Who owns each critical system, dataset, security control, and escalation decision?
Evidence guide
Questions that reveal more than a posture score
This checklist is a conversation aid, not an assessment, penetration test, risk rating, or compliance determination. Good answers point to current evidence, named owners, and tested procedures.
Can we show that privileged access is limited, reviewed, and protected with strong authentication?
Do we maintain a current inventory with business criticality, owner, exposure, and lifecycle state?
Which events are logged, who reviews them, and what evidence proves that the review occurs?
Are containment actions rehearsed, human-approved, reversible, and protected by explicit stop conditions?
When were backups last restored in a test, and what did that test actually demonstrate?
Which third parties receive data or access, and how are those dependencies reviewed?
Which incidents, exercises, and control failures have produced a documented change?