Offensive security has a strategic home. A documented strategy connects testing to how the organization understands and manages its own risk, through whatever practices already exist. The model requires no specific risk framework or GRC infrastructure. It requires that the connection between offensive security outcomes and risk decisions is documented, intentional, and evidenced. An executive sponsor is formally engaged, and remediation is SLA-governed.
Outcomes
- ·A documented strategy, reviewed yearly, explicitly connects testing to the organization's understanding of its risk
- ·An executive sponsor is formally engaged and accountable, not merely listed as a stakeholder
- ·Remediation SLAs are set by severity tier, with a formal escalation path for breaches
- ·Findings demonstrably inform existing risk management practices and decisions
- ·Offensive security requirements sit inside change management and project approval workflows
Actions
- 01Write an offensive security strategy that reflects the organization's actual risk management practices
- 02Engage an executive sponsor with real accountability, able to set priorities and influence resourcing
- 03Set remediation SLAs by severity tier with a formal escalation path
- 04Document how findings reach risk decision-makers and what response is expected
- 05Formalize testing requirements in change management and project approval
Sustainment Criteria
All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.
An approved offensive security strategy is current and reviewed yearly
The executive sponsor engages on a defined cadence and can articulate program priorities
SLAs are applied consistently, with a documented escalation path and breach visibility
Documented evidence shows findings informing existing risk practices and decisions
Testing requirements are embedded in change management, with evidence of application
Practitioner note
G3 does not require a risk register, a mature GRC program, or a dedicated risk function. It requires that the link between offensive security and risk decisions is documented and intentional. The most common G3 failure is nominal sponsorship: a name on the program with no real accountability.
Moving to G4
Set a leadership reporting cadence independent of exercise schedules, extend tabletops beyond technical teams, define business-unit accountability between cycles, and fold offensive security into governance and risk reporting.
Corresponding Technical Practice level
T3 Measured
Organizations often develop these axes at different rates. Compare your position on both.
