What Discover means
Once the board has decided what level of risk it's willing to carry, Discover is where that decision meets reality. This is the unglamorous, essential work of finding out what's actually there: which systems hold sensitive data, which suppliers have access to what, which dependencies would cause real damage if they failed. Generic checklists don't survive contact with a real organisation — every business has its own shape, its own blind spots, its own systems nobody's touched in three years but everyone's afraid to switch off.
Discover isn't a one-off audit. It's a standing question a CSISC Executive Cyber Leader keeps asking as the business changes — a new supplier, a new system, a new office, a new acquisition all shift what needs protecting.
The board question
What your board should be able to answer at this stage
“Do we actually know what needs protecting, and what threatens it?”
In practice
What good looks like
- An asset register that's actually current, not a spreadsheet from two audits ago
- A clear map of which third parties can touch which systems and data
- An honest view of which risks are unique to this business, not copied from a generic industry list
- Nobody in the organisation says “I think someone else owns that” about a critical system
Where this shows up