Understand what must be protected
Identify processes, information, identities and services whose compromise or unavailability would cause relevant impact.
- Critical assets and services.
- Users, third parties and privileged access.
- Recent changes that altered exposure.
Review available visibility
Determine which events can be observed today, who reviews them and how a signal becomes an action.
- Available logs and alerts.
- Analysis, escalation and communication owners.
- Evidence from prior exercises or incidents.
Agree on the assessment outcome
Define whether you need executive prioritization, technical validation, architecture design or an implementation roadmap.
