ARMORARMOR

Testing happens only when something external demands it: a compliance audit, a customer questionnaire, a contract requirement. There is no internal driver, no defined owner, and no expectation that results change anything. The organization sees its attack surface only when forced to look.

Outcomes

  • ·At least one penetration test or vulnerability assessment is completed each year
  • ·Critical business systems are identified, at least at a basic level
  • ·Test findings are documented and available for review
  • ·Critical and High vulnerabilities are prioritized for remediation

Actions

  1. 01Engage a qualified third party to conduct an annual penetration test or vulnerability assessment
  2. 02Create a basic asset inventory covering the systems, applications, and data stores critical to operations
  3. 03Store results centrally so they can be referenced and tracked across cycles
  4. 04Prioritize remediation of Critical and High findings before the next assessment cycle
  5. 05Brief IT and security stakeholders on findings after each test

Sustainment Criteria

All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.

The annual assessment is completed on schedule, not deferred or skipped

An asset inventory covers known critical systems and is reviewed at least once a year

Every Critical finding is either remediated or covered by a documented mitigation plan

Results and remediation actions are stored centrally and accessible to relevant staff

Practitioner note

At T1 the primary risk is not technical, it is organizational inertia. A test that produces a report no one reads, closes no findings, and informs no decisions has not improved security. The value of T1 is establishing the habit of looking.

Moving to T2

Establish a predictable testing cadence independent of compliance demands, expand the asset inventory beyond compliance-defined scope, and implement a remediation workflow that tracks findings to validated closure.

Corresponding Governance & Accountability level

G1 Absent

Organizations often develop these axes at different rates. Compare your position on both.

View G1 Absent