Readiness is not binary. Use the capstone, earlier module work, and new scenario reasoning to decide how confidently you can apply each domain.
Architecture and dependencies
Ready means: I can explain mission, assets, identities, service flows, trust boundaries, concentration dependencies, degraded states, controls, and recovery paths.
Common weakness: Treating a diagram as proof of current implementation or ignoring shared dependencies.
Capstone evidence: A20.3 Architecture and Threat Model Decision Pack.
Final self-check: Can I explain why one architecture relationship changes a monitoring, identity, recovery, or risk decision?
Threat modeling
Ready means: I can write bounded threat statements connecting a plausible condition to an affected asset or outcome, controls, evidence, and uncertainty.
Common weakness: Calling every concern a confirmed vulnerability or assuming malicious intent.
Capstone evidence: A20.3 bounded threat statements and validation needs.
Final self-check: Can I distinguish a plausible threat condition from evidence that an incident actually occurred?
Identity and access
Ready means: I can distinguish authentication, authorization, approval, purpose, privilege, ownership, lifecycle, and action-level evidence for human and workload identities.
Common weakness: Treating successful authentication as proof that every action was authorized.
Capstone evidence: A20.6 Cloud and Identity Governance Review.
Final self-check: Can I explain why a confirmed identity event may still have unresolved authorization status?
Detection and monitoring
Ready means: I can start from a defensive question, choose telemetry, evaluate source health, separate severity from confidence, validate safely, and measure usefulness.
Common weakness: Treating alerts as incidents or missing alerts as proof during source delay.
Capstone evidence: A20.4 Detection and Monitoring Review.
Final self-check: Can I explain what a delayed source changes about positive and negative evidence?
Incident response
Ready means: I can triage, scope, preserve competing hypotheses, choose proportional response, record decisions, define recovery, and preserve reopen triggers.
Common weakness: Declaring root cause too early or equating restored availability with complete closure.
Capstone evidence: A20.5 Incident Response Decision Record.
Final self-check: Can I explain what action is justified now and what evidence would change that action?
Cloud security
Ready means: I can separate provider capability from customer responsibility across identity, configuration, data, monitoring, recovery, and governance.
Common weakness: Assuming a cloud feature automatically means the customer configured or governs it correctly.
Capstone evidence: A20.6 shared-responsibility and cloud-control review.
Final self-check: Can I identify who owns the decision rather than merely naming the platform feature?
Risk management
Ready means: I can connect condition, likelihood, impact, controls, evidence confidence, treatment, residual risk, ownership, and review triggers.
Common weakness: Forcing precise risk ratings from incomplete evidence or treating control existence as effectiveness.
Capstone evidence: A20.7 Risk and Privacy Decision Register.
Final self-check: Can I explain why residual risk may remain even when several controls are present?
Privacy
Ready means: I can evaluate purpose, minimization, access, retention, sharing, transparency, lifecycle, and proportionality inside security design.
Common weakness: Assuming security purpose automatically justifies all available data collection.
Capstone evidence: A20.7 privacy inventory and monitoring-data decisions.
Final self-check: Can I identify the minimum data needed for the defensive decision?
Recovery and resilience
Ready means: I can distinguish backup availability from restoration readiness and evaluate dependencies, identity, configuration, validation, and residual risk.
Common weakness: Treating a current backup or one healthy service check as proof of complete recovery.
Capstone evidence: A20.3 recovery architecture, A20.5 recovery criteria, and A20.7 recovery risk.
Final self-check: Can I state what evidence is needed before normal confidence should return?
Governance and exceptions
Ready means: I can assign policy, control, evidence, risk, exception, decision, and review ownership and explain how deviations are governed.
Common weakness: Treating acceptance or exception as a reason to remove the issue from review.
Capstone evidence: A20.6 control governance and A20.7 treatment/acceptance decisions.
Final self-check: Can I identify the owner, rationale, duration, residual risk, and review trigger for a deviation?
Evidence discipline
Ready means: I can distinguish facts, interpretations, hypotheses, assumptions, findings, risks, incidents, recommendations, decisions, and unknowns.
Common weakness: Turning correlation, chronology, policy expectation, or missing evidence into a stronger conclusion than supported.
Capstone evidence: A20.2 case charter, A20.5 incident record, and A20.9 traceability index.
Final self-check: Can I say exactly what the evidence proves and what it does not prove?
Professional communication
Ready means: I can preserve the same facts and uncertainty while changing detail for technical, manager, executive, risk/privacy, and portfolio audiences.
Common weakness: Changing the case truth for a leadership audience or hiding uncertainty to sound confident.
Capstone evidence: A20.8 Executive Capstone Brief.
Final self-check: Can I make the message shorter without changing authorization, incident, confidence, or risk status?