Bertie
search
auto_awesomeActioninventory_2Consultant review
Action 3 · Task 295 · Group 15

Collect System Architecture and Policy Evidence

Audit and aggregate existing technical documentation, infrastructure topology diagrams, access control lists, and operational policies. Conduct a gap analysis against standard security control baseline requirements to expose missing artefacts.

Objective

Gathering these inputs establishes a single source of truth regarding the venture's current security posture. It accelerates the creation of the compliance artefact by identifying explicit gaps in documentation, policy, and technical controls early.

What's expected from the founder

Compile an inventory of operational evidence, including system architecture diagrams, identity provider configurations, logging setups, and current HR policies. A gap log must clearly document missing policies and technical control deficiencies.

psychologyBertie consultant stress-test

Five questions an expert would ask when reviewing your output

Use these to challenge assumptions, pressure-test your logic, and check the quality of this action's output in the context of the parent task and wider venture development.

  1. 1

    What evidence proves that your current infrastructure diagrams accurately reflect production environments and data pipelines?

  2. 2

    Where are the critical gaps between your informal security practices and formal, documented policies?

  3. 3

    How do you verify that access control lists for production databases are strictly enforced and regularly reviewed?

  4. 4

    What proportion of your current evidence relies on manual processes rather than automated compliance monitoring?

  5. 5

    How complete is your inventory of subprocessors and third-party tools processing customer data?