- 01Business and service context
- Business processes, critical services, user groups, locations, working hours, accessibility and language needs, risk and regulatory context, priorities, expected demand, maintenance windows, continuity needs, internal teams, current initiatives, budgets, contracts, decision rights, and consequences of interruption or delay.
- 02Users, assets, identities, and systems
- People and roles, joiner-mover-leaver paths, devices, operating systems, software, licenses, identities, authentication, privileges, applications, data, networks, servers, cloud services, backups, integrations, certificates, domains, vendors, warranties, ownership, lifecycle state, and known inventory gaps.
- 03Work, access, and evidence
- Requests, incidents, problems, changes, security events, alerts, support channels, queues, priorities, approvals, runbooks, remote access, service accounts, privileged tools, secrets boundaries, logs, tickets, asset and configuration records, knowledge, communications, exceptions, retention, audit needs, and current measures.
- 04Continuity, suppliers, and transition
- Coverage dependencies, provider and subcontractor roles, supplier escalation, service and data locations, incident cooperation, insurance and legal constraints, backups, restore evidence, disaster and business continuity plans, emergency access, alternate communication, transition assistance, data return and deletion, credential rotation, and exit ownership.