| Database security assessment | Establish current exposure and control maturity | Estate, findings, evidence, severity, dependencies and limitations | Security, technology, risk, audit |
| Control framework | Define expected protection | Control objectives, requirements, ownership and evidence | Security architecture, DBAs, governance |
| Secure configuration baseline | Standardise platform settings | Approved settings, exceptions, validation and change rules | DBAs, engineering, operations |
| Access governance model | Control user and privileged access | Roles, approvals, recertification, emergency and service accounts | IAM, DBAs, application owners |
| Remediation roadmap | Sequence risk treatment | Priorities, owners, dependencies, acceptance criteria and milestones | Programme, security, technology leaders |
| Operating procedures | Sustain controls after delivery | Monitoring, exceptions, review, escalation, evidence and reporting | Operations, SOC, governance |
| Validation and evidence pack | Support assurance and closure | Test results, approvals, residual risks, exceptions and sign-offs | Risk, compliance, audit, management |