Control matrix thay cho checklist rời
Mỗi control cần asset → threat → scope → control → evidence → owner → severity → response → residual risk. IAM, network/edge, secret, monitoring, backup và lifecycle phải liên kết với nhau nhưng không gộp thành “bật security”.
Assessment và incident
Làm scenario theo framework requirement/boundary/control/evidence/trade-off. Trong incident, preserve evidence, contain tối thiểu, rollback có điều kiện, thông báo owner và tạo follow-up đo được. Review cả câu đúng do đoán để phát hiện confidence gap.
Gate
Pass khi matrix đủ, đạt 8/10 scenario, không có lỗi public access/credential/production target và hoàn thành variant nhóm lỗi lớn nhất. Nếu chưa, quay lại ngày 22–27 theo error log.