Baseline intake
Understand the regulatory and policy landscape before designing anything.
- Obtain the documents that regulate the organisation's cybersecurity activity
- Obtain existing information security policy documents and procedures
- Analyse them as the basis for the operating model
- Deliverables
- Document inventory and gap analysis
- Gate to the next phase
- The document baseline exists and has been read