// DECISION CONTEXTS
Start where
the consequence lives.
These are qualification contexts. The final scope, authority, evidence, method, deliverable, and applicability decision are established for the specific organization and engagement.
01 / FIT CONTEXT / NOT CLIENT EVIDENCEPublic-sector and government programs
When procurement, public accountability, authority, and evidence handling are part of the technical decision.
- Scope and decision-owner clarity
- Control and readiness evidence
- Supplier and dependency risk
- Executive and procurement-ready reporting
First brief should cover: Decision date, accountable owner, service boundary, applicable contract or framework, and the evidence question.
Boundary: This is a fit context, not a claim of government clients, contracts, or approval.
Aligned service lanes: Cyber risk management / Vendor due diligence / Compliance readiness
Representative evidence path: Executive risk brief / Control-readiness map / Supplier-risk matrix
Controlled method path: Qualify the objective / Confirm authority and scope / Report for decisions
02 / FIT CONTEXT / NOT CLIENT EVIDENCEDefense suppliers and primes
When a prime, subcontractor, or technology provider must make security, resilience, controlled-information, and fourth-party questions visible.
- Technical and vendor due diligence
- Supply-chain and exit-risk review
- Authorized testing boundaries
- Remediation and retest evidence
First brief should cover: Role in the supply chain, system or information boundary, decision owner, contract context, and dependency or exit question.
Boundary: Applicability depends on the contract, information category, system boundary, and responsible authority.
Aligned service lanes: Authorized penetration testing / Technical due diligence / Vendor due diligence / Disaster recovery and BCP
Representative evidence path: Technical findings register / Supplier-risk matrix / Retest and closeout note
Controlled method path: Confirm authority and scope / Set the rules of engagement / Treat and retest
03 / FIT CONTEXT / NOT CLIENT EVIDENCEEssential services and critical functions
When disruption could affect public safety, mission delivery, or a function that must remain available and recoverable.
- Critical-service and dependency mapping
- Incident and continuity readiness
- Recovery assumptions and exercises
- Residual risk and next validation
First brief should cover: Critical service, disruption scenario, dependency owner, recovery assumption, decision date, and exercise question.
Boundary: A plan, framework, or exercise does not itself prove operational resilience or regulatory compliance.
Aligned service lanes: Cyber risk management / Disaster recovery and BCP / Incident readiness
Representative evidence path: Resilience exercise record / Executive risk brief / Retest and closeout note
Controlled method path: Qualify the objective / Collect bounded evidence / Close the loop
04 / FIT CONTEXT / NOT CLIENT EVIDENCERegulated technology and SaaS
When an architecture, product, or provider needs a proportionate view of controls, supply-chain exposure, and evidence gaps.
- Architecture and control review
- Vendor and subprocessor analysis
- Framework applicability
- Decision-ready risk and treatment options
First brief should cover: Product or provider boundary, data category, applicable jurisdiction or framework, decision owner, and evidence gap.
Boundary: The applicable law, contract, assessor, auditor, regulator, and legal interpretation remain outside a generic site claim.
Aligned service lanes: Technical due diligence / Vendor due diligence / Compliance readiness
Representative evidence path: Technical findings register / Supplier-risk matrix / Control-readiness map
Controlled method path: Collect bounded evidence / Validate and interpret / Report for decisions