Section 1 of 5 Answers save as you choose them.

Foundation and policies

Foundation and policies

1. Do you have written security policies that employees can find - e.g. information security, acceptable use, data handling?

We mean actually written down in a doc or wiki, not just understood by the team.

2. Have all current employees and contractors signed off on those policies in the last 12 months?

A documented acknowledgment - email confirmation, signed PDF, or a tool that tracks it - is what we mean.

3. Is there one named person responsible for security at the company?

At small teams this is usually the CTO or a technical founder. It just needs to be someone, on paper.