Skip to content

Runbook: Year-End Security and Compliance Checklist

Purpose

The year-end checklist is the once-a-year pass across Cirius Group's security and compliance program that cannot be handled by monthly or quarterly cadences. It covers annual policy re-approval, strategic reviews, license and certificate renewals that land on calendar boundaries, and the formal annual refresh of the threat model.

Estimated time: 1 working week, spread across December. Run by the Security Officer (Rory). Items with co-owners are marked inline. The checklist is the source of truth for "annual" items — anything referenced elsewhere in the runbooks or compliance docs as "annual" should be represented here.

Trigger: first working day of December. Target completion: December 20 so everything is closed before the year-end freeze.


Contents

  1. Governance and ownership confirmation
  2. Identity and access annual review
  3. Network and firewall annual review
  4. Backup, DR, and recovery annual review
  5. Vendor and BAA annual review
  6. Annual threat model review (TMOD-007)
  7. Compliance program annual tasks
  8. Certificates, licenses, and contract renewals
  9. Year-end documentation pass
  10. Sign-off

1. Governance and ownership confirmation

  • [ ] Re-confirm Security Officer designation for the coming year (Rory) — capture in compliance/hipaa-administrative-procedures.md
  • [ ] Re-confirm Greg and Kevin as T1 Domain Admins (DR) and compliance-report consumers
  • [ ] Re-confirm Adriana as BAA / vendor-risk document owner
  • [ ] Review the RACI in compliance/hipaa-administrative-procedures.md — update any role changes from the year
  • [ ] Confirm break-glass credential custodians are unchanged; if personnel changed, run credential rotation per security/palo-alto-backup-credential-rotation.md and AD / Entra equivalents

2. Identity and access annual review

  • [ ] Run full LPRIV audit across PROD, DDE, AWS, SecOps (compliance/lpriv-*)
  • [ ] Review every standing role assignment in Entra PIM — target is nothing standing
  • [ ] Review every Global Admin, Privileged Role Admin, and Conditional Access Admin account — justify each
  • [ ] Confirm FIDO2 enrollment for all privileged accounts (addresses RA-2026-001)
  • [ ] Guest account purge — remove any guest whose business justification has lapsed
  • [ ] Service principal inventory — confirm every SP has a named owner and current justification; purge orphans
  • [ ] Review AWS IAM users (should be near-zero — verify), review every role trust policy

3. Network and firewall annual review

  • [ ] Full Palo Alto security-policy review — rules without hits in the past 12 months are candidates for removal (document in change ticket)
  • [ ] Decryption policy review — confirm TLS decryption coverage matches current PHI egress paths
  • [ ] DNS Security category tuning — review block/alert categories against the year's telemetry
  • [ ] NSG ruleset review across every subscription — remove stale 0.0.0.0/0 exceptions
  • [ ] Twingate resource catalog review — purge resources that have been decommissioned
  • [ ] Confirm Panorama and all 4 VM-Series are on a supported PAN-OS version with next-year upgrade path planned

4. Backup, DR, and recovery annual review

  • [ ] Full DR test executed at least once in the year (Q2 + Q4 plans live at compliance/q2-dr-test-plan-2026.md and compliance/q4-dr-test-plan-2026.md)
  • [ ] Confirm Veeam → S3 Object Lock → RSV three-path independence still holds after any infrastructure change in the year
  • [ ] Review RPO / RTO targets per workload — are they still accurate for business need?
  • [ ] Confirm backup retention matches the retention schedule in runbooks/backup-architecture.md
  • [ ] Confirm S3 Object Lock retention is 2190 days (6 years) on every backup bucket
  • [ ] Run a restore spot-check of a DDE workload (critical path for CJ-1 recovery)

5. Vendor and BAA annual review

  • [ ] Pull the vendor inventory from compliance/vendor-risk-inventory.md
  • [ ] For each vendor: confirm BAA is IN_FORCE, SOC2 Type II report is on file, attestation is current
  • [ ] Close any BAA backlog items (per 2026: Arctic Wolf, Keeper, Twingate, Cortex — target closed before SOC2 audit)
  • [ ] Review vendor-access accounts in Entra, AWS IAM, Palo Alto — remove any vendor login that did not log in during the year
  • [ ] Adriana reviews the SharePoint BAA repository and uploads any missing documents

6. Annual threat model review (TMOD-007)

Artifact under review: security/threat-model.md

Why this exists: The threat model is a living document. Without an annual forced refresh it will drift — new TTPs emerge, new crown jewels are added, mitigations ship, new actors appear. This item forces the refresh.

Owner: Rory (Security Officer). Co-reviewers: Greg and Kevin.

Checklist:

  • [ ] Re-read security/threat-model.md end to end
  • [ ] Crown jewel inventory (§2 of the threat model):
    • Any system added this year that meets crown-jewel criteria? Add it.
    • Any system decommissioned or materially reduced in sensitivity? Remove or re-rank.
    • Re-confirm the impact-if-compromised ranking.
  • [ ] Threat actor profiles (§3):
    • RaaS group branding refresh — note LockBit / ALPHV successor groups and any new Akira-style affiliate
    • New campaign intelligence — update the list of actively-targeted user accounts (currently: justinc, gregd, adrianam, paulb, sophien, lauramaeb)
    • Insider threat — if any personnel change affected the insider threat surface, note it
    • Nation-state — review vendor supply chain list (Microsoft, Palo Alto, Cortex, Arctic Wolf, Keeper) for the year's disclosed incidents
  • [ ] STRIDE analysis (§4) — re-score every cell:
    • Any HIGH gap that is now LOW because an agent went live? Update.
    • Any new gap because a control was removed, a new system was added, or a new TTP emerged? Update.
    • Cross-check that every MEDIUM/HIGH gap has an entry in compliance/risk-acceptance-register.md or the compliance scorecard.
  • [ ] Kill chain control map (§5.1) — re-score Preventive/Detective/Overall for every stage
  • [ ] Attack chain walkthroughs (§5.2) — for Chain A (ransomware), Chain B (data theft), Chain C (nation-state), Chain D (insider):
    • Any stage where the "detect" entry was pending and is now live? Update.
    • Any new stage or new attacker action observed in the wild this year? Add.
  • [ ] Residual risk register (§6) — close items shipped this year; re-open anything that regressed
  • [ ] Recommendations (§7) — remove done items; add recommendations from the year's incidents, pen tests, and audit findings
  • [ ] Update the "Last reviewed" date at the top of the document to December YYYY
  • [ ] Append a row to the Document history table describing the year's changes
  • [ ] Present the refreshed document to Greg and Kevin; capture sign-off in the §9 ready-for-review note (reset it to reference the current year's review)
  • [ ] Close a SecOps story each year titled "Annual threat model review — YYYY" with PR URL of the annual update

Output artifacts:

  1. Updated security/threat-model.md with a Document history row for the year
  2. Any new or closed rows in compliance/risk-acceptance-register.md
  3. Any new or closed rows in the compliance scorecard
  4. A SecOps story closed with the PR URL
  5. Sign-off capture (Slack thread, email, or meeting notes) from Greg and Kevin

Timing target: completed by December 20 so sign-off is in before year-end freeze.


7. Compliance program annual tasks

  • [ ] Full HIPAA risk assessment refresh (informs security/threat-model.md § 6)
  • [ ] HITRUST + SOC2 control mapping — confirm evidence for every control exists in compliance/
  • [ ] Annual policy re-approval — every policy in compliance/hipaa-policy-set.md must be re-approved with a date and signature
  • [ ] Compliance scorecard year-end: every row must be GREEN or have a documented RA
  • [ ] Workforce annual HIPAA training — confirm completion for every workforce member
  • [ ] KnowBe4 annual phishing simulation report — review results, update training focus

8. Certificates, licenses, and contract renewals

  • [ ] Inventory every certificate expiring in the next 12 months — log in SecOps as upcoming work
  • [ ] Licenses expiring in the next 12 months — Microsoft, AWS, Palo Alto, Cortex, Arctic Wolf, Keeper, Twingate — confirm renewal budget and schedule
  • [ ] Domain renewals — ciriusgroup.com, ciriusdde.com, ancillary domains
  • [ ] Support contract renewals — confirm each vendor support tier matches current operational need

9. Year-end documentation pass

  • [ ] README / CLAUDE.md check — any fact that changed this year must be corrected
  • [ ] key-learnings.md — append the year's major gotchas and lessons
  • [ ] All runbooks reviewed — any runbook not updated in the past 12 months gets a "Last reviewed: December YYYY" stamp after verification
  • [ ] Architecture diagrams refreshed to match current tenant / subscription / account / network topology

10. Sign-off

  • [ ] Rory signs the year-end summary (what was completed, what carries over)
  • [ ] Greg and Kevin counter-sign the annual threat model review §6 output
  • [ ] Adriana signs the vendor / BAA section §5 output
  • [ ] Artifacts archived to compliance/year-end-YYYY/ folder

Document history

DateChangeAuthor
April 2026Initial year-end checklist; annual threat model review added as §6 (TMOD-007)Kobe

Internal use only — Cirius Group