1. Model Explanation (Kickoff meeting):
– Initial session with CISO and security team
– Explanation of the Security Maturity Model
– Agreement with customer to start the Security Journey
2. Strategy Definition (Commonly on Kickoff meeting):
– Determine assessment scope alignment: Full vs. Partial model assessment
– Definition of schedule to conduct weekly assessment coordination meetings
3. Assessment Phase:
– Weekly 3-4 hour interactive sessions
– Open-ended discussions about security practices
– Immediate remediation of identified issues where possible
– Automated security posture assessment
– Leveraging of service free trials for enhanced visibility
– Integration of AWS security services
– Development of strategic security roadmap
– For Enterprise Support customers: Execute ESSR (Enterprise Support Security Review)
– Hands-on collaboration with security teams
4. Reporting and Follow-up:
– Detailed assessment results
– List current successful practices
– Identify and document critical risks
– List areas requiring enhancement
– Provide actionable recommendations based on findings
– Connection to additional resources (AWS ProServe, Partners)
– Customer satisfaction survey