01
Qualify the context
Identify critical assets, feared events, dependencies, exposure and operating constraints.
Vulnerabilities & risk
Prioritize CVEs, hardening gaps and risk scenarios by exposure, business impact and operating constraints.
01
Identify critical assets, feared events, dependencies, exposure and operating constraints.
02
Describe threat sources, attack paths, likelihood, impacts and existing measures.
03
Produce a backlog that connects CVEs, exposure, affected assets, actions, correction evidence and residual risk.
Deliverables
risk scenarios
CVE/remediation backlog
KPI/KRI
residual-risk decisions