Appearance
Runbook: Year-End Security and Compliance Checklist
Purpose
The year-end checklist is the once-a-year pass across Cirius Group's security and compliance program that cannot be handled by monthly or quarterly cadences. It covers annual policy re-approval, strategic reviews, license and certificate renewals that land on calendar boundaries, and the formal annual refresh of the threat model.
Estimated time: 1 working week, spread across December. Run by the Security Officer (Rory). Items with co-owners are marked inline. The checklist is the source of truth for "annual" items — anything referenced elsewhere in the runbooks or compliance docs as "annual" should be represented here.
Trigger: first working day of December. Target completion: December 20 so everything is closed before the year-end freeze.
Contents
- Governance and ownership confirmation
- Identity and access annual review
- Network and firewall annual review
- Backup, DR, and recovery annual review
- Vendor and BAA annual review
- Annual threat model review (TMOD-007)
- Compliance program annual tasks
- Certificates, licenses, and contract renewals
- Year-end documentation pass
- Sign-off
1. Governance and ownership confirmation
- [ ] Re-confirm Security Officer designation for the coming year (Rory) — capture in
compliance/hipaa-administrative-procedures.md - [ ] Re-confirm Greg and Kevin as T1 Domain Admins (DR) and compliance-report consumers
- [ ] Re-confirm Adriana as BAA / vendor-risk document owner
- [ ] Review the RACI in
compliance/hipaa-administrative-procedures.md— update any role changes from the year - [ ] Confirm break-glass credential custodians are unchanged; if personnel changed, run credential rotation per
security/palo-alto-backup-credential-rotation.mdand AD / Entra equivalents
2. Identity and access annual review
- [ ] Run full LPRIV audit across PROD, DDE, AWS, SecOps (
compliance/lpriv-*) - [ ] Review every standing role assignment in Entra PIM — target is nothing standing
- [ ] Review every Global Admin, Privileged Role Admin, and Conditional Access Admin account — justify each
- [ ] Confirm FIDO2 enrollment for all privileged accounts (addresses RA-2026-001)
- [ ] Guest account purge — remove any guest whose business justification has lapsed
- [ ] Service principal inventory — confirm every SP has a named owner and current justification; purge orphans
- [ ] Review AWS IAM users (should be near-zero — verify), review every role trust policy
3. Network and firewall annual review
- [ ] Full Palo Alto security-policy review — rules without hits in the past 12 months are candidates for removal (document in change ticket)
- [ ] Decryption policy review — confirm TLS decryption coverage matches current PHI egress paths
- [ ] DNS Security category tuning — review block/alert categories against the year's telemetry
- [ ] NSG ruleset review across every subscription — remove stale
0.0.0.0/0exceptions - [ ] Twingate resource catalog review — purge resources that have been decommissioned
- [ ] Confirm Panorama and all 4 VM-Series are on a supported PAN-OS version with next-year upgrade path planned
4. Backup, DR, and recovery annual review
- [ ] Full DR test executed at least once in the year (Q2 + Q4 plans live at
compliance/q2-dr-test-plan-2026.mdandcompliance/q4-dr-test-plan-2026.md) - [ ] Confirm Veeam → S3 Object Lock → RSV three-path independence still holds after any infrastructure change in the year
- [ ] Review RPO / RTO targets per workload — are they still accurate for business need?
- [ ] Confirm backup retention matches the retention schedule in
runbooks/backup-architecture.md - [ ] Confirm S3 Object Lock retention is 2190 days (6 years) on every backup bucket
- [ ] Run a restore spot-check of a DDE workload (critical path for CJ-1 recovery)
5. Vendor and BAA annual review
- [ ] Pull the vendor inventory from
compliance/vendor-risk-inventory.md - [ ] For each vendor: confirm BAA is IN_FORCE, SOC2 Type II report is on file, attestation is current
- [ ] Close any BAA backlog items (per 2026: Arctic Wolf, Keeper, Twingate, Cortex — target closed before SOC2 audit)
- [ ] Review vendor-access accounts in Entra, AWS IAM, Palo Alto — remove any vendor login that did not log in during the year
- [ ] Adriana reviews the SharePoint BAA repository and uploads any missing documents
6. Annual threat model review (TMOD-007)
Artifact under review: security/threat-model.md
Why this exists: The threat model is a living document. Without an annual forced refresh it will drift — new TTPs emerge, new crown jewels are added, mitigations ship, new actors appear. This item forces the refresh.
Owner: Rory (Security Officer). Co-reviewers: Greg and Kevin.
Checklist:
- [ ] Re-read
security/threat-model.mdend to end - [ ] Crown jewel inventory (§2 of the threat model):
- Any system added this year that meets crown-jewel criteria? Add it.
- Any system decommissioned or materially reduced in sensitivity? Remove or re-rank.
- Re-confirm the impact-if-compromised ranking.
- [ ] Threat actor profiles (§3):
- RaaS group branding refresh — note LockBit / ALPHV successor groups and any new Akira-style affiliate
- New campaign intelligence — update the list of actively-targeted user accounts (currently: justinc, gregd, adrianam, paulb, sophien, lauramaeb)
- Insider threat — if any personnel change affected the insider threat surface, note it
- Nation-state — review vendor supply chain list (Microsoft, Palo Alto, Cortex, Arctic Wolf, Keeper) for the year's disclosed incidents
- [ ] STRIDE analysis (§4) — re-score every cell:
- Any HIGH gap that is now LOW because an agent went live? Update.
- Any new gap because a control was removed, a new system was added, or a new TTP emerged? Update.
- Cross-check that every MEDIUM/HIGH gap has an entry in
compliance/risk-acceptance-register.mdor the compliance scorecard.
- [ ] Kill chain control map (§5.1) — re-score Preventive/Detective/Overall for every stage
- [ ] Attack chain walkthroughs (§5.2) — for Chain A (ransomware), Chain B (data theft), Chain C (nation-state), Chain D (insider):
- Any stage where the "detect" entry was pending and is now live? Update.
- Any new stage or new attacker action observed in the wild this year? Add.
- [ ] Residual risk register (§6) — close items shipped this year; re-open anything that regressed
- [ ] Recommendations (§7) — remove done items; add recommendations from the year's incidents, pen tests, and audit findings
- [ ] Update the "Last reviewed" date at the top of the document to December YYYY
- [ ] Append a row to the Document history table describing the year's changes
- [ ] Present the refreshed document to Greg and Kevin; capture sign-off in the §9 ready-for-review note (reset it to reference the current year's review)
- [ ] Close a SecOps story each year titled "Annual threat model review — YYYY" with PR URL of the annual update
Output artifacts:
- Updated
security/threat-model.mdwith a Document history row for the year - Any new or closed rows in
compliance/risk-acceptance-register.md - Any new or closed rows in the compliance scorecard
- A SecOps story closed with the PR URL
- Sign-off capture (Slack thread, email, or meeting notes) from Greg and Kevin
Timing target: completed by December 20 so sign-off is in before year-end freeze.
7. Compliance program annual tasks
- [ ] Full HIPAA risk assessment refresh (informs
security/threat-model.md§ 6) - [ ] HITRUST + SOC2 control mapping — confirm evidence for every control exists in
compliance/ - [ ] Annual policy re-approval — every policy in
compliance/hipaa-policy-set.mdmust be re-approved with a date and signature - [ ] Compliance scorecard year-end: every row must be GREEN or have a documented RA
- [ ] Workforce annual HIPAA training — confirm completion for every workforce member
- [ ] KnowBe4 annual phishing simulation report — review results, update training focus
8. Certificates, licenses, and contract renewals
- [ ] Inventory every certificate expiring in the next 12 months — log in SecOps as upcoming work
- [ ] Licenses expiring in the next 12 months — Microsoft, AWS, Palo Alto, Cortex, Arctic Wolf, Keeper, Twingate — confirm renewal budget and schedule
- [ ] Domain renewals — ciriusgroup.com, ciriusdde.com, ancillary domains
- [ ] Support contract renewals — confirm each vendor support tier matches current operational need
9. Year-end documentation pass
- [ ] README / CLAUDE.md check — any fact that changed this year must be corrected
- [ ]
key-learnings.md— append the year's major gotchas and lessons - [ ] All runbooks reviewed — any runbook not updated in the past 12 months gets a "Last reviewed: December YYYY" stamp after verification
- [ ] Architecture diagrams refreshed to match current tenant / subscription / account / network topology
10. Sign-off
- [ ] Rory signs the year-end summary (what was completed, what carries over)
- [ ] Greg and Kevin counter-sign the annual threat model review §6 output
- [ ] Adriana signs the vendor / BAA section §5 output
- [ ] Artifacts archived to
compliance/year-end-YYYY/folder
Document history
| Date | Change | Author |
|---|---|---|
| April 2026 | Initial year-end checklist; annual threat model review added as §6 (TMOD-007) | Kobe |