INNSKILL
METHOD / 006Classification: public

A delivery route with decision gates.

An illustrative six-stage architecture for moving from business context and identity inventory to controls that can be operated, measured, and assured.

01

frame

Frame the Mission

Agree on the business service, security concern, obligations, scope, and decision owners before assessing technology.

Activities

  • Interview business, security, technology, risk, and operations stakeholders.
  • Define critical services, sensitive information, regulatory drivers, and material threats.
  • Set scope boundaries, assumptions, governance, and success measures.

Decision gate

Sponsors confirm scope, accountable owners, and measurable outcomes.

Engagement charter · Stakeholder and decision map · Initial service and risk context

02

discover

Discover the Current State

Establish evidence-based visibility across identities, assets, controls, processes, dependencies, and operational constraints.

Activities

  • Review architecture, policy, configuration, workflow, and operational evidence.
  • Map identity sources, access paths, privileged accounts, applications, cloud resources, and control coverage.
  • Validate findings through technical walkthroughs and representative samples.

Decision gate

Technical and business owners agree that the baseline is sufficiently complete for risk decisions.

Current-state architecture · Control and dependency inventory · Validated findings register

03

prioritize

Prioritize Risk

Separate material exposure from control noise by connecting findings to plausible paths and business consequences.

Activities

  • Evaluate likelihood, impact, reachability, privilege, data sensitivity, and existing safeguards.
  • Group findings into root causes, attack paths, and regulatory control themes.
  • Identify immediate containment needs and risk-acceptance decisions.

Decision gate

Risk owners approve priorities, urgent actions, and accepted constraints.

Prioritized risk register · Attack-path or misuse-case narratives · Immediate action plan

04

design

Design the Target

Create a workable target architecture and operating model with explicit ownership, controls, and transition choices.

Activities

  • Define target capabilities, architecture patterns, policies, workflows, and integrations.
  • Design ownership, support, exception, evidence, and service-management processes.
  • Sequence dependencies and evaluate delivery options against risk and operational impact.

Decision gate

Architecture, security, operations, and sponsors approve the target and investment sequence.

Target architecture · Target operating model · Dependency-aware roadmap

05

deliver

Deliver in Controlled Increments

Implement and validate prioritized controls through small releases that preserve service continuity.

Activities

  • Configure, integrate, migrate, and test controls against agreed acceptance criteria.
  • Pilot with representative identities, assets, applications, or engineering teams.
  • Manage change, training, exceptions, rollback, and evidence throughout release.

Decision gate

Control owners accept effectiveness, operational readiness, and residual risk before expansion.

Production-ready control increments · Test and acceptance evidence · Runbooks and trained service owners

06

operate-and-improve

Operate & Improve

Sustain control effectiveness through accountable operations, measurable service levels, and recurring improvement.

Activities

  • Monitor control health, security signals, exceptions, vulnerabilities, and service performance.
  • Review incidents, audit evidence, user feedback, threat changes, and recurring failure patterns.
  • Prioritize improvements and retire temporary processes or unsupported controls.

Decision gate

Service and risk owners review outcomes and approve the next improvement cycle.

Service dashboard and review cadence · Control-effectiveness reporting · Continuous-improvement backlog

Start with the control question

Frame the mission.