Day 0–30
Find & frameEstablish the decision record security leadership can govern.
- 1Confirm approved scope and confidential boundaries
- 2Map cryptographic exposure into a CBOM-style decision record
- 3Name owners for material paths — not a ticket pile without accountability

