GRC Foundation Sprint
A complete risk & compliance baseline delivered in two weeks. Before we start, here's everything we'll need from you (or your client).
1. Company & engagement details
We need to scope the workspace, tailor the risk universe, and understand the regulatory landscape.
- Company legal name & primary domain
- Industry / vertical (e.g. fintech, healthcare, SaaS, manufacturing)
- Company size (headcount & approximate annual revenue range)
- Primary office locations & any remote-workforce considerations
- Engagement sponsor name, title & email (the person who will own the workspace after handoff)
- Any secondary stakeholders who should have workspace access (names, emails, roles)
2. Target compliance framework
The Sprint includes one framework gap assessment — we need to know which one to run.
- Which framework? (SOC 2 Type II, ISO 27001, NIST CSF 2.0, HITRUST CSF, HIPAA, or ISO 27002)
- Have you started any prior compliance work against this framework? If yes, share any existing evidence or gap analysis
- Are you pursuing certification/attestation, or is this for internal readiness?
- Target audit date or compliance deadline (if any)
3. Risk landscape
This seeds the initial risk assessment and populates the risk register with real, relevant entries.
- Any existing risk register, risk assessment, or threat model (spreadsheet, PDF, or other format)
- Known top concerns or past incidents (ransomware, data breach, vendor failure, natural disaster, etc.)
- Existing security policies or an information security policy document
- Cyber insurance coverage summary (if applicable)
4. IT & infrastructure overview
Understanding the environment lets us identify the right technical risks and map controls accurately.
- Cloud providers in use (AWS, Azure, GCP, other)
- Key SaaS tools (e.g. Google Workspace, Microsoft 365, Salesforce, Jira, GitHub)
- On-premise infrastructure summary (if any)
- Identity provider & SSO setup (Okta, Azure AD, Google, none)
- Data classification — what sensitive data types do you handle? (PII, PHI, PCI, financial, IP)
- Backup & disaster recovery approach (cloud snapshots, tape, third-party, none)
5. Five critical business processes (for BIA)
We build a Business Impact Analysis for your five most important processes. Tell us what keeps the business running.
- List your five most critical business processes (e.g. customer onboarding, payment processing, production deployment, patient scheduling, order fulfillment)
- For each process: who owns it, which systems support it, and what happens if it goes down for 4 hours / 24 hours / 72 hours
- Existing RTO (Recovery Time Objective) and RPO (Recovery Point Objective) targets, if defined
- Any known single points of failure
6. Key vendors & third parties
Third-party risk is almost always in scope. Knowing your critical vendors helps us assess concentration risk.
- List of critical vendors / subprocessors (hosting, payment, HR, legal, managed IT)
- Any existing vendor risk assessments or SOC 2 reports from vendors
- Vendor SLAs or contractual recovery commitments (if available)
7. Existing documentation (share whatever you have)
Anything you've already written saves time and ensures we build on your existing work rather than starting from scratch.
- Information security policy
- Acceptable use policy
- Incident response plan
- Business continuity or disaster recovery plan
- Previous audit reports or penetration test summaries
- Org chart or RACI for security responsibilities
- Network diagram or architecture overview
How it works
Once you submit the checklist above, here's what the next 14 days look like.
Day 0
Kickoff call
60-minute walkthrough of your submitted materials, confirm scope and framework, set up workspace access.
Days 1–3
Risk assessment & register
We analyze your environment, identify threats, and populate the risk register with scored, owned entries.
Days 4–6
Framework gap assessment
Control-by-control review against your chosen framework. Every gap is documented with remediation guidance.
Days 7–9
BIA for five processes
Impact analysis, dependency mapping, RTO/RPO recommendations for each critical process.
Days 10–12
Remediation roadmap
Prioritized, executive-ready action plan: what to fix first, estimated effort, and quick wins.
Day 14
Handoff call
Walk through every deliverable in your configured NovaGRC workspace. Q&A, next steps, 90-day access begins.
What you receive
Start your Sprint
Fill in what you can below. We'll review your submission and schedule a 60-minute kickoff call within one business day.
