You do not need identical depth in every domain to start A20. You do need enough understanding to recognize when one domain changes the interpretation or decision in another.
Security architecture
Systems, assets, identities, services, data, dependencies, control placement, failure paths, resilience, and the reasons a design exists.
Capstone question
What must be protected, how is the environment connected, and where can one dependency affect many outcomes?
Useful evidence
Architecture diagrams, service inventories, ownership records, dependency maps, recovery design, control descriptions.
Threat modeling
Assets, actors, trust boundaries, entry points, assumptions, plausible adverse conditions, controls, prioritization, and residual uncertainty.
Capstone question
Which plausible conditions could affect the mission, and which controls or evidence would reduce that concern?
Useful evidence
Threat statements, trust-boundary map, assumptions register, control mapping, review notes.
Networking defense
Communication paths, segmentation, identity-aware access, expected behavior, dependencies, visibility, resilience, and safe degraded operation.
Capstone question
Which connections are expected, why are they allowed, and what evidence supports that expectation?
Useful evidence
Network architecture, approved service relationships, synthetic connection summaries, policy context, source health.
Identity and access
Authentication, authorization, workforce and workload identities, privilege, approvals, role purpose, lifecycle, federation, exceptions, and accountability.
Capstone question
Who or what can act, what can it do, why is that access needed, and when should it change or end?
Useful evidence
Role inventories, approval records, synthetic sign-in records, ownership, access reviews, lifecycle events.
Detection and monitoring
Security questions, telemetry, source health, context, correlation, confidence, severity, tuning, metrics, validation, and rollback.
Capstone question
What evidence would help a defender make the next decision, and how reliable is that evidence right now?
Useful evidence
Alerts, logs, source-health records, detection plans, change context, validation cases, quality metrics.
Incident response
Triage, scope, facts, hypotheses, decision ownership, containment, communication, evidence preservation, recovery, reassessment, and closure.
Capstone question
What is confirmed now, what remains uncertain, and what response is justified at the current evidence level?
Useful evidence
Timeline, case notes, decision log, alerts, service health, communications, containment and recovery records.
Cloud security
Shared responsibility, cloud identity, data handling, managed services, exposure, logging, resilience, configuration governance, and service dependencies.
Capstone question
Which security outcomes belong to provider capabilities and which still depend on customer decisions and evidence?
Useful evidence
Cloud service inventory, identity roles, architecture, audit-source map, recovery records, policy and exception evidence.
Application and API security
Input handling, authorization, identity, object ownership, data exposure, error behavior, dependency trust, logging, and secure change.
Capstone question
Which application decisions must hold true for approved users and services, and what evidence supports them?
Useful evidence
Fictional application flows, authorization rules, expected outcomes, validation records, service-identity design.
Risk management
Business context, threat condition, likelihood, impact, controls, inherent and residual risk, treatment, ownership, acceptance, and review.
Capstone question
Why does this issue matter to the organization, and what decision should the accountable owner make?
Useful evidence
Risk register, control evidence, impact analysis, treatment record, owner decision, review trigger.
Privacy
Purpose, minimization, access, retention, sharing, transparency, data lifecycle, proportional monitoring, ownership, and governance.
Capstone question
Is the collection or use of data necessary for the stated purpose, and is the lifecycle governed proportionately?
Useful evidence
Data map, purpose statement, classification, retention rules, access roles, exception and review evidence.
Governance and policy
Policy, standards, procedures, control ownership, evidence, exceptions, review cycles, risk acceptance, escalation, and accountability.
Capstone question
What rule or decision governs this security outcome, who owns it, and how can compliance or exception status be reviewed?
Useful evidence
Policy requirements, standards, approvals, exceptions, ownership records, review and closure evidence.
Professional communication
Audience, materiality, business impact, evidence confidence, options, decisions, ownership, limitations, revision, and truthful presentation.
Capstone question
What does this audience need to understand or decide, and how much detail is necessary without changing the facts?
Useful evidence
Technical report, manager brief, executive summary, presentation notes, reflection and revision record.