Why a worksheet matters
Many businesses can say they use multifactor authentication, backups, antivirus protection, and security training. Fewer can show when those controls were reviewed, who reviewed them, what exceptions were found, and whether the exceptions were corrected.
Evidence does not need to be complicated. A dated export, screenshot, ticket, meeting note, test result, or signed approval may be enough to demonstrate that a task occurred. The point is not paperwork for its own sake. The point is to create reliable memory for the business and a clear starting point after an incident.
Use this worksheet monthly for high-risk items and quarterly for broader reviews.
Section one: ownership and scope
Record the following:
- Review date.
- Person completing the review.
- Business owner approving follow-up.
- Systems included and excluded.
- Technology provider involved.
- Open exceptions carried from the previous review.
If a system is excluded, record why. “Not reviewed” is more useful than an undocumented assumption.
Section two: identity and access
For each important service, verify:
- Administrator accounts are assigned to named individuals.
- Multifactor authentication is enabled for administrators and users.
- Former employees and contractors have been removed.
- Shared accounts have been eliminated or formally approved.
- High-risk applications and integrations are still needed.
- External guest access is known and reviewed.
- Password-reset and recovery methods point to current contacts.
- Emergency or break-glass accounts are protected and monitored.
Evidence examples include an access-review export, account list, approval record, or service ticket. Do not place passwords or authentication secrets in the worksheet.
Section three: devices and software
Confirm that:
- Business laptops and desktops are inventoried.
- Encryption is enabled where supported.
- Endpoint protection is active and reporting.
- Operating systems and browsers are supported and patched.
- Remote-management tools are documented.
- Personal devices accessing business data are governed by written rules.
- Lost or stolen devices can be locked or wiped when appropriate.
- Unsupported equipment has an owner and replacement plan.
A device inventory should include the responsible person, business purpose, operating system, last check-in, and replacement status. It does not need to include unnecessary personal information.
Section four: data and backups
List the business data that would cause the greatest disruption if unavailable or exposed. Examples include payroll, tax records, customer files, contracts, financial statements, health information, legal matter files, and credentials.
For each category, record:
- Where it is stored.
- Who can access it.
- How long it must be retained.
- Whether it is encrypted.
- How it is backed up.
- How it would be restored.
- Who approves deletion or destruction.
Perform a small restore test. Record the date, data restored, result, time required, and corrective action. A successful backup job is not the same as a successful recovery.
Section five: awareness and fraud controls
Review whether employees know how to report suspicious messages and whether the business verifies sensitive requests through a second channel. Pay particular attention to:
- Bank-account changes.
- Payroll changes.
- New vendor payment instructions.
- Urgent gift-card requests.
- Password-reset messages.
- Unexpected shared documents.
- Requests for tax forms or identity documents.
Training evidence may be a dated attendance record, learning-platform report, or staff acknowledgment. Avoid treating a single annual presentation as proof that the process works.
Section six: findings and follow-up
For each issue, record:
- What was observed.
- The affected system or process.
- The business consequence.
- Risk rating and rationale.
- Owner.
- Due date.
- Temporary measure.
- Verification method.
- Closure date.
Use plain language. “Former contractor account remained enabled after project completion” is better than “identity hygiene gap.”
What the worksheet can and cannot prove
The worksheet can show that a review was performed and that management responded to identified issues. It cannot prove that a business is immune to attack, that a vendor is fully secure, or that a regulatory obligation has been satisfied. Those conclusions require a fact-specific assessment.
NIST describes cybersecurity as risk management, while CISA emphasizes practical actions for smaller organizations. A review worksheet translates those principles into repeatable office operations.
Store completed reviews in a controlled location with limited editing rights. Keep prior versions so management can see whether recurring findings are improving. The most valuable worksheet is not the prettiest one; it is the one that leads to decisions and verified follow-through.
