Step 1: Establish Governance, the Program Charter, and Leadership Approval
The work: governance structure, roles and responsibilities, the program charter, and everything leadership needs to approve it.
The call: who should own security risk at TechFlow, how much authority the program needs, and how far its reach should extend at the start.
Produces: an Information Security Program Charter covering scope, objectives, roles and responsibilities, oversight, and a first statement of what risk TechFlow will accept, prepared for leadership approval.
Step 2: Define Scope, Business Context, and the Asset and Data Inventory
The work: scoping, asset inventory, classifying health and financial data, and identifying the obligations that come with them.
The call: what belongs inside the program, and which customer and regulatory obligations follow from that choice.
Produces: a TechFlow Scope and Information Profile, and a Requirements Register naming each obligation and its owner.
Step 3: Conduct the Gap Analysis
The work: comparing where TechFlow stands against NIST guidance and what its customers expect.
The call: which gaps are real problems, which are symptoms of the same cause, and what to tackle first.
Produces: a Gap Assessment with a ranked short list and the reasoning behind the ranking.
Step 4: Build the TechFlow Risk Register
The work: risk method, risk identification, scoring likelihood and impact, and building the register.
The call: which risk ranks first, and on what basis.
Produces: the TechFlow Information Security Risk Register with a reasoning note on every entry.
After completing your own TechFlow risk assessment, you receive a 15-entry reference register with notes explaining the reasoning behind the scores, rankings, and recommendations. It arrives after your own work is done, so it serves as a comparison, not an answer key.
Step 5: Conduct the Third-Party and Vendor Risk Assessment
The work: vendor intake, risk tiering, sending security questionnaires, reviewing vendor audit reports, security terms in contracts, and ongoing monitoring.
The call: whether a supplier's security is good enough, and what to require when it is not.
Produces: a TechFlow Vendor Risk Assessment covering two suppliers at different risk levels, with a written recommendation for each.
The Challenge introduced this supplier as one short risk among several. Here, participants receive the full vendor file: the questionnaire, supporting evidence, the audit report, contract terms, and monitoring information. Then they decide whether the vendor is acceptable, and defend the call.
Step 6: Select Controls and Document Applicability Decisions
The work: choosing controls, mapping them across frameworks, and recording why each one applies or does not.
The call: which controls TechFlow needs, which it does not, and how to justify leaving anything out.
Produces: a Control Selection Matrix and a Control Applicability Record, with every row naming the option not chosen and why.
When ISO/IEC 27001 is discussed, participants learn how their control-applicability decisions support a Statement of Applicability and what additional information that document requires.
Step 7: Design Policies, Procedures, and Evidence Requirements
The work: choosing and tailoring the policy set, writing procedures, and deciding what evidence each control has to produce.
The call: which policies TechFlow actually needs, how strict each one should be, and what to leave out.
Produces: a Policy Selection Note and the tailored policy set. The selection note is the portfolio piece. Participants choose and adapt rather than writing from scratch.
Step 8: Implement Controls, Access Reviews, and Security Awareness
The work: sequencing implementation, running a user access review, and building the security awareness program.
The call: what happens first when everything cannot happen at once.
Produces: a Control Implementation Plan with sequence, owners, dates, and dependencies, a completed simulated access review, and a security awareness plan worked through as a scenario.
Step 9: Build Audit Readiness, Evidence, and Control Testing
The work: organizing the evidence, mapping it to controls, testing whether controls hold up, and answering auditor requests.
The call: how much evidence is enough, and whether a control is genuinely working.
Produces: an Audit Readiness Evidence Package with an evidence index and control test results, built from provided TechFlow case evidence.
Step 10: Respond to Customer Security Questionnaires
The work: completing customer security questionnaires, building a reusable answer library, and supporting sales conversations.
The call: how to describe TechFlow's security honestly when the honest answer is partial, and what evidence to share.
Produces: a completed customer security questionnaire and the answer library behind it.
This mirrors Step 5. Participants assess a supplier, then answer as one.
Step 11: Conduct the Internal Audit, Prepare the Management Review, and Track Remediation
The work: a simulated internal audit using the fictional case records, preparing the management review, tracking fixes, handling exceptions and risk acceptance, and reporting on compliance.
The call: which findings should be raised to leadership, which corrective actions should be recommended, and which remaining risks leadership should consider accepting.
Produces: an Internal Audit Report and a Management Review and Remediation Presentation, prepared for leadership.
The curriculum teaches that a real internal audit must be objective, and that people should not audit their own work without safeguards for independence. Leadership conducts the management review; the analyst prepares it.