1. Planning &
Scoping
- Understand the organization’s security environment and security program.
- Review relevant IT security policies, standards, and organizational structure.
- Define the assessment scope, activities, responsibilities, and schedule.