How to study Part 6
For every security scenario:
- identify the asset, data, threat, and owner,
- identify human, workload, service, and automation identities,
- evaluate all policy layers,
- select preventive, detective, and corrective controls,
- automate with safe scope and exceptions,
- verify organization and Region coverage,
- preserve evidence and test the response.
Do not answer with the most restrictive control unless it still satisfies the business and operational requirement.