This guide contains everything you need to know about conducting an information security risk assessment questionnaire at your organization.
Isora GRC gives security teams one connected workspace to assess cybersecurity practices, collect evidence, and track risks and remediation for Florida public sector cybersecurity programs.




























Meeting § 282.318 and § 282.3185 is difficult when control assessments, asset inventories, and the risk register live in separate spreadsheets that were never reconciled with each other. When an audit or incident triggers a review, reconstructing the compliance picture takes weeks.
Launch assessments using prebuilt questionnaires aligned to Florida's Cybersecurity Standards (Chapter 60GG-2) and NIST CSF Functions. Target every agency unit, system, and data repository in scope, and collect access control policies, encryption documentation, and training records inline so responses and proof stay connected. Recurring cycles document continuous compliance between audit periods.
Every asset, application, and vendor record links to its assessments, risks, and documentation. Classify systems by FIPS 199 impact level, low through high, to drive assessment scoping and control selection, and track vendor relationships with linked questionnaires and attestations. When DMS or FDLE asks which systems handle sensitive data, the answer is structured and current.
Publish a control gap to the risk register as soon as an assessment identifies it, and each risk carries lineage back to the Chapter 60GG-2 control it maps to and the system it applies to. Assign owners, set deadlines, and track remediation while an append-only audit log documents every action.
Generate reports and scorecards that pull from live assessment data, risk register entries, and inventory records to show assessment completion, control effectiveness, risk ratings by system, and remediation progress. Export packages aligned to DMS submission requirements, FDLE notification documentation, and agency leadership briefings.
State Information Security Regulations: Complete Guide Across the U.S., all fifty state governments have issued their own state information security...
The Florida Cybersecurity Act (Chapter 282, Section 318, F.S.) establishes cybersecurity requirements for state agencies. The Local Government...
The State Cybersecurity Act (§ 282.318) requires state agencies to conduct formal risk assessments, implement controls aligned to the State of Florida Cybersecurity Standards (Chapter 60GG-2, F.A.C.), and report to the Department of Management Services (DMS). The Local Government Cybersecurity Act (§ 282.3185) extends cybersecurity requirements to local governments, including incident reporting to the Florida Department of Law Enforcement (FDLE). Isora GRC provides the assessment, risk tracking, inventory management, and reporting workflows to operationalize both statutes.
Isora includes prebuilt questionnaires mapped to Chapter 60GG-2 control areas and NIST CSF functions. Agencies can launch assessments immediately without building templates from scratch. Templates cover the statutory control domains, including asset management, encryption, access controls, training, and incident response, and are customizable for agency-specific requirements.
Isora’s inventory management supports FIPS 199 impact level classification (low, moderate, high) for systems, applications, and data repositories. Classification drives assessment scoping and control selection, so agencies apply the level of rigor Florida’s cybersecurity standards set for each data sensitivity and system criticality tier.
Yes. Isora generates reports from live assessment and risk data. Agencies can produce outputs aligned to DMS submission requirements and FDLE notification documentation without manual compilation. Reports include assessment completion rates, control effectiveness, risk ratings, and remediation progress with drill-down to underlying evidence.
§ 282.3185 requires local governments to report ransomware incidents and severity level 3 to 5 incidents within specified timelines. Reports go to the Cybersecurity Operations Center, FDLE, and the local sheriff. Isora’s audit trail and risk register document the timeline of incident discovery, assessment, and response, providing the evidence trail that supports timely notification and post-incident review.
Isora deploys in weeks with no-code setup, minimal IT lift, and no outside consultants. Agencies can run their first Chapter 60GG-2 assessment within days of onboarding, because the prebuilt questionnaire templates remove the template-building step.