# Security Roadmap Template

**Obfuscation Hub Toolkit — starter template (Release 0.1)**

> Adapt to your organization: replace the example entries with your own
> assessment findings, resequence for your constraints, and review with
> leadership quarterly. Educational template — not legal advice, and completing
> it does not by itself satisfy any framework.

---

## 1. Context (fill in first — the roadmap is only as good as this section)

- **Drivers:** [What is forcing prioritization? Customer requirements, insurance, incident, growth, framework target…]
- **Target state (12 months):** [One honest paragraph. e.g., "Foundation controls operating with evidence; ready to begin a SOC 2 readiness effort in Q4."]
- **Constraints:** [Budget range, staff time, change freezes, dependencies on vendors]
- **Owner of this roadmap:** [name] — reviews with leadership on [cadence]

## 2. Workstreams

Keep 4–6 workstreams; more fragments attention. Starter set:

| Workstream | Scope | Owner |
| --- | --- | --- |
| Identity & Access | Central identity, MFA enforcement, lifecycle, access reviews | [name] |
| Endpoints & Infrastructure | Device baseline, patching, server/cloud hardening | [name] |
| Resilience | Backup coverage, restore testing, incident readiness | [name] |
| Third Parties | Vendor inventory, questionnaires, access constraints | [name] |
| Governance | Policies, risk register, evidence habit, reporting | [name] |

## 3. Quarterly plan

Rules that keep this honest: every item has **one owner** and a **verifiable
done-condition** ("MFA enforced for all users; enforcement report filed" — not
"improve MFA"). Anything without a done-condition is a wish, not a roadmap item.

### Q1 — [quarter/year]: Foundations

| Item | Workstream | Owner | Done-condition (evidence) | Depends on | Status |
| --- | --- | --- | --- | --- | --- |
| EXAMPLE: Build asset + SaaS inventory | Governance | IT Mgr | Inventory ≥95% complete; dated export filed | — | ☐ |
| EXAMPLE: Enforce MFA (all users, all admins) | Identity | IT Mgr | Enforcement policy screenshot + exception list (empty) | Inventory of apps | ☐ |
| EXAMPLE: Leaver checklist written + in use | Identity | HR + IT | Checklist doc; used for next 3 departures | — | ☐ |
| [your item] | | | | | ☐ |

### Q2 — [quarter/year]: Hardening

| Item | Workstream | Owner | Done-condition (evidence) | Depends on | Status |
| --- | --- | --- | --- | --- | --- |
| EXAMPLE: Endpoint baseline via MDM | Endpoints | IT Mgr | Compliance report ≥90% of fleet | Q1 inventory | ☐ |
| EXAMPLE: First quarterly access review | Identity | IT Mgr | Completed worksheet + remediation closed | MFA/identity central | ☐ |
| [your item] | | | | | ☐ |

### Q3 — [quarter/year]: Resilience

| Item | Workstream | Owner | Done-condition (evidence) | Depends on | Status |
| --- | --- | --- | --- | --- | --- |
| EXAMPLE: Backup coverage decision + restore test | Resilience | IT Mgr | Restore test note with date/result | Q1 inventory | ☐ |
| EXAMPLE: One-page incident plan + tabletop | Resilience | Ops Dir | Plan filed; tabletop notes; contact tree verified | — | ☐ |
| [your item] | | | | | ☐ |

### Q4 — [quarter/year]: Governance and next horizon

| Item | Workstream | Owner | Done-condition (evidence) | Depends on | Status |
| --- | --- | --- | --- | --- | --- |
| EXAMPLE: Minimum policy set acknowledged by staff | Governance | Ops Dir | 3 policies + acknowledgment record | — | ☐ |
| EXAMPLE: Vendor inventory + T1 questionnaires | Third Parties | Ops Dir | Inventory + responses on file for privileged vendors | — | ☐ |
| EXAMPLE: Decide next-year target (e.g., SOC 2 readiness) | Governance | Leadership | Decision memo with budget range | All above | ☐ |

## 4. Sequencing guidance

- Inventory and identity come first — nearly everything else references them.
- Prefer finishing a control (with evidence) over starting three.
- Schedule restore tests and access reviews on the calendar now; recurring
  items that live only in intentions do not recur.
- When an item slips, record why in one line — patterns in the "why" column
  are your real constraint list.

## 5. Reporting one-pager (monthly or quarterly, to leadership)

- On track / at risk / done counts by workstream
- The single most important risk accepted this period, in plain language
- Decisions needed from leadership (with options and a recommendation)
- Next period's three commitments

---

*Source: Obfuscation Hub Toolkit. Pairs with the asset inventory, access review
worksheet, and incident response checklist in the same kit.*
