Vetting

System & Architecture Vetting

Independent technical assurance over solution architectures, cloud estates and code before you commit.

The situation

A structured, adversarial review of a system's security design before money and reputation are committed to it. We examine the architecture against its own threat model, verify that stated controls exist and function, test the security assumptions embedded in the design, and report in the language of decision-makers as well as engineers.

Typical triggers are a pre-production go/no-go, a supplier's claim you cannot verify internally, a major re-platforming, or an internal team that needs an independent voice to unblock a stalled security debate.

What the client receives

Schedule of deliverables

  1. 01Threat model and attack-surface map (STRIDE / MITRE ATT&CK aligned)
  2. 02Architecture review report with prioritised findings and residual risk
  3. 03Secure configuration and hardening baseline verification
  4. 04Cloud posture assessment against CIS Benchmarks and provider well-architected security pillars
  5. 05Source code and SSDLC review where in scope
  6. 06Go / no-go recommendation with conditions

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • ISO/IEC 27001
  • NIST CSF 2.0
  • OWASP ASVS / SAMM
  • CIS Benchmarks
  • ITSRM²

Discuss this engagement

Tell us about the system and the decision in front of you and we will set out the scope, the method and the reporting format.

Contact us