Goal: Assess the organization’s digital footprint, business structure, and attack surface as it currently stands.
  1. Crucial Business Processes & Functions
  2. Key Stakeholders
  3. Hardware Asset Inventory
  4. Software Asset Inventory
  5. Third-Party Access Inventory
  6. User Roles & Job Functions
  7. Digital Identities & Accounts
  8. Privileged Accounts
  9. Shared & Service Accounts
  10. Shadow IT Identification
  11. AI Tool Identification
  12. Legacy Systems
  13. Network Maps
  14. Site Survey
  15. Data Discovery
  16. Data Classification
  17. Data Flows
  18. Interdependencies
  19. Legal/Regulatory Requirements
  20. Reconnaissance
  21. Threat Scenarios