Leadership, responsibility and oversight
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
The platform uses the NIST Cybersecurity Framework 2.0 as its main organising structure. Current CRAN and NAM-CSIRT reporting provides Namibian context. Information security management principles inform the attention given to leadership, people, policies, processes and technology.
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.
Each question carries a risk weight. “Yes” receives full credit, “Partly” receives partial credit, “No” receives none, and “Unknown” receives limited credit because uncertainty is itself a management concern.
The rules engine produces explainable findings and referrals. Any optional ML feature may improve wording or flag contradictions, but it does not replace the assessment rules or professional judgement.
| Score | Assessment position |
|---|---|
| 0 to 20 | Critical exposure |
| 21 to 40 | High risk |
| 41 to 60 | Developing controls |
| 61 to 80 | Reasonable controls |
| 81 to 100 | Strong controls |
CRAN’s Q2 2026 Cybersecurity Constituent Newsletter, published on 23 July 2026, reports 513,921 vulnerabilities and a 39.8 percent quarterly increase.
The six functions are Govern, Identify, Protect, Detect, Respond and Recover. They help organisations understand and communicate cybersecurity risk.
This platform does not provide ISO certification, penetration testing, vulnerability scanning, forensic investigation or technical assurance.