This guide contains everything you need to know about conducting an information security risk assessment questionnaire at your organization.
Isora GRC gives North Carolina executive agencies one connected workspace to operationalize the Statewide Information Security Manual. In Isora, teams can run NIST-aligned assessments, manage POA&Ms, track risks, and produce EGRC-ready reports for ESRMO oversight, all in one place.




























North Carolina’s Statewide Information Security Manual (NC SISM) requires every executive agency to implement security programs aligned with NIST SP 800-53 and the Risk Management Framework. Agencies must conduct annual risk assessments, maintain POA&Ms in the EGRC system, submit results within 30-day windows, and complete independent or self-assessments every three years.
Responsibility is distributed — NCDIT sets policy, agency CISOs execute, security liaisons coordinate — but the tools are disconnected. Assessments live in spreadsheets, POA&Ms live in separate trackers, vendor evidence sits in shared drives organized by date instead of by policy domain, and VRARs are completed but not linked to the systems they evaluate. When ESRMO requests a status update, the agency CISO assembles a response from five different files, hoping the numbers reconcile. Spreadsheets and shared drives simply weren’t designed for the level of coordination NC SISM requires across a distributed compliance program.
Launch structured assessments using prebuilt questionnaires aligned to NIST SP 800-53 control families and SCIO-SEC policies 301–318. Target agency departments, systems, and data repositories. Collect evidence inline — access control documentation, encryption records, incident response procedures — so responses and proof stay connected. Support both the annual assessment requirement and the three-year independent assessment cycle with recurring campaigns.
Build the inventory foundation SISM compliance requires. In Isora, every system, application, and vendor record links to its assessments, risks, POA&Ms, and documentation. Track Vendor Readiness Assessment Reports (VRARs) and third-party attestations (FedRAMP, SOC 2, ISO 27001) in the same workspace. When procurement or ESRMO asks about a vendor's security posture, the VRAR, assessment history, and risk rating are connected — not scattered across shared drives.
Publish control gaps that surfaced during the assessment directly to the risk register and POA&M tracker. In Isora, every finding carries lineage across the SCIO-SEC policy it maps to, the NIST 800-53 control it references, the assessment that surfaced it, and the system it applies to. From there, teams can assign owners, set remediation milestones, and track progress toward submitting POA&M results to ESRMO within the 30-day window.
Generate reports that pull directly from live assessment scores, POA&M status, risk register entries, and inventory records. Demonstrate control implementation status, remediation progress, and program maturity across the agency. Produce structured outputs aligned to EGRC submission requirements and SCIO-SEC policy families. In Isora, reports export in formats ready for ESRMO review, State CIO oversight, and agency leadership briefings.
State Information Security Regulations: Complete Guide Across the U.S., all fifty state governments have issued their own state information security...
All of North Carolina SISM's (Statewide Information Security Manual) requirements, controls, implementation steps for agency compliance.
The Statewide Information Security Manual (SISM) establishes minimum cybersecurity requirements for all North Carolina executive-branch agencies, departments, and institutions. Issued under the authority of the State CIO and enforced by ESRMO, SISM aligns with NIST SP 800-37 (Risk Management Framework) and NIST SP 800-53 Rev. 5 (Security and Privacy Controls). SCIO-SEC policies 301–318 define the control domains agencies must implement.
SCIO-SEC policies 301 through 318 translate NIST SP 800-53 control families into enforceable, North Carolina-specific standards. Each policy governs a security domain — access control, risk assessment, incident response, system integrity — and defines implementation requirements for executive agencies. Together with SISM, they form the operational framework for statewide cybersecurity compliance.
Agencies must submit risk assessment results and remediation plans to ESRMO within 30 days of completion through the EGRC system. Isora generates structured reports aligned to EGRC submission requirements, consolidating assessment findings, POA&M status, and continuous monitoring data into exports ready for ESRMO review.
SISM requires agencies to complete independent or self-assessments at least every three years. Isora supports both approaches with NIST-aligned questionnaire templates, recurring campaign scheduling, structured evidence capture during assessments, and remediation tracking. Agencies document assessment cycles, track POA&M closure, and demonstrate continuous improvement across multiple review periods in one platform.
Yes. Isora tracks Vendor Readiness Assessment Reports (VRARs), third-party attestations (FedRAMP, SOC 2, ISO 27001), and contract controls required under SISM. Each vendor record links to associated assessments and risks, providing complete visibility into third-party compliance and supporting ESRMO vendor oversight.
Isora deploys in weeks, not months. No-code setup, no consultants, no dedicated admin headcount. Agencies can run their first NIST-aligned assessment within days of onboarding. Prebuilt NIST SP 800-53 questionnaire templates map to SCIO-SEC policy families out of the box.