AEGRIX methodology
From security signal to remediation proof
A defensible assessment is not a questionnaire with a percentage at the end. It is a chain of context, declared state, evidence, independent review, findings, decisions, corrective work, and proof. AEGRIX uses the same auditable engine across three layers while changing the depth and rules of review.
AEGRIX 360 Pulse
Executive baseline
Create a fast picture across 25 canonical capabilities and identify the risk priorities that deserve deeper work.
Evidence
Optional. Evidence can reduce uncertainty, but Pulse is not a compliance assessment.
Output
Risk priorities and a recommendation on whether to progress to Compass.
AEGRIX 360 Compass
Guided preparation
Turn Discovery context into a defensible scope, applicability decisions, evidence plan, and roadmap.
Evidence
Evidence depth increases. Insufficiency should become visible before formal verification begins.
Output
Confirmed scope, preliminary gaps, and a decision on whether to begin Assurance.
AEGRIX 360 Assurance
Formal assessment
Create an independent assessment snapshot with traceable responses, evidence, review, findings, and remediation.
Evidence
Reviewer judgment and evidence limitations are explicit; affirmative claims should withstand structured verification.
Output
A formal record of evaluated coverage and active gaps — never an automatic certification.
The assessment chain
Eight records that should never collapse into one field
1. Context
Organization, sector, country, operating model, critical processes, sensitive data, systems, vendors, and discovery signals define what is actually being assessed.
2. Scope and applicability
Choose the assessment layer and reference framework deliberately. Preserve what is included, excluded, pending, and why.
3. Declaration
Record the organization's claimed implementation state without silently treating that claim as verified fact.
4. Evidence
Attach attributable artifacts and preserve source, date, scope, period covered, limitations, and the exact claim each artifact supports.
5. Review
A reviewer evaluates sufficiency and operating effectiveness where relevant, documents uncertainty, and keeps judgment separate from the original declaration.
6. Findings
Convert unsupported, partial, missing, or otherwise deficient states into findings without erasing the underlying assessment record.
7. Remediation
Assign owner, priority, target date, action, expected proof, and status. Merge remediation only when gaps genuinely share a root cause.
8. Proof and history
Preserve the evidence that corrective work was completed and retain a durable trail of changes, decisions, and prior snapshots.
Why snapshots matter
Frameworks change, systems change, evidence expires, and remediation closes gaps. A formal assessment should therefore preserve what was evaluated at that moment rather than quietly rewriting history when the current catalog changes. Progress should create a new state while retaining the prior one.
Five rules that prevent misleading assessment results
Unknown is not compliant
Missing information should remain visible instead of being forced into yes/no scoring.
Evidence attached is not evidence verified
Presence of a file cannot substitute for reviewer judgment on relevance, freshness, scope, or operating proof.
One score cannot carry all meaning
Scores can summarize, but accepted risk, uncertainty, evidence weakness, and severity must remain independently visible.
Crosswalk does not mean equivalence
The same security practice may support several frameworks without making their requirements or conclusions interchangeable.
Closed remediation needs proof
Changing a status to complete is weaker than preserving the artifact or review record that demonstrates the corrective action actually worked.