Vetting
System & Architecture Vetting
Independent technical assurance over solution architectures, cloud estates and code before you commit.
The situation
What the client receives
Schedule of deliverables
- Threat model and attack-surface map (STRIDE / MITRE ATT&CK aligned)
- Architecture review report with prioritised findings and residual risk
- Secure configuration and hardening baseline verification
- Cloud posture assessment against CIS Benchmarks and provider well-architected security pillars
- Source code and SSDLC review where in scope
- Go / no-go recommendation with conditions
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- ISO/IEC 27001
- NIST CSF 2.0
- OWASP ASVS / SAMM
- CIS Benchmarks
- ITSRM²
Related services
Discuss this engagement
Tell us about the system and the decision in front of you and we will set out the scope, the method and the reporting format.