Domain 1 · Adversarial Assurance
Enterprise Adversarial Assurance Baseline
Establish an evidence-grounded baseline of enterprise exposure, controls, dependencies, and assurance readiness.
Decision it answers
Which systemic risks and control gaps require immediate executive and engineering action?
Inputs it needs
- Authorization packet naming the accountable authority and permitted execution level
- Asset and identity inventories
- Architecture documentation
- Control configuration and telemetry
- Business criticality of systems and data
Methods applied
- Corpus-grounded capability registry
- Digital-twin baseline construction
- Threat modelling against the twin
- Evidence grading by provenance and freshness
- Red, blue and purple review of the findings
Outputs produced
- Executive baseline
- Technical exposure register
- Assurance status
- Prioritised action plan
- Evidence ledger
Must remain human-owned
Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.
