TJFDigital Systems Risk Assessment
Review environmentTechnical review by SALT Essential IT (Technical Partner)Demo data only
Assessment methodology

A plain language framework supported by recognised risk principles

The platform uses the NIST Cybersecurity Framework 2.0 as its main organising structure. Current CRAN and NAM-CSIRT reporting provides Namibian context. Information security management principles inform the attention given to leadership, people, policies, processes and technology.

Logical framework diagram
Govern

Leadership, responsibility and oversight

The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.

Identify

Knowledge of systems, information and risks

The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.

Protect

Safeguards for accounts, devices, information and backups

The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.

Detect

Ability to notice and report warning signs

The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.

Respond

Preparedness to act during an incident

The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.

Recover

Ability to restore operations and learn from disruptions

The questions assess whether relevant responsibilities and practices are established, understood and consistently applied.

How scoring works

Weighted responses

Each question carries a risk weight. “Yes” receives full credit, “Partly” receives partial credit, “No” receives none, and “Unknown” receives limited credit because uncertainty is itself a management concern.

Transparent logic

The rules engine produces explainable findings and referrals. Any optional ML feature may improve wording or flag contradictions, but it does not replace the assessment rules or professional judgement.

ScoreAssessment position
0 to 20Critical exposure
21 to 40High risk
41 to 60Developing controls
61 to 80Reasonable controls
81 to 100Strong controls

Public reference base

CRAN and NAM-CSIRT

CRAN’s Q2 2026 Cybersecurity Constituent Newsletter, published on 23 July 2026, reports 513,921 vulnerabilities and a 39.8 percent quarterly increase.

Direct CRAN source link

NIST CSF 2.0

The six functions are Govern, Identify, Protect, Detect, Respond and Recover. They help organisations understand and communicate cybersecurity risk.

Direct NIST framework link

Assessment boundary

This platform does not provide ISO certification, penetration testing, vulnerability scanning, forensic investigation or technical assurance.