools can help address the issue of self-service and self-assessment of cybersecurity – from simple questionnaires and email to specialized automation platforms, which we will discuss in this article.

 

Large corporations, holdings, and groups of companies have a specific management hierarchy: the parent organization or central office (head office, corporate center) defines strategic goals, makes key decisions, establishes rules, and oversees the work of subordinate (subsidiary) companies/subsidiaries/associates/branches/representative offices. Cybersecurity management is also structured hierarchically. For example, the chief information security officer or risk committee at the parent company or central office defines the information security architecture, overall concept, and high-level requirements: they formulate the strategy and principles of information protection, develop and implement policies and internal information security standards, create a cybersecurity process framework, list the minimum mandatory technical and organizational requirements for information security, and define reporting requirements. The formulated high-level requirements are then passed down to subordinate subsidiaries/affiliates, where tactical and operational tasks are addressed with a certain level of local autonomy, depending on the specific implementation of the organizational model (strictly centralized, federated, or hybrid). These tasks will be handled by responsible individuals on the ground – heads of information security departments/units, information security specialists, or IT specialists performing local cybersecurity tasks. Internal information security standards in a corporation, holding company, or group of companies can be based on various Russian and international standards, frameworks, and best practices, such as the ISO 27000 and 31000 series of standards and the NIST Cybersecurity frameworks. Framework and NIST Risk Management Framework, recommendations of CIS Critical Security Controls (Top-18).

 

For example, at the corporate center level, a unified standard for endpoint security (specific information security tools and OS versions) and account protection (set password complexity and rotation, use of MFA) is defined, a policy for processing confidential information (encryption at rest and in transit, backup, compliance with applicable legal requirements) is created, and a cyber incident response strategy is developed, which articulates general principles, roles, processes, technologies used, and expected results. Branches or subsidiaries adapt and refine the requirements of the parent organization's high-level information security policies, implement technical measures (install information security tools, configure the infrastructure), and develop local regulations and instructions for those responsible. If the parent company operates a SOC (cybersecurity monitoring center), the developed internal standards will require subsidiaries/branches to configure their IT systems and information security tools to forward information security events to the corporate SIEM system that the SOC integrates with.

 

Regulatory requirements for subsidiaries and affiliates may include not only internal corporate requirements, but also external legislative ones, which are mandatory for implementation and reflected in state regulatory legal acts. Non-compliance with them is fraught with various sanctions – from fines to suspension of operations and administrative or criminal liability for responsible persons of the company or subsidiaries and affiliates. The activities of a corporation, group of companies or holding company may be regulated by various government regulations in the field of cybersecurity, including federal legislation (187-FZ, 152-FZ, 63-FZ, 98-FZ, etc.), state standards (GOST 57580 series, GOST R 56939-2024, GOST R ISO/IEC 27001-2021, etc.), Regulations of the Central Bank of the Russian Federation (Nos. 757-P, 851-P, 821-P, 779-P, 716-P, 802-P, etc.), orders of the FSTEC of Russia (Nos. 239, 235, 117, 31, 21, etc.), orders of the FSB of the Russian Federation (Nos. 539, 540, 546, 547, 548, 553, 554, etc.) and other regulatory legal acts. Various indicators and metrics can be used to assess the cybersecurity status of subsidiaries and affiliates and their level of information security compliance. These indicators and metrics should be linked to the cyber risk management process, including the legal risk of non-compliance with legal requirements.

 

As a result, subsidiaries and affiliates are subject to a multitude of different requirements, the importance and priority of which depend on the potential damage to the entire group of companies resulting from a cyber incident and violation of legal or industry regulations. Managing compliance with these requirements manually is becoming impossible – it is necessary not only to compile a list of applicable regulations, deduplicating and comparing them, but also to assess the level of compliance with each requirement across all subsidiaries, affiliates, and representative offices. Using questionnaires in the form of Excel spreadsheets with data collection via email is no longer a viable solution, as responsible persons will face common compliance management challenges , such as manual completion, the inability to verify actual evidence of compliance, difficulties with questionnaire version control, and timely data entry. A corporate web portal with the ability to complete questionnaires and attach evidence of compliance (screenshots of settings, information security system reports, developed internal instructions) may be acceptable in terms of convenience and control over completion. However, the most effective mechanism for collecting information for information security self-assessment will be an automation platform with self-service functionality for entering information by responsible persons at subsidiaries and affiliates, with flexible configuration of the questionnaire lifecycle, monitoring of deficiencies, integrated compliance assessment, the construction of a resource-service model, and integration with corporate systems.

 

Below we describe the requirements for the functionality that should be implemented in such an information security self-assessment platform:


1) Construction of a structural diagram of the entire corporation/holding/group of companies and all subsidiaries and affiliates, maintenance of a register of organizations (parent and subsidiary organizations, corporate center and branches/representative offices), accounting of legal and economic ties between dependent organizations.


2) Formation of a unified resource-service model of the infrastructure of related organizations and branches/representative offices with the maintenance of records of interconnected assets, information systems, business processes, resources and with support for integration with ITAM, CMDB, ITSM class systems.


3) Availability of pre-established and decomposed into individual requirements legislative acts, standards, recommendations, best practices, including federal legislation (187-FZ, 152-FZ, 63-FZ, 98-FZ, etc.), state standards (series GOST 57580, GOST R 56939-2024, GOST R ISO/IEC 27001-2021, etc.), Regulations of the Central Bank of the Russian Federation (No. 757-P, 851-P, 821-P, 779-P, 716-P, 802-P, etc.), orders of the FSTEC of Russia (No. 239, 235, 117, 31, 21, etc.), orders of the FSB of the Russian Federation (No. 539, 540, 546, 547, 548, 553, 554, etc.), ISO 27000 and 31000 series standards, NIST Cybersecurity frameworks Framework and NIST Risk Management Framework, recommendations of CIS Critical Security Controls (Top-18), knowledge bases of the FSTEC of Russia and MITRE (ATT&CK, ATLAS), risk management frameworks COSO ERM and FAIR.


4) The ability to import corporate standards and create individual specialized requirements, the implementation of which will be verified.


5) Pre-installed and customizable procedures for assessing compliance of the entire corporation/holding/group of companies and all subsidiaries and affiliates: selection of applicable requirements (external and internal), their inclusion in created questionnaires (questionnaires, checklists) with the ability to select the response format (pre-installed selectable values, user input, file attachment), selection of target objects for assessment (the entire holding, individual subsidiaries and affiliates, business processes, information systems, assets, etc.), setup and control of the stages of the questionnaire life cycle (updating, in progress, completed, archived, etc.), preparation of personal accounts, views, roles for responsible persons in subsidiaries and affiliates, sending out notifications and invitations to those responsible to fill out questionnaires.


6) Preset and customizable formulas for assessing compliance with information security requirements: setting question weights to prioritize specific requirements, evaluating responses in various areas (e.g., specific technical and organizational measures, compliance with legal requirements for personal data protection, compliance with account security requirements), calculating a consolidated resulting/integrated compliance assessment for all organizations within the entire corporation/holding/group of companies, or calculating a specific compliance assessment for an individual subsidiary, business process, information system, etc.


7) Formulation and monitoring of action plans to eliminate non-conformities: based on the results of the compliance assessment, lists of tasks and activities are generated with deadlines and responsible parties to eliminate identified deficiencies and bring individual subsidiaries and affiliates, business processes, information systems, etc. into compliance, with subsequent monitoring of the statuses and deadlines for task completion, with the functionality of sending notifications to those responsible when task statuses change or deadlines are missed, with the ability to discuss tasks in the built- in chat on the platform.


8) Informing subsidiaries and affiliates and branches/representative offices about current cyber threats, cyber incidents, ongoing information security activities, changes in legislation and corporate standards for information protection in the format of information bulletins with notifications and familiarization control.


9) Integration with ticketing solutions and ITSM systems for task synchronization, integration with risk and compliance management systems (SGRC systems) to take into account the results of self-assessment when calculating the level of cyber and legal risks, integration with notification/alert systems (messengers, email, corporate communication tools).


10) Visualization and reporting on the status of information security: presentation of processed information and the level of information security compliance on interactive dashboards with drill functionality down, on connection graphs, geographic maps and floor plans, in tables and detailed asset cards, in the form of various compliance indicators (speedometers, traffic lights), displaying compliance ratings of subsidiaries and associates with the identification of leaders and outsiders, generating reports using custom templates with custom fonts and colors in PDF, DOCX, XLSX, CSV, ODS, ODT, etc. formats, and restricting access to visualization elements and reports in accordance with a customizable role model.


11) Deep and convenient customization: use the No-Code / Low-Code designer to configure questionnaires and surveys, change the logic of the compliance assessment process, customize visualization panels and reporting forms.

 

The described functionality is implemented in the Security Vision Self-Assessment (SA) product, which allows you to build a hierarchy of subsidiaries and affiliates and divisions within a corporation/holding/group of companies, automate the information security assessment process with a choice of methods based on applicable pre-defined regulatory requirements, standards, recommendations, or unique corporate rules. Security Vision SA allows for flexible customization of the entire compliance self-assessment process using a No-Code / Low-Code constructor, calculates the compliance level based on completed questionnaires using customizable formulas, generates a structural diagram of all related organizations/divisions and a unified resource and service infrastructure model, generates action plans and tasks to bring corporate cybersecurity into compliance, monitors the execution of plans and tasks, informs organizations about information security issues, visualizes results, and generates reports.