RACF-CC Starter Path

Start small. Find what matters. Improve what you can prove.

A practical starting route into RACF-CC for organisations that do not yet have a complete security baseline, mature governance process or dedicated cybersecurity team.

Two ways in

Begin where you are

The Starter Path is guidance, not another assessment. Use the route that matches what you already know.

Your first improvement cycle

Five approachable steps into the RACF-CC method

These are not five new framework stages. They are a guided entry route into the existing four-stage lifecycle.

Define + Look = Understand Choose = Prioritise Act = Implement Prove = Evidence
01

Define

Choose what you are protecting

Do not begin with the whole organisation if that makes the work unmanageable. Choose one service, environment or operational concern that can be understood well enough to support a decision.

What are you considering?
For example, Microsoft 365 and staff endpoints.
Who depends on it?
Care staff, managers, volunteers, partners or service users.
What matters most?
Personal data, availability, trusted communications or access to care systems.
What could seriously hurt?
Account takeover, ransomware, prolonged outage or data disclosure.
Who can approve change?
Name the realistic technical, service and risk decision-makers.
Record unknowns rather than inventing certainty.

Missing evidence is useful information. Note what is uncertain and carry that confidence judgement into later decisions.

A defined assessment scope and the services that matter.
02

Look

Gather evidence before deciding what is wrong

Use a compact evidence sweep across the eight domains. Follow meaningful exposure rather than completing every domain equally for the sake of a full dashboard.

ConfigurationPlatform telemetryVulnerability scansLogsPolicyIncident and change recordsStaff knowledge
Evidence does not need to be perfect.

A Secure Score, vulnerability count or compliance percentage can contribute evidence, but it should not be treated as the complete risk picture.

Found an unpatchable dependency?

Treat it as a risk decision, not a closed finding. The legacy-risk guide shows how to reduce exposure, retain evidence and set a review or exit path.

A short list of exposures, evidence gaps and uncertainties.
03

Choose

Turn exposures into candidate improvements

Evidence and attack-path reasoning identify the problem and a plausible treatment. Prioritisation then helps sequence that treatment; it does not decide what constitutes a security problem.

Observation

Privileged administrators can authenticate using ordinary MFA methods.

Attack path

Phishing or session compromise could provide privileged access.

Candidate improvement

Require phishing-resistant authentication for privileged roles.

Expected outcome

Reduce viable authentication paths for an attacker targeting privileged accounts.

Keep the first cycle achievable

Start with 3–7 candidate improvements

Combine related findings into meaningful control improvements. Investigate lower-confidence issues further rather than turning every weakness, recommendation or dashboard finding into an immediate project.

Complete, validate and sustain a manageable set before beginning the next cycle.

Current RACF-CC model

Sequence the shortlist consistently

Compare Risk Reduction with Implementation Effort, Operational Impact and Cost. Risk Reduction is weighted twice as strongly as each individual delivery constraint.

Priority Score = (Risk Reduction × 2) − (Effort + Impact + Cost)

The result supports First, Next, Develop or Review decisions. The calculated tier indicates sequencing, not absolute security importance. Record Confidence separately and use Governance Action where duties, active exploitation or an unacceptable critical-service threat require management attention.

A small, evidence-based and governed set of prioritised improvements.
04

Act

Improve one thing safely

The purpose of prioritisation is not to produce a prettier spreadsheet. Choose a priority that can move into controlled implementation with realistic ownership and safety measures.

ObservePilotValidateEnforceMonitorReview

Not every control needs every stage. Use the full Safe Enforcement Pattern where enforcement could disrupt access, systems, information flows or care delivery.

Owner

Who is accountable?

Scope

What will change?

Success

What should improve?

Safety

What legitimate workflow could break?

Recovery

How will failure be reversed or mitigated?

One implemented control with ownership, scope and retained implementation evidence.
05

Prove

Changed is not the same as improved

Check whether the control operated, whether the expected exposure reduced, whether legitimate services continued to work and what risk remains.

01

Did the control operate?

02

Did the expected exposure reduce?

03

Did legitimate services continue to work?

04

What risk remains?

Worked evidence chain

Restricting unnecessary inter-VLAN access

A firewall change is an activity. This evidence chain shows whether it achieved a useful and supportable outcome.

Baseline
User VLAN could reach multiple server networks.
Change
Replace broad access with required destination and service rules.
Technical evidence
Firewall configuration and traffic logs.
Validation
A test device reaches required authentication services but cannot reach an unrelated server.
Operational evidence
Required staff workflows continue to function.
Residual risk
Approved exceptions remain documented and owned.
Next review
Revalidate after a material network or service change.
ImplementedEvidencedSustainedExplore Control Assurance →
A defensible control outcome, residual-risk decision and next review.

Your first RACF-CC cycle

One journey, from scope to evidence

Define

Microsoft 365 privileged access.

Look

Some privileged identities lack phishing-resistant MFA.

Choose

Prioritise stronger administrator authentication.

Act

Protect emergency access, pilot and enforce in stages.

Prove

Validate coverage, outcomes, exceptions and support impact.

Repeat

Move to the next meaningful exposure.

What you should have at the end

A minimum evidence chain—not a mountain of paperwork

  • A defined scope and important service
  • An evidence-based exposure and confidence judgement
  • A small candidate-control list and recorded priority
  • An owner and expected security outcome
  • Implementation and validation evidence
  • Any exception or residual risk
  • A review date or trigger

Start with one defensible improvement

You do not have to solve everything at once.

Define what matters, understand a meaningful exposure, choose a proportionate treatment, implement it safely and retain enough evidence to show whether it worked.

Already have evidence of a specific problem? Go directly to the Control Prioritisation Tool.