- 01Service and continuity
- Users, critical journeys, business rules, service windows, acceptable interruption, data criticality, manual continuity, recovery objectives, communication needs, legal or contractual constraints, current expectations, and accountable business and product owners.
- 02Software and change path
- Source, build, environments, releases, runtime, architecture, interfaces, jobs, data stores, dependencies, configuration, identities, permissions, tests, documentation, code ownership, support status, technical debt, and change history.
- 03Signals and operational work
- User reports, support tickets, incidents, alerts, logs, metrics, traces, audit events, service and business measures, performance, capacity, batch and queue health, data quality, provider status, manual checks, escalation, and unresolved work.
- 04Security and recovery
- Assets, threat context, vulnerability and component information, credential and access lifecycle, backups, restore evidence, retention, incident and disclosure paths, suppliers, response roles, known failure modes, and previous recovery exercises.