Classify the data and failure impact
List the data entered, generated and connected. Identify personal, financial, health, customer, credential and confidential business information.
Describe the harm from exposure, corruption, deletion and unavailability. This determines how deep the rest of the review must go.
Test identity lifecycle
Confirm MFA, SSO, role design, privileged access, service accounts and session controls on the exact plan. Create and remove a pilot user.
Offboarding is as important as sign-in. Verify how access to integrations, shared links and API tokens is revoked.
Understand vendor and data boundaries
Review hosting regions, subprocessors, encryption, backups, retention, deletion and whether customer data is used for model training or product improvement.
Marketing claims are not a substitute for contract terms and technical documentation. Record the source and review date for each conclusion.
Exercise detection and recovery
Check audit events, security alerts, restore options, support escalation and incident communication. Ask for evidence appropriate to the risk, such as assurance reports.
Run a user-error or compromised-account scenario in the pilot. Record who notices, who acts and what can be recovered.
Approve with conditions
Document required configuration, prohibited data, named administrators and a review date. A secure product can be deployed insecurely when defaults and ownership are ignored.
Reassess after major plan, integration or data changes rather than treating security review as a permanent badge.