AEGRIX methodology

From security signal to remediation proof

A defensible assessment is not a questionnaire with a percentage at the end. It is a chain of context, declared state, evidence, independent review, findings, decisions, corrective work, and proof. AEGRIX uses the same auditable engine across three layers while changing the depth and rules of review.

AEGRIX 360 Pulse

Executive baseline

Create a fast picture across 25 canonical capabilities and identify the risk priorities that deserve deeper work.

Evidence

Optional. Evidence can reduce uncertainty, but Pulse is not a compliance assessment.

Output

Risk priorities and a recommendation on whether to progress to Compass.

AEGRIX 360 Compass

Guided preparation

Turn Discovery context into a defensible scope, applicability decisions, evidence plan, and roadmap.

Evidence

Evidence depth increases. Insufficiency should become visible before formal verification begins.

Output

Confirmed scope, preliminary gaps, and a decision on whether to begin Assurance.

AEGRIX 360 Assurance

Formal assessment

Create an independent assessment snapshot with traceable responses, evidence, review, findings, and remediation.

Evidence

Reviewer judgment and evidence limitations are explicit; affirmative claims should withstand structured verification.

Output

A formal record of evaluated coverage and active gaps — never an automatic certification.

The assessment chain

Eight records that should never collapse into one field

1. Context

Organization, sector, country, operating model, critical processes, sensitive data, systems, vendors, and discovery signals define what is actually being assessed.

2. Scope and applicability

Choose the assessment layer and reference framework deliberately. Preserve what is included, excluded, pending, and why.

3. Declaration

Record the organization's claimed implementation state without silently treating that claim as verified fact.

4. Evidence

Attach attributable artifacts and preserve source, date, scope, period covered, limitations, and the exact claim each artifact supports.

5. Review

A reviewer evaluates sufficiency and operating effectiveness where relevant, documents uncertainty, and keeps judgment separate from the original declaration.

6. Findings

Convert unsupported, partial, missing, or otherwise deficient states into findings without erasing the underlying assessment record.

7. Remediation

Assign owner, priority, target date, action, expected proof, and status. Merge remediation only when gaps genuinely share a root cause.

8. Proof and history

Preserve the evidence that corrective work was completed and retain a durable trail of changes, decisions, and prior snapshots.

Why snapshots matter

Frameworks change, systems change, evidence expires, and remediation closes gaps. A formal assessment should therefore preserve what was evaluated at that moment rather than quietly rewriting history when the current catalog changes. Progress should create a new state while retaining the prior one.

Five rules that prevent misleading assessment results

Unknown is not compliant

Missing information should remain visible instead of being forced into yes/no scoring.

Evidence attached is not evidence verified

Presence of a file cannot substitute for reviewer judgment on relevance, freshness, scope, or operating proof.

One score cannot carry all meaning

Scores can summarize, but accepted risk, uncertainty, evidence weakness, and severity must remain independently visible.

Crosswalk does not mean equivalence

The same security practice may support several frameworks without making their requirements or conclusions interchangeable.

Closed remediation needs proof

Changing a status to complete is weaker than preserving the artifact or review record that demonstrates the corrective action actually worked.