| Enterprise risk | Which cyber scenarios could materially affect critical objectives? | Top risk exposure by scenario; change in estimated impact and likelihood; risks above tolerance; treatment decision due. | Cybersecurity risk register, enterprise risk register, business impact analysis, approved risk criteria. | Do not average unlike scenarios. Show business service, risk owner, assumptions, treatment, and uncertainty. |
| Identity | Can attackers reach privileged or sensitive systems with weak authentication? | Phishing-resistant MFA coverage for privileged and high-risk users; stale privileged accounts; conditional-access exceptions. | Identity directory, role inventory, authentication-method registration, sign-in and policy records. | Separate enrolled from enforced. Reconcile the population to HR, contractor, service-account, and privileged-role sources. |
| Endpoint and server | Are managed assets visible, protected, and reporting recently? | EDR healthy coverage; telemetry freshness; unsupported systems; critical protection exclusions; unmanaged asset count. | Asset inventory, endpoint platform, RMM, server inventory, exception register, discovery scans. | Coverage is meaningful only when the denominator is complete and health has a defined freshness window. |
| Exposure and vulnerability | Which exploitable weaknesses threaten important services? | Internet-facing known-exploited vulnerabilities; overdue critical findings by business criticality; median age; validation rate. | External attack-surface inventory, vulnerability scanner, CISA KEV catalog, CMDB, remediation tickets. | Do not rank by severity alone. Combine exploitability, exposure, asset criticality, compensating controls, and fix validation. |
| Detection and response | Can the organization identify and contain significant events? | Material or high-impact incidents; time to validate and contain; recurrence; open post-incident actions; tested use cases. | SIEM, EDR, incident record, case-management timestamps, lessons-learned register, detection tests. | Averages can hide severe outliers. Show distribution, business impact, severity criteria, and major cases separately. |
| Resilience and recovery | Can critical services be restored within approved objectives? | Protected workload coverage; immutable or isolated copy coverage; restore tests meeting RTO and RPO; unresolved test defects. | Backup platform, recovery plan, business impact analysis, restore-test record, recovery ticket and validation evidence. | Successful backup jobs are not equivalent to successful recovery. Report tested restoration against a defined service objective. |
| Third-party and cloud | Where does dependency or concentration risk exceed tolerance? | Critical vendors with current review; overdue high-risk findings; unsupported integrations; privileged vendor access; concentration exposure. | Vendor inventory, contracts, assessments, identity logs, cloud inventory, issue register, exit and continuity plans. | Count only vendors with a defined criticality model. Distinguish questionnaire completion from verified control evidence. |
| Governance and treatment | Are risk decisions owned, funded, and closed on time? | Overdue remediation by risk; exception age and expiration; funded versus unfunded treatment; CSF Current-to-Target Profile gaps. | Risk and exception registers, project portfolio, budget decisions, control test results, CSF Profiles. | A closed ticket is not proof of risk reduction. Require revalidation evidence and record residual risk. |