Identity and access
Review account structure, administrative access, roles, permissions, authentication, service identities, privileged access, and offboarding responsibilities.
Security configuration and visibility
Review supported network, workload, storage, encryption, logging, monitoring, alerting, backup, and recovery configurations.
Governance and shared responsibility
Document policies, ownership, approval paths, exceptions, vendor responsibilities, change control, and the evidence required for internal review.
Remediation plan and implementation
Prioritize agreed control improvements, assign owners, implement in-scope changes, validate results, and document remaining risks. This service does not provide legal advice or certification.
Before work begins
Confirm the system, responsibilities, and next action.
Confirm the request belongs within the selected service.
Document systems, access, responsibilities, dependencies, and exclusions.
Agree on assessment, implementation, or ongoing support.
