ARMORARMOR

Offensive security has a strategic home. A documented strategy connects testing to how the organization understands and manages its own risk, through whatever practices already exist. The model requires no specific risk framework or GRC infrastructure. It requires that the connection between offensive security outcomes and risk decisions is documented, intentional, and evidenced. An executive sponsor is formally engaged, and remediation is SLA-governed.

Outcomes

  • ·A documented strategy, reviewed yearly, explicitly connects testing to the organization's understanding of its risk
  • ·An executive sponsor is formally engaged and accountable, not merely listed as a stakeholder
  • ·Remediation SLAs are set by severity tier, with a formal escalation path for breaches
  • ·Findings demonstrably inform existing risk management practices and decisions
  • ·Offensive security requirements sit inside change management and project approval workflows

Actions

  1. 01Write an offensive security strategy that reflects the organization's actual risk management practices
  2. 02Engage an executive sponsor with real accountability, able to set priorities and influence resourcing
  3. 03Set remediation SLAs by severity tier with a formal escalation path
  4. 04Document how findings reach risk decision-makers and what response is expected
  5. 05Formalize testing requirements in change management and project approval

Sustainment Criteria

All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.

An approved offensive security strategy is current and reviewed yearly

The executive sponsor engages on a defined cadence and can articulate program priorities

SLAs are applied consistently, with a documented escalation path and breach visibility

Documented evidence shows findings informing existing risk practices and decisions

Testing requirements are embedded in change management, with evidence of application

Practitioner note

G3 does not require a risk register, a mature GRC program, or a dedicated risk function. It requires that the link between offensive security and risk decisions is documented and intentional. The most common G3 failure is nominal sponsorship: a name on the program with no real accountability.

Moving to G4

Set a leadership reporting cadence independent of exercise schedules, extend tabletops beyond technical teams, define business-unit accountability between cycles, and fold offensive security into governance and risk reporting.

Corresponding Technical Practice level

T3 Measured

Organizations often develop these axes at different rates. Compare your position on both.

View T3 Measured