A documented starting point
- Platform and service inventory.
- Current controls, responsibilities and dependencies.
- Prioritised actions linked to business services and owners.
Evidence of accepted changes
Record the approved change, implementation result, validation and rollback position. Identify excluded systems. A configuration score is one input; it does not establish that every relevant threat is controlled.
A service record you can review
- Coverage and source health, where monitoring is contracted.
- Incident or case records with escalation and ownership.
- Risks, exceptions and remediation dependencies.
- Leadership decisions and agreed improvement actions.
Measures that support decisions
Define how each measure is calculated and what it excludes. Acknowledgement, triage and containment times describe different events. Raw alert counts do not show whether a critical service has the required protection.
Inspect the catalogue
Preview the 28-page service catalogue for workstreams, procurement questions, responsibility models and the 62-service source index.

