Company Profile
The organizational scope informs the risk assessment, control selection, and report tailoring.
Legal entity name used on the compliance report.
Person accountable for the security program.
Self-assessed maturity using a CMM-style scale.
Examples: PII, PCI, PHI, intellectual property.
Critical systems in scope for the assessment.