Start with the decision
Identify the decision the audit must support: further investment, a release, a migration or an assessment of security concerns. Name the sponsor and explain how the findings will be used. Agree the business services involved and the consequences that matter, including interruption, unreliable data or inappropriate access.
Set the review boundaries
Connect requirements and stakeholder ownership to governance, architecture, development practices, implementation and operation. Identify the systems, repositories, environments and dependencies in scope. Agree the depth of examination around the business question and material risks. Record exclusions and sampling choices so readers understand what the conclusions cover. Identify the people who can explain each part of the system.
Agree the evidence and outputs
Prepare the relevant documents, code, configuration, test records and operational evidence. Establish access and information-handling arrangements before sharing material. Record which versions and period are being reviewed. Findings should explain what was examined, what was observed and where evidence is limited.
Agree an executive summary, a technical record and recommended priorities. Each recommendation needs a reason, dependencies and a way to check the next action. Decide who receives the report and how findings will be discussed.
Know the criteria and the assessor
NIST CSF 2.0 connects governance and cybersecurity risk management. NIST SSDF addresses secure development practices, and OWASP ASVS provides requirements for verifying web application security controls. Agree the relevant criteria and editions for the review.
I am the Company Owner and do all consulting alone, including interviews, assessment, reporting and follow-up. These recommendations describe my professional approach; the framework references are listed below.