Control matrix
Các cột bắt buộc: threat → principal/resource → control → scope → evidence → owner → action → review. Ví dụ contractor ngoài location cần Conditional Access/MFA; app đọc Blob cần managed identity/RBAC; region/tag cần Policy; accidental delete cần Lock; HTTP attack cần WAF; volumetric flood cần DDoS; error cần Monitor/Log Analytics.
Incident drill
Ưu tiên containment theo blast radius/data sensitivity, sau đó điều tra và sửa root cause. Budget breach cần xác minh billing delay và owner; secret exposure cần rotate/revoke và xem access logs.
Checkpoint
Bài đạt khi bạn không chọn “security service” chung chung mà chứng minh control đúng layer/scope/evidence.