Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
57 criteria
baselineWhat risk-quantification methodology does the platform use — FAIR (Factor Analysis of Information Risk), a proprietary scoring model, or simple qualitative heat maps — and can risk be expressed in financial terms (expected annual loss) for executive/board reporting?
baselineDescribe how the platform ingests and correlates findings from other tools (vulnerability scanners, CAASM, pentest results, compliance evidence) into one unified risk register, and provide a customer reference on de-duplication accuracy across sources.
baselineHow are risk scenarios modeled — can the platform simulate the impact of a specific threat against a specific asset/business process, or does it only aggregate generic control-gap scores?
baselineWhat third-party/vendor risk assessment capability is included — can external vendors be scored using the same framework as internal risk, and is this integrated or a bolted-on separate module?
baselineDetail residual-risk tracking over time — as compensating controls or remediations are applied, does the platform show risk trending down with a defensible before/after calculation, and can this be exported as board-ready trend reporting?
baselineHow does the platform handle risk appetite and tolerance thresholds — can different business units set different thresholds, and does the platform flag when a risk exceeds the organization's stated appetite?
baselineExplain regulatory/framework alignment — does the risk model map to NIST CSF, ISO 27005, or sector-specific frameworks, with evidence output an auditor can consume directly?
baselineWhat is the typical time-to-value — how long from deployment to a first credible, populated risk register, and how much of that requires manual data entry versus automated ingestion?
baselineIdentify threats and risk scenarios impacting IT systems, infrastructure, and data (Risk Identification).
baselineWhat is the pricing model — per asset scored, per user seat, or a flat enterprise tier — and how does cost scale as the organization's asset/risk-scenario count grows significantly?
baselineDoes a real, confirmed security incident automatically trigger a risk-register reassessment (updating the affected asset's risk score based on what actually happened), or does the risk register stay static until a manual periodic review cycle?
baselineIs the platform's risk-quantification output used or accepted by cyber-insurance underwriters for coverage/premium decisions, and can the vendor cite a real customer example where this data influenced actual insurance terms?
baselineDetail board-level reporting cadence and format specifically — is there a maintained, presentation-ready board report generated automatically, or does the security team need to manually build board materials from raw platform data every cycle?
baselineWho within the customer organization gets access to the risk register itself, and is there role-based access control over it, given that a complete risk register is itself sensitive information (a map of the organization's worst weaknesses) if it fell into the wrong hands?
baselineDoes the platform support genuinely isolated, per-subsidiary risk registers for a multi-entity organization (different business units with different risk appetites and separate data), or is there only one flat, shared risk register across the whole organization?
baselineWhat correction/appeal process exists when a risk score is inflated or wrong (e.g., a compensating control the platform doesn't know about that actually mitigates the scored risk), and how quickly can an analyst adjust and document that correction?
baselineIs there a documented, accessible API for exporting the full risk register into the customer's own BI/reporting tooling, and is that a one-time pull or a continuously synced feed?
baselineAssess the design and operating effectiveness of key security controls (e.g., IAM, logging, endpoint protection, network segmentation) (Control & Configuration Review).
baselineProvide a thorough review of the port authority's Cybersecurity Program using the NIST Cybersecurity Framework (CSF) version 2.0 or future versions; document assessment results on a spreadsheet for each CSF control with risk findings rated high, medium, and low.
baselineWhat risks that are beyond your control do you see in providing this service and how would you mitigate them?
baselineConduct white-box testing for both a Cybersecurity Risk Assessment and a Penetration Test across eight of the housing authority's locations and fourteen departments, covering 10+ cloud applications, 2 web applications, AD, endpoints, and on-premises equipment for 500+ devices, targeting 350+ users, including phishing, vishing, smishing, and physical pretexting.
baselineValidate and document critical systems, applications, data types, and dependencies (Asset & Data Inventory, NIST CSF Identify).
baselineAnalyze current vulnerabilities using scan results, prior audits/test findings, and relevant threat intelligence (Vulnerability Review).
baselineRate risks by likelihood and business impact, and align ratings to the housing authority's internal risk register using a NIST RMF approach (Risk Rating & Prioritization).
baselineAssess alignment to NIST CSF and applicable requirements/frameworks (e.g., NIST SP 800-53, CJIS, and other applicable regulations/standards) (Compliance & Standards Alignment).
baselineProvide a prioritized remediation plan with owners, target timelines, and quick wins (Recommendations & Roadmap).
baselineDeliver a Cybersecurity Risk Assessment Report (PDF/Word) covering risks, vulnerabilities, threat scenarios, and a prioritized mitigation plan aligned to NIST CSF.
baselineProvide an Executive Summary: non-technical overview of key risks, business impact, and top priorities.
baselineProvide a Prioritized Action Plan: ranked remediation backlog with severity/criticality, effort level, and recommended sequencing.
baselineDeliver a Leadership Readout Presentation briefing results, themes, and recommended next steps.
baselineProvide details of the cybersecurity professionals who will be involved in the engagement, including qualifications, certifications (e.g., CISSP, CEH, OSCP), and experience (Team Qualifications).
baselineProvide a clear outline of the approach and methodology for both the Cybersecurity Risk Assessment and Penetration Test, including tools, techniques, and standards followed (e.g., NIST, OWASP).
baselineProvide a detailed project timeline for conducting the risk assessment and penetration test, including key milestones and deliverable dates.
baselineProvide a detailed and transparent breakdown of all pricing, including fees for services, tools, testing activities, optional/add-on services, and a fixed rate for skill-to-remediation support.
baselineProvide periodic network health check reviews with a deliverable report and debriefing upon completion.
baselineProvide periodic Information Security Assessments (ISA) on the housing finance agency's IT infrastructure, providing ISA ratings for each category in a deliverable report with debriefing.
baselineProvide Security Assessments covering network, firewall, switches, virtual infrastructure, and VoIP, and provide Firewall and Router Configuration Reviews.
baselineProvide Data Breach Risk Assessment and Response Plan Development, and Information Security Risk Assessment.
baselineProvide Physical Security Reviews.
baselineTask Area 1: Contractor shall provide integrated security compliance, vulnerability management, and risk support services, including ISSO support for security authorization activities, development/maintenance of security documentation, and support for RMF, Assessment and Authorization (A&A), and continued authorization lifecycle activities.
baselineVendor must provide Risk Management capability: evaluate risk levels across data storage, collection, and transmission with impact analysis and mitigation recommendations.
baselineManage IT risk assessments based on common cyber security frameworks (NIST CSF & 800 series, ISO 27001, GLBA and others).
baselineSupport enterprise risk management: collection, analysis and communication of high impact/high likelihood programmatic or operational risks across the enterprise.
baselineContractor shall provide resources with a working and holistic understanding and knowledge of the Risk Management Framework (RMF) as defined by NIST SP 800-53 and NIST SP 800-53A, and serve as the source of technical expertise with regard to maintaining and improving the organization's RMF implementation.
baselineContractor shall provide Assessment & Authorization (A&A) support for approximately 15 moderate baseline systems consisting of the organization's Enterprise Common Controls, organization-hosted systems, systems hosted on FedRAMP-authorized cloud platforms, and systems hosted on non-FedRAMP-authorized cloud services.
baselineContractor shall develop and maintain a plan for the organization's ISSM and CISO approval to maintain authorization or risk acceptance for all relevant systems, including achievement of Authorization to Operate (ATO) for new or significantly changed systems, in accordance with OMB, NIST, and FISMA guidance/regulations.
baselineContractor shall prepare A&A packages, including a System Security Plan (SSP) for each of the organization's systems; strategically advise on the restructuring/reordering of system boundaries for compliance packages; prepare risk management recommendations; and track POA&Ms internally and with system owners.
baselineContractor shall conduct internal risk assessments to ensure controls and countermeasures are identified to compensate for weaknesses to reduce risk to the organization's operations, assets, individuals, or stakeholders, and prepare risk determination statements outlining potential risk with planned or completed corrective actions.
baselineContractor shall serve as system liaison to the Security Controls Assessor (SCA), penetration tester, and for overall system security purposes for both internal and external parties, and compile documentation and supporting materials required for each system assessment, including SSP, Risk Assessment Report, Contingency Plans and Test Results, SORN, FIPS 199, Configuration Management Plan, Cybersecurity and Privacy Incident Response Plan, and Disaster Recovery Plan.
baselineContractor shall provide quarterly reports on A&A activities for Executive Briefing to the CIO and/or the organization's Enterprise Risk Management Council, including SCAs completed, penetration tests completed, and relevant POA&M updates.
baselineNo later than 18 months after award, Contractor shall develop a comprehensive plan to migrate systems from legacy A&A practices to Ongoing Security Authorization (OSA), leveraging NIST SP 800-37 (Risk Management), NIST SP 800-53 (Control Guidance), and NIST SP 800-137 (Continuous Monitoring), and recommend innovative ways to automate OSA activities such as automated control testing and results reporting.
baselineContractor shall be responsible for establishing and managing an IT Risk Management Program per OMB Circular A-123/A-130, including developing an IT Risk Management Program Charter and Plan, defining risk appetite and governance methodology, recommending an automated mechanism for capturing and tracking IT risks, and providing quarterly trending/metrics reports to the CIO and/or Enterprise Risk Management Council.
baselineBidder should have at least 3 years' experience offering Information Security Services (security assessment, defining security policies/procedures/baselines, risk assessment, security consulting) to public sector Banks in India, evidenced by copy of purchase order.
baselinePerform a comprehensive Risk Assessment of DC/DR operations (and third-party relationships) on a yearly basis per a defined Risk Assessment methodology, hold periodic meetings with the Bank, and submit a granular, deficiency-specific Risk Mitigation Plan (generic recommendations to be avoided) based on industry best practices; actual risk remediation is out of scope but the Bidder must coordinate with the Bank's system integrator and provide handholding support until risks are remediated.
baselineProvide an analysis of the current security posture of the internally hosted and cloud-based systems, both public-facing and internal.
baselineAnalyze the security assessment findings and prepare documentation providing a detailed analysis of the desired security posture in relation to industry best practices, with a prioritized action plan.
baselineHave at least five (5) years of experience assessing security posture on hosts, networks, databases, and applications, with recent experience (within the past 3 years) providing security vulnerability and risk assessment services directly or through a partner relationship.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat risk-quantification methodology does the platform use — FAIR (Factor Analysis of Information Risk), a proprietary scoring model, or simple qualitative heat maps — and can risk be expressed in financial terms (expected annual loss) for executive/board reporting?Answer key — what a strong answer shows
Financial risk quantification (FAIR or equivalent) is materially more actionable for the board than red/yellow/green heat maps — look for a named, defensible methodology, not a black-box score.
RFPDescribe how the platform ingests and correlates findings from other tools (vulnerability scanners, CAASM, pentest results, compliance evidence) into one unified risk register, and provide a customer reference on de-duplication accuracy across sources.Answer key — what a strong answer shows
Risk assessment platforms live or die on integration breadth and correlation quality — look for named source integrations and a real de-dup accuracy figure, not a manual spreadsheet-import workflow.
RFIHow are risk scenarios modeled — can the platform simulate the impact of a specific threat against a specific asset/business process, or does it only aggregate generic control-gap scores?Answer key — what a strong answer shows
Scenario-based modeling (this threat, against this asset, given these controls) is far more decision-useful than an aggregate score with no causal story.
RFIWhat third-party/vendor risk assessment capability is included — can external vendors be scored using the same framework as internal risk, and is this integrated or a bolted-on separate module?Answer key — what a strong answer shows
Look for one unified framework covering both internal and third-party risk, not two disconnected products under one brand.
RFPDetail residual-risk tracking over time — as compensating controls or remediations are applied, does the platform show risk trending down with a defensible before/after calculation, and can this be exported as board-ready trend reporting?
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Strong answers show real before/after risk-reduction math tied to specific remediations, with exportable trend reporting — not just a re-run score with no explanation of what changed.
RFIHow does the platform handle risk appetite and tolerance thresholds — can different business units set different thresholds, and does the platform flag when a risk exceeds the organization's stated appetite?Answer key — what a strong answer shows
Look for configurable, business-unit-scoped thresholds with automatic appetite-breach flagging, not a single global threshold that doesn't reflect how real organizations vary risk tolerance.
RFPExplain regulatory/framework alignment — does the risk model map to NIST CSF, ISO 27005, or sector-specific frameworks, with evidence output an auditor can consume directly?Answer key — what a strong answer shows
Look for named-framework mapping with auditor-consumable evidence export, not a generic risk report that needs manual translation to whatever framework the auditor expects.
RFIWhat is the typical time-to-value — how long from deployment to a first credible, populated risk register, and how much of that requires manual data entry versus automated ingestion?Answer key — what a strong answer shows
Risk platforms often stall on manual population; look for a stated time-to-value figure dominated by automated ingestion, not months of manual workshops before the register is usable.
RFPIdentify threats and risk scenarios impacting IT systems, infrastructure, and data (Risk Identification).
RFIWhat is the pricing model — per asset scored, per user seat, or a flat enterprise tier — and how does cost scale as the organization's asset/risk-scenario count grows significantly?Answer key — what a strong answer shows
Look for transparent, predictable scaling economics; a vendor unable to project cost at meaningfully higher scale creates real budget risk for a growing risk-register scope.
RFPDoes a real, confirmed security incident automatically trigger a risk-register reassessment (updating the affected asset's risk score based on what actually happened), or does the risk register stay static until a manual periodic review cycle?Answer key — what a strong answer shows
A risk register that only updates on a manual review cadence, not in response to real incidents, quickly goes stale relative to actual current risk — ask for a concrete example of incident-driven reassessment.
RFIIs the platform's risk-quantification output used or accepted by cyber-insurance underwriters for coverage/premium decisions, and can the vendor cite a real customer example where this data influenced actual insurance terms?Answer key — what a strong answer shows
Real underwriter acceptance is a concrete, checkable claim distinct from a generic 'insurance-ready' marketing statement — press for a specific customer example.
RFPDetail board-level reporting cadence and format specifically — is there a maintained, presentation-ready board report generated automatically, or does the security team need to manually build board materials from raw platform data every cycle?Answer key — what a strong answer shows
A real, automatically-generated board-ready report is a meaningful time-saver distinct from raw dashboard access — ask to see an actual sample output, not just a description.
RFIWho within the customer organization gets access to the risk register itself, and is there role-based access control over it, given that a complete risk register is itself sensitive information (a map of the organization's worst weaknesses) if it fell into the wrong hands?Answer key — what a strong answer shows
A complete risk register is a meaningful target in its own right — role-based access control over the tool's own findings, not just over the underlying systems, is an often-overlooked consideration.
RFIDoes the platform support genuinely isolated, per-subsidiary risk registers for a multi-entity organization (different business units with different risk appetites and separate data), or is there only one flat, shared risk register across the whole organization?Answer key — what a strong answer shows
Genuine multi-entity isolation (separate registers, separate risk appetites) is materially more useful for a diversified organization than one shared register forcing a one-size-fits-all view.
RFPWhat correction/appeal process exists when a risk score is inflated or wrong (e.g., a compensating control the platform doesn't know about that actually mitigates the scored risk), and how quickly can an analyst adjust and document that correction?Answer key — what a strong answer shows
A risk score that can't be corrected when it's demonstrably wrong (missing context about a real compensating control) undermines trust in the whole register — ask for a concrete correction workflow.
RFIIs there a documented, accessible API for exporting the full risk register into the customer's own BI/reporting tooling, and is that a one-time pull or a continuously synced feed?Answer key — what a strong answer shows
A continuously synced API feed keeping the customer's own systems current is materially more valuable than a one-time export that goes stale immediately after the initial pull.
RFPAssess the design and operating effectiveness of key security controls (e.g., IAM, logging, endpoint protection, network segmentation) (Control & Configuration Review).
RFPProvide a thorough review of the port authority's Cybersecurity Program using the NIST Cybersecurity Framework (CSF) version 2.0 or future versions; document assessment results on a spreadsheet for each CSF control with risk findings rated high, medium, and low.
RFPWhat risks that are beyond your control do you see in providing this service and how would you mitigate them?
RFPConduct white-box testing for both a Cybersecurity Risk Assessment and a Penetration Test across eight of the housing authority's locations and fourteen departments, covering 10+ cloud applications, 2 web applications, AD, endpoints, and on-premises equipment for 500+ devices, targeting 350+ users, including phishing, vishing, smishing, and physical pretexting.
RFPValidate and document critical systems, applications, data types, and dependencies (Asset & Data Inventory, NIST CSF Identify).
RFPAnalyze current vulnerabilities using scan results, prior audits/test findings, and relevant threat intelligence (Vulnerability Review).
RFPRate risks by likelihood and business impact, and align ratings to the housing authority's internal risk register using a NIST RMF approach (Risk Rating & Prioritization).
RFPAssess alignment to NIST CSF and applicable requirements/frameworks (e.g., NIST SP 800-53, CJIS, and other applicable regulations/standards) (Compliance & Standards Alignment).
RFPProvide a prioritized remediation plan with owners, target timelines, and quick wins (Recommendations & Roadmap).
RFPDeliver a Cybersecurity Risk Assessment Report (PDF/Word) covering risks, vulnerabilities, threat scenarios, and a prioritized mitigation plan aligned to NIST CSF.
RFPProvide an Executive Summary: non-technical overview of key risks, business impact, and top priorities.
RFPProvide a Prioritized Action Plan: ranked remediation backlog with severity/criticality, effort level, and recommended sequencing.
RFPDeliver a Leadership Readout Presentation briefing results, themes, and recommended next steps.
RFPProvide details of the cybersecurity professionals who will be involved in the engagement, including qualifications, certifications (e.g., CISSP, CEH, OSCP), and experience (Team Qualifications).
RFPProvide a clear outline of the approach and methodology for both the Cybersecurity Risk Assessment and Penetration Test, including tools, techniques, and standards followed (e.g., NIST, OWASP).
RFPProvide a detailed project timeline for conducting the risk assessment and penetration test, including key milestones and deliverable dates.
RFPProvide a detailed and transparent breakdown of all pricing, including fees for services, tools, testing activities, optional/add-on services, and a fixed rate for skill-to-remediation support.
RFPProvide periodic network health check reviews with a deliverable report and debriefing upon completion.
RFPProvide periodic Information Security Assessments (ISA) on the housing finance agency's IT infrastructure, providing ISA ratings for each category in a deliverable report with debriefing.
RFPProvide Security Assessments covering network, firewall, switches, virtual infrastructure, and VoIP, and provide Firewall and Router Configuration Reviews.
RFPProvide Data Breach Risk Assessment and Response Plan Development, and Information Security Risk Assessment.
RFPProvide Physical Security Reviews.
RFPTask Area 1: Contractor shall provide integrated security compliance, vulnerability management, and risk support services, including ISSO support for security authorization activities, development/maintenance of security documentation, and support for RMF, Assessment and Authorization (A&A), and continued authorization lifecycle activities.
RFPVendor must provide Risk Management capability: evaluate risk levels across data storage, collection, and transmission with impact analysis and mitigation recommendations.
RFPManage IT risk assessments based on common cyber security frameworks (NIST CSF & 800 series, ISO 27001, GLBA and others).
RFPSupport enterprise risk management: collection, analysis and communication of high impact/high likelihood programmatic or operational risks across the enterprise.
RFPContractor shall provide resources with a working and holistic understanding and knowledge of the Risk Management Framework (RMF) as defined by NIST SP 800-53 and NIST SP 800-53A, and serve as the source of technical expertise with regard to maintaining and improving the organization's RMF implementation.
RFPContractor shall provide Assessment & Authorization (A&A) support for approximately 15 moderate baseline systems consisting of the organization's Enterprise Common Controls, organization-hosted systems, systems hosted on FedRAMP-authorized cloud platforms, and systems hosted on non-FedRAMP-authorized cloud services.
RFPContractor shall develop and maintain a plan for the organization's ISSM and CISO approval to maintain authorization or risk acceptance for all relevant systems, including achievement of Authorization to Operate (ATO) for new or significantly changed systems, in accordance with OMB, NIST, and FISMA guidance/regulations.
RFPContractor shall prepare A&A packages, including a System Security Plan (SSP) for each of the organization's systems; strategically advise on the restructuring/reordering of system boundaries for compliance packages; prepare risk management recommendations; and track POA&Ms internally and with system owners.
RFPContractor shall conduct internal risk assessments to ensure controls and countermeasures are identified to compensate for weaknesses to reduce risk to the organization's operations, assets, individuals, or stakeholders, and prepare risk determination statements outlining potential risk with planned or completed corrective actions.
RFPContractor shall serve as system liaison to the Security Controls Assessor (SCA), penetration tester, and for overall system security purposes for both internal and external parties, and compile documentation and supporting materials required for each system assessment, including SSP, Risk Assessment Report, Contingency Plans and Test Results, SORN, FIPS 199, Configuration Management Plan, Cybersecurity and Privacy Incident Response Plan, and Disaster Recovery Plan.
RFPContractor shall provide quarterly reports on A&A activities for Executive Briefing to the CIO and/or the organization's Enterprise Risk Management Council, including SCAs completed, penetration tests completed, and relevant POA&M updates.
RFPNo later than 18 months after award, Contractor shall develop a comprehensive plan to migrate systems from legacy A&A practices to Ongoing Security Authorization (OSA), leveraging NIST SP 800-37 (Risk Management), NIST SP 800-53 (Control Guidance), and NIST SP 800-137 (Continuous Monitoring), and recommend innovative ways to automate OSA activities such as automated control testing and results reporting.
RFPContractor shall be responsible for establishing and managing an IT Risk Management Program per OMB Circular A-123/A-130, including developing an IT Risk Management Program Charter and Plan, defining risk appetite and governance methodology, recommending an automated mechanism for capturing and tracking IT risks, and providing quarterly trending/metrics reports to the CIO and/or Enterprise Risk Management Council.
RFPBidder should have at least 3 years' experience offering Information Security Services (security assessment, defining security policies/procedures/baselines, risk assessment, security consulting) to public sector Banks in India, evidenced by copy of purchase order.
RFPPerform a comprehensive Risk Assessment of DC/DR operations (and third-party relationships) on a yearly basis per a defined Risk Assessment methodology, hold periodic meetings with the Bank, and submit a granular, deficiency-specific Risk Mitigation Plan (generic recommendations to be avoided) based on industry best practices; actual risk remediation is out of scope but the Bidder must coordinate with the Bank's system integrator and provide handholding support until risks are remediated.
RFPProvide an analysis of the current security posture of the internally hosted and cloud-based systems, both public-facing and internal.
RFPAnalyze the security assessment findings and prepare documentation providing a detailed analysis of the desired security posture in relation to industry best practices, with a prioritized action plan.
RFPHave at least five (5) years of experience assessing security posture on hosts, networks, databases, and applications, with recent experience (within the past 3 years) providing security vulnerability and risk assessment services directly or through a partner relationship.