Server Administration Self Assessment Scorecard (SASAS)

This scorecard will guide you through a brief review of your server administration practices, and may help you to identify ways to improve your server's security and availability.

Note: Completion of this self-assessment is not a replacement for a professional detailed risk analysis and operational review.

Section I. Server Hardware

____ QI-1. Server hardware:

____ QI-2. Server age:

____ QI-3. Server capacity:

____ QI-4. Server redundancy:

____ QI-5. Server maintenance:

____ QI-6. Server access control:

____ QI-7. Server power:

____ QI-8. Server air conditioning:

_____ QI-9. Fire detection and suppression:

Section II. Operating System

____ QII-1. Operating system version:

____ QII-2. Operating system patch status:


____ QII-3. Automatic patch application:

____ QII-4. Unneeded network services:

____ QII-5. File sharing:

____ QII-6. Firewalls:

____ QII-7. Checksumming of critical system files:

____ QII-8. Antivirus/Antispyware:

____ QII-9. MS Baseline Security Analyzer v2:

Section III. Accounts/Passwords

____ QIII-1. Account Creation and Deletion:

____ QIII-2. Passwords:

____ QIII-3. Password encryption:

____ QIII-4. Acceptable use policy:

Section IV. Application Software

____ QIV-1. Software licensing:

____ QIV-2. Locally developed applications:

____ QIV-3. Change control:

Section IV. Network

____ QIV-1. IP address:

____ QIV-2. Hardware firewall:


____ QIV-3. Network capacity:

Section V. Staffing

____ QV-1. System administration:

____ QV-2. Coverage:

Section VI. Operational Practice

____ QVI-1. Server documentation:

____ QVI-2. Server monitoring:

____ QVI-3. Maintenance windows:

____ QVI-4. User communication:

____ QVI-5. Data on the server:

____ QVI-6. Backups:

____ QVI-7. Disaster recovery:


Total score (sum all items): ______ out of 185 possible total points.

Interpretting your score:

v0.2 March 28th, 2006