Risk Assessment Checklist

Decision Preparation

A practical question set for aligning assets, risk, data, stakeholders, and acceptance criteria before requesting a proposal.

Security specialists using a working document to review evidence
ICS / OPERATIONAL EVIDENCEDecide whether the organization is ready for discovery, a POC, or a scoped project.
Security specialists using a working document to review evidence
ICS / OPERATIONAL CONTEXTDecide whether the organization is ready for discovery, a POC, or a scoped project.
Security specialists using a working document to review evidence
ICS / OPERATIONAL CONTEXT

Risk Assessment Checklist

Decide whether the organization is ready for discovery, a POC, or a scoped project.

Critical assetsIdentify the applications, data, devices, identities, and processes that cannot fail.
Risk surfaceDocument threat scenarios, blind spots, dependencies, and current control limits.
Integration readinessConfirm telemetry, APIs, access, test environments, and systems that must remain.
CONTROL AND EVIDENCE

What the first scoped conversation should clarify.

Use these areas to confirm fit, dependencies, ownership, and the evidence required for acceptance.

01

Critical assets

Identify the applications, data, devices, identities, and processes that cannot fail.

02

Risk surface

Document threat scenarios, blind spots, dependencies, and current control limits.

03

Integration readiness

Confirm telemetry, APIs, access, test environments, and systems that must remain.

04

Acceptance criteria

Define measures, approvers, thresholds, exceptions, and scale conditions.

Decide whether the organization is ready for discovery, a POC, or a scoped project.

A practical question set for aligning assets, risk, data, stakeholders, and acceptance criteria before requesting a proposal.

Discuss this scope