This guide contains everything you need to know about conducting an information security risk assessment questionnaire at your organization.
Isora GRC helps Ohio’s counties, municipalities, and special districts implement and maintain cybersecurity programs that meet ORC § 9.64, with risk assessments aligned to NIST CSF and the CIS Controls, a connected system and vendor inventory, risk tracking and remediation with assigned owners, and program documentation for the Auditor of State produced from that same record, all in one place.




























Building the six required program components for ORC 9.64 is difficult when the system inventory, risk register, incident procedures, and training records live in separate spreadsheets and shared drives. When the Auditor of State opens an audit cycle, teams must gather documentation from files that were never designed to connect.
Launch risk assessments using prebuilt questionnaires aligned to NIST CSF and the CIS Controls, the two frameworks the statute names. Target departments, systems, and service providers, and collect policies, procedures, and training records inline so responses and proof stay connected. Recurring cycles keep the program current between audits.
Every system, application, and vendor record links to its assessments, risks, and documentation, with critical function designations, dependencies, and owners captured alongside it. ORC 9.64 calls for a complete inventory of systems and interdependencies, and that inventory stays current because maintaining it is part of the assessment workflow.
Publish a gap to the risk register as soon as an assessment identifies it. Every finding carries lineage back to the program component it maps to, the assessment that surfaced it, and the system it affects. Assign owners, set completion dates, and track progress while an append-only audit log records every decision.
Generate reports and scorecards that pull from live assessment scores, risk register entries, inventory records, and training completion. Show coverage across all six program components without weeks of manual assembly, and drill into any metric to reach the assessment response behind it.
State Information Security Regulations: Complete Guide Across the U.S., all fifty state governments have issued their own state information security...
Complete guide for Ohio ORC § 9.64 requirements including deadlines, program components, incident reporting, and compliance strategies.
Ohio Revised Code § 9.64 requires every political subdivision to adopt a cybersecurity program covering six components, which are risk identification and critical functions, impact assessment, threat detection, incident response, infrastructure repair and maintenance, and employee training. The statute directs subdivisions to build programs consistent with NIST CSF and the CIS Controls, leaving control selection to each subdivision. Isora GRC provides the assessment, inventory, risk tracking, and reporting workflows to operationalize those components.
The law covers counties, municipalities, townships, and special districts, while state agencies fall under ORC § 125.18 instead. It took effect September 30, 2025, and audits of counties and municipalities began January 1, 2026. All other subdivisions were required to adopt a program by July 1, 2026.
Isora includes prebuilt questionnaires mapped to NIST CSF functions and CIS Control safeguards, so a subdivision can launch an assessment without building templates first. Because ORC 9.64 asks for programs consistent with these frameworks, assessments can usually be scoped to the size, mission, and risk profile of each subdivision.
Isora maintains the record behind both notifications, including the incident response procedures, the systems affected, the risks and remediation actions tied to an event, and the audit log documenting each step. That record supplies the documentation for the seven-day Ohio Cyber Integration Center (OCIC) notification and the thirty-day Auditor of State submission, though the subdivision files them.
Political subdivisions remain accountable for the program regardless of who operates the controls, so a managed service provider arrangement still has to be documented. Isora tracks service providers in the same inventory as internal systems, keeping provider assessments, contract terms, and associated risks alongside the rest of the program record.