Step 1 — your environment
What you run, what you collect and how you work. Everything downstream is derived from this.
What this step establishes
Everything downstream derives from this step. The platforms you declare determine which ATT&CK techniques can apply to you at all; the telemetry you declare determines what could ever be detected; the operating model and size determine how much of the model you are assessed against.
What it asks
- Operating systems — declared explicitly rather than inferred, because inferring them produced advice about macOS for organisations with no Macs.
- Estate and cloud — on-premises, hybrid, cloud-native, OT/ICS or developer platform, plus the cloud and productivity platforms in use.
- Endpoint and network telemetry — tick everything present somewhere. These are sets, not single choices, because EDR on servers with native logging on laptops is the normal shape of an estate.
- Workload — also a set. Servers, containers, serverless and mainframe are not alternatives; a single choice dropped the others’ techniques from your in-scope set, which is precisely the scoping error this model exists to expose.
- Identity — also a set, because a directory alongside a cloud identity provider is the normal enterprise shape rather than the exception. AWS IAM and Identity Center, Google Workspace and Ping are declarable in their own right; an AWS-native estate forced to answer “other IdP” was credited none of the CloudTrail telemetry it actually holds.
- Threat intelligence sources — what actually reaches the detection team.
- Deception — what is deployed, where it is placed, and what happens when it fires.
- Operating model, size and regulation — which derive your applicability profile. Where you declare that you are regulated, the tool asks which regimes and records them on the report, because an evidence expectation is only arguable against a named rule.
How to answer well
Declare what is true today, not what is planned or partially rolled out. The telemetry step later asks how much of the estate each source covers, so there is a place for “we have it on the servers only” — it is not here.
The profile is derived, not chosen. A small organisation with no SOC lands on the essential profile and is assessed against 22 sub-capabilities. You may choose a heavier or lighter profile, and the model records a challenge if the choice is implausible for what you declared. The tool shows the reasoning behind the derivation rather than only its result, because a derivation nobody can see is indistinguishable from an arbitrary one.
Declaring that you are regulated never leaves you on the essential profile. That profile exists for teams under no obligation to show their working to anyone outside. A regulator, an auditor or an incoming CISO is exactly such a reader, so the floor for a regulated organisation is the standard profile.