01
Programme Framework
5 layers · governance · IAM · data · app/infra · detection/response
02
SOC 2 TSC Map
Security · availability · processing integrity · confidentiality · privacy
03
Control Inventory
Register · ownership · evidence · automation · quarterly walk-through
04
Vendor Security DD
SOC 2 + ISO + pentest + sub-processors + incident SLA
05
Incident Playbook
Hour-by-hour · 72-hour notification · NYDFS 24-hr
06
Identity & Access Mgmt
SSO · MFA · joiner/mover/leaver · privileged · access reviews
07
Vulnerability Mgmt
Scanner inventory · cadence · remediation SLA · pen-test · bounty
08
Change Management
Ticket · review · CI/CD · approval · rollback · CAB
09
BCP / DR
RTO · RPO · architecture · backup · annual exercise · tabletop
10
Awareness Training
6 tracks · annual · phishing simulation · board briefing
11
Risk Assessment
Live JS · likelihood × impact × controls · band → action
12
Annual Review
10-section template · for Audit Committee / Board
13
Committee Charter
CISO chair · cross-functional · cadence · decision authority