Inputs
- Policies, standards and obligations
- Asset, identity and service inventories
- Configurations, scans and logs
- Staff interviews and known constraints
- Critical-service and supplier dependencies
The RACF-CC method
A repeatable four-stage cycle for turning an imperfect view of risk into prioritised, safely implemented and demonstrably effective security improvement.
More than recommendations
RACF-CC does not assume that buying a product, applying a policy or raising a dashboard score proves that risk has been reduced. Each stage receives evidence, performs a distinct kind of work and produces an output that can be reviewed before the organisation moves forward.
Understand produces an evidence-based current-state picture.
Prioritise produces a governed improvement plan.
Implement produces a safely deployed, owned control.
Evidence produces a validated outcome and next-cycle decision.
Across every stage
Care impact, safeguarding, accessibility, privacy, legal and contractual duties, service continuity, approval and risk ownership should shape the whole cycle—not appear as a final compliance check.
Understand
Begin with the services the organisation must sustain and the evidence actually available. Record uncertainty rather than treating absent telemetry as proof that no problem exists.
A current-state evidence pack containing service dependencies, material control gaps, plausible risk scenarios and an evidence register.
Ready to prioritise when: decision-makers can explain what is exposed, why it matters, how reliable the evidence is and which unknowns remain.
Prioritise
Compare meaningful security benefit with effort, cost and disruption. Mandatory or critical issues retain a separate governance requirement even when delivery is difficult.
A governed improvement plan with rationale, owners, dependencies, target evidence, interim safeguards and required risk decisions.
Ready to implement when: priorities, ownership, resources and acceptance criteria are approved, and deferred risks have an authorised treatment.
Implement
Translate the selected improvement into a tested operational change. Pilot where practical, communicate clearly and decide the conditions that would pause or reverse deployment.
A safely deployed, owned control supported by a change record, communications, operational ownership, exceptions and a usable rollback route.
Ready to evidence when: the intended scope is deployed safely, material exceptions are recorded and the organisation knows what evidence will demonstrate effectiveness.
Apply the reusable pattern whenever a control can block access, applications, traffic, data movement, updates or care workflows. Open the Safe Enforcement guide →
Evidence
Test coverage, technical behaviour and operational effect against the baseline. Evidence should support a decision, not merely show that a setting exists.
A validated outcome and next-cycle decision supported by control evidence, operational effects, residual risk, lessons and a review owner.
Ready to begin the next cycle when: the result and its limitations are understood, residual risks have owners and new evidence has updated the current-state picture.
Compact worked example
This simplified example shows how one improvement moves through the method. Local design and governance would still be required.
Identify privileged identities, current authentication methods, emergency access, legacy dependencies, sign-in patterns and gaps in available evidence.
Output:Defined exposure and baseline.Assess likely account-compromise reduction against licensing, administration effort, user impact and compatibility. Flag any mandatory treatment separately.
Output:Approved scope, owner and success measures.Protect emergency access, pilot with administrators, review report-only results, communicate the change and enforce in controlled stages with rollback criteria.
Output:Deployed control with managed exceptions.Verify authentication coverage, sign-in outcomes, exception use and support impact. Record residual legacy paths and decide the next improvement.
Output:Validated result and residual-risk decision.Practical artefacts
Future RACF-CC spreadsheets and downloadable templates can support these handovers without becoming the framework itself.
See how control status is evidenced →Continue the RACF-CC journey
Compare proposed controls with the prioritisation tool, explore the relevant domain guidance and see how the cycle worked in an anonymised care environment.