Identity and access

Review account structure, administrative access, roles, permissions, authentication, service identities, privileged access, and offboarding responsibilities.

Security configuration and visibility

Review supported network, workload, storage, encryption, logging, monitoring, alerting, backup, and recovery configurations.

Governance and shared responsibility

Document policies, ownership, approval paths, exceptions, vendor responsibilities, change control, and the evidence required for internal review.

Remediation plan and implementation

Prioritize agreed control improvements, assign owners, implement in-scope changes, validate results, and document remaining risks. This service does not provide legal advice or certification.

Before work begins

Confirm the system, responsibilities, and next action.

01Fit

Confirm the request belongs within the selected service.

02Scope

Document systems, access, responsibilities, dependencies, and exclusions.

03Next action

Agree on assessment, implementation, or ongoing support.