A management prompt. Follow the firm’s security program and consult qualified security professionals for technical controls.
| Done | Action | Owner or notes |
|---|---|---|
| Inventory systems, devices, data stores, vendors, and accountable owners. | ||
| Classify client, employee, financial, and project information under firm policy. | ||
| Use unique accounts and multifactor authentication where supported. | ||
| Grant access by role and remove access promptly when roles change. | ||
| Confirm backups, restore responsibilities, and recovery procedures are documented. | ||
| Review vendor access, data handling, retention, and incident terms. | ||
| Train staff to report suspicious messages, lost devices, and suspected exposure. | ||
| Document incident contacts and escalation steps. | ||
| Review data retention and secure disposal practices. | ||
| Schedule periodic access and control reviews with a qualified owner. |
Educational information only, not engineering, legal, tax, or investment advice. Licensed PE judgment and applicable local codes govern project decisions. Calculators and planning frameworks provide estimates only.
Print or copy the relevant list, assign an owner, and record follow-up actions. These checklists help organize work; they do not certify readiness, suitability, safety, or compliance.
