Step 2: What is the state of your written Information Security Policies?
Step 3: Can you precisely trace where your CUI, Federal Contract Information (FCI), or sensitive customer data lives?
Step 4: How do you evaluate the cyber posture of your subcontractors or third-party vendors?
Step 5: How often are your security controls audited or independently reviewed?