Survey
2
Email address
Email address
4
Total number of staff
The number of staff (approximation is fine), both full-time and part-time, that use technology at your organization. Total number of staff
5
Who is most responsible for your organization's technology management and support?
Who is most responsible for your organization's technology management and support?
In-house IT staff
Outside consultants
Both in-house IT staff and outside consultants
Other
6
What is the annual operating budget of your organization?
What is the annual operating budget of your organization?
Under $500,000
$500,000 to $1,000,000
$1,000,000 to $2,000,000
$2,000,000 to $5,000,000
$5,000,000 to $10,000,000
Over $10,000,000
7
Technology planning
The organization engages in regular technology planning that is informed by strategic and operational goals.
Response Guidelines:
No strategic technology planning
Informal, ad-hoc planning
A strategic technology plan has been conducted within past 5 years
Strategic technology planning is conducted annually (or ongoing)
Technology is included in organizational strategic planning
Technology planning
8
Onboarding and offboarding
There is a documented process and policy in place regarding the onboarding and offboarding of personnel. This includes procedures for necessary hardware, accounts, training and support.
Response Guidelines:
No onboarding/offboarding procedures
Informal onboarding/offboarding procedures
Documented, but incomplete onboarding/offboarding procedures
Documented and thorough onboarding/offboarding procedures
Through onboarding/offboarding including feedback process for improvements
Onboarding and offboarding
9
Project ownership
All technology projects have a designated project lead who is responsible for managing resources and ensuring that projects stay in scope, on time and within budget.
Response Guidelines:
Ad hoc project ownership
Informal ownership for larger projects
Ownership for all projects with a mix of processes
Ownership and clear processes in place for all projects
Ownership, clear processes and all projects include continuous learning and improvement
Project ownership
10
Training program
New staff, interns and volunteers receive training on the organization's systems as part of a new hire orientation and the organization provides ongoing training to staff as part of their professional development.
Response Guidelines:
No technology training provided
Some basic training from staff
Technology training overview
Formal onboarding training provided
Ongoing formal training offered to all staff
Training program
11
Available technology support
Personnel have a clear process for submitting technology support requests and are able to have clear expectations for response time on these requests.
Response Guidelines:
No technology support provided
Reactive support provided by vendor
Most support provided by internal resource or "accidental techie"
Ongoing support provided by technology vendor
Ongoing support from technology service provider and internal resource
Available technology support
12
Complete this question: "In the area of technology management, our biggest challenge is..."
(Optional)
Complete this question: "In the area of technology management, our biggest challenge is..."
13
Staff workstations
Staff have workstations that are reliable and well-performing. Staff are not hindered in their work by slow or unreliable workstations.
Response Guidelines:
Many workstations are old, poor performing and unreliable
Some workstations are slow and/or unreliable
Few workstations are slow and/or unreliable
Workstations meet meet staff needs with few exceptions
Workstations are high quality and seldom cause staff any issues
Staff workstations
14
Internet bandwidth and networking
Internet and networking is fast and reliable throughout the organization, both via wireless (wi-fi) and wired networking.
NOTE: If you support work-from-home (WFH) or are a predominately remote work organization, this questions applies to the home/office networks from where your personnel work.
Response Guidelines:
Network, Internet and wireless are slow and/or highly unreliable
Network, Internet and wireless are slow and/or somewhat unreliable
Network, Internet and wireless are of reasonable speed and mostly reliable
Network, Internet and wireless are fast and mostly reliable
Network, Internet and wireless are fast and completely reliable
Internet bandwidth and networking
15
Remote working / work from home
Staff are able to securely and reliably work remotely and/or from home and are able to access email, documents, applications and data as appropriate to their role.
Response Guidelines:
There is no ability to work effectively and securely outside the office
There is limited ability to work effectively and securely outside the office
There is some ability to work effectively and securely outside the office
There is good ability to work effectively and securely outside the office
There is near perfect support for working effectively and securely outside the office
Remote working / work from home
16
Backup and restore
Our organization's important information is backed up securely and restore tests are performed.
Response Guidelines:
Backup systems unknown
There are backups, but limited documentation and no testing
There are backups and documentation, but no testing
Backups are documented and tested for integrity
Backups are documented, tested, and backup requirements are reviewed annually
Backup and restore
17
Business continuity
Leadership demonstrates an understanding of its most critical technology services and how those services may be impacted by various disruptive events.
Response Guidelines:
No business continuity planning
Some informal business continuity planning with limited documentation
There is a business continuity plan, but not reviewed
Business continuity plan exists and is reviewed/revised annually
Business continuity plan is reviewed annually and tabletop exercises peformed
Business continuity
18
Complete this question: "In the area of infrastructure, our biggest challenge is..."
(Optional)
Complete this question: "In the area of infrastructure, our biggest challenge is..."
19
Data leader / administrator
There is an identified owner, such as a Data Leader or Database Administrator, who is responsible for overseeing the organization's data system(s).
Response Guidelines:
No organizational data systems
Data is departmentally owned and managed
Data is departmentally owned with informal organizational oversight
Data team is responsible for overseeing data on organization-wide basis
A data leader(s) is responsible for overseeing a data team
Data leader / administrator
20
Centralized decision-making
The organization has a framework for centralized, cross-departmental decision-making regarding data systems.
Response Guidelines:
No data systems in place
Decision-making made at the individual or departmental level
Decision-making is mostly departmental with some cross-departmental input or collaboration
Decision-making is mostly made centrally with some processes for departmental input
Consistent cross-organizational process exists for making all or most data-related decisions
Centralized decision-making
21
Data collection process and management
There is a clear framework in place and established standards on agency-wide data collection and management.
Response Guidelines:
No organizational data systems
No data standards other than those that are system-required
Some data standards based on organizational reporting needs
Data standards are defined and socialized across staff
Data standards are defined and data is routinely scrubbed
Data collection process and management
22
Relevant reports
Staff are able to access relevant real-time reports directly from the system(s).
Response Guidelines:
No organizational data systems
Reports are not available or used by most staff
Some reports are available to most staff
Some reports available and process for staff to request reports
Staff are able to generate relevant reports on demand
Relevant reports
23
Success metrics
Data is used across the organization to evaluate performance, drive decision making and set departmental/organizational goals.
Response Guidelines:
No data system
Metrics exist primarily to satisfy funder requests
Metrics used by departmental leaders for internal evaluation
Metrics used by staff across the organization for evaluation and planning
Metrics are a common organizational language for evaluating performance, identifying areas of growth and testing assumptions
Success metrics
24
Complete this question: "In the area of data, our biggest challenge is..."
(Optional)
Complete this question: "In the area of data, our biggest challenge is..."
25
Cybersecurity program
Our organization has an active cybersecurity program.
Response Guidelines:
No cybersecurity program exists in any form
Informal and inconsistent cybersecurity activities performed
Cybersecurity assessment performed at some point within past 1-2 years
Cybersecurity is part of ongoing strategic technology planning
Documented cybersecurity plan in place with measurable goals and monitoring
Cybersecurity program
26
Cybersecurity awareness training
All staff at our organization have received cybersecurity awareness training within the past year.
Response Guidelines:
No awareness training provided at any point
Some staff have sought out awareness training on their own
Staff have been provided at least one security awareness training within past year
Staff are provided awareness training as part of onboarding and ongoing.
Awareness training program is active and ongoing and measured for effectiveness
Cybersecurity awareness training
27
Cyber liability Insurance
Our organization has reviewed options for cyber liability insurance and is confident the appropriate coverage is in place.
Response Guidelines:
Unknown or no cyber liability
N/A
Cyber liability policy included, but not reviewed
N/A
Cyber liability policy included and reviewed annually to ensure adequate coverage
Cyber liability Insurance
28
Two-factor authentication (2FA)
Multi-Factor Authentication (MFA) / Two-Factor Authentication (2FA) is required for access to all systems, services and applications that support MFA/2FA and contain sensitive information.
Guide to response
No MFA/2FA encouraged or enforced on any systems/services
Some staff use MFA/2FA on some systems/services
MFA/2FA enforced for all staff email, at a minimum
MFA/2FA enforced on most critical systems (email, CRM, file sharing & finance)
MFA/2FA enforced on all systems containing sensitive information
Two-factor authentication (2FA)
29
Patch management
The organization uses a patch management system to keep endpoints patched with current software versions.
Guide to response
No patch management at all
Staff are encouraged to patch their workstations
Workstations are configured to receive automatic updates
We have a patch management system, but do not review it regularly
We have a patch management system and review it regularly
Ideally, a patch management solution that addresses Windows and Macs, servers, desktops and laptops and also handles third-party applications such as Adobe, Java & MS Office.
Patch management
30
Complete this question: "In the area of cybersecurity, our biggest challenge is..."
(Optional)
Complete this question: "In the area of cybersecurity, our biggest challenge is..."
31
Digital communications plan
A digital communications plan is in place (e.g. goals, objectives, audiences, key messaging, timelines, measurement/tracking and budget) and followed at our organization.
Response Guidelines:
No communications plan
Departmental communications are deployed and not coordinated
Departmental communications are deployed, and these efforts are coordinated and timed
Organization-wide communications guidelines are in place and most follow it
An organization-wide communications plan is in place, followed and reviewed regularly
Digital communications plan
32
Dynamic website
The organization maintains a dynamic website, and appropriate organizational staff are able to update the website with new content.
Response Guidelines:
No organizational website
Website is out-of-date and consists of static pages
Website is functional but only an outside developer can make editorial changes
Website utilizes a Content Management System (e.g. WordPress, Drupal, Joomla), is mobile optimized and content can be updated by staff with some coding skills
Website utilizes a Content Management System, is fully mobile optimized and content is easily updated without coding skills
Dynamic website
34
Targeted email communications
The organization's email list is segmented to allow specific groups to be targeted with appropriate and relevant messages.
Guidelines:
No email system exists for centralizing communications
Email system is used to broadcast messages to a full list
Email system is used to send emails to specific groups, but the data is not integrated
Email system is used to send emails to specific groups and data is integrated and updated
Email system is fully integrated with central data system and communications are highly personalized
Targeted email communications
35
Email communications metrics
The organization conducts regular analysis of their e-communications activities.
Response Guidelines:
Communications metrics are not tracked
Basic metrics such as open rates, click-through's are informally reviewed
Basic metrics are formally reviewed
Engagement metrics, such as conversion rate, used informally reviewed
Engagement metrics are regularly reviewed and provide insight on recipients
Email communications metrics
36
Complete this question: "In the area of digital communications, our biggest challenge is..."
Complete this question: "In the area of digital communications, our biggest challenge is..."