Assess
Establish the facts before committing to a design: what exists today, what the organisation needs, and what could go wrong.
Activities
- Stakeholder interviews with business owners, operators and risk functions
- Review of current architecture, data flows, integrations and dependencies
- Threat modelling and risk assessment of the target scope
- Definition of measurable acceptance criteria and service levels
- Delivery plan with stages, gates and exit points
Evidence produced
- Current-state architecture and data-flow diagrams
- Risk register with owners and proposed treatments
- Agreed scope, acceptance criteria and non-functional requirements
- Delivery plan and gate criteria signed off by the client