You have the dossier finished — or a first complete version, which is what matters — and now the structural problem of a self-taught course appears: there is nobody to mark it for you. This lesson solves that problem by turning it into an advantage, because assessing yourself with judgement is not a substitute for someone else's marking: it is exactly the same competency an internal auditor exercises when reviewing their own organisation knowing that the uncomfortable finding will land on them (06-04, section 9). Whoever can look at their own work and say "this is weak and here is why" is the person who ends up being asked to review everyone else's.

Here you have the complete rubric with seven dimensions and four levels, with observable descriptors rather than adjectives; the rubric applied to one and the same deliverable shown at its four levels, which is the most instructive part of the lesson; the red flags that invalidate a dossier however good it looks; how to ask for a peer review if you want one; the acid test, five questions you must be able to answer without looking at your documents; a self-assessment sheet ready to fill in; and what to do afterwards with the result, inside and outside the course.

Contents

  1. Why self-assessment is a professional competency
  2. Three rules for assessing yourself honestly
  3. The rubric: dimensions, weights and threshold
  4. The descriptors, dimension by dimension
  5. The rubric applied: an E2 risk at its four levels
  6. The rubric applied: an E4 control at its four levels
  7. Red flags that invalidate a dossier
  8. Peer review: how to ask for it and how to receive it
  9. The acid test: five defence questions
  10. Self-assessment sheet ready to fill in
  11. What to do with the result: the second pass
  12. How to use the project professionally

  1. Why self-assessment is a professional competency

In real work almost nobody is going to mark your dossier. Your boss has no time, your colleagues are not specialists and the customer cannot tell a good risk register from a bad one. The first — and often the only — quality review is the one you do. The moments when external correction does arrive are the expensive ones: an audit, a customer questionnaire that is lost, or an incident that proves the plan was no good.

That is why self-assessment appears in every profession where mistakes are paid for late. And it has a well-known trap: author bias. You assess the intention of what you wrote rather than what is written; you remember the reasoning that never made it onto the page; and you score highly whatever cost you a lot of effort even if the result is mediocre. The three rules in the next section exist to neutralise that bias.

There is a practical reason too: the rubric tells you where to invest the second pass. A dossier does not improve "a bit everywhere"; it improves by attacking the two weakest dimensions, which usually concentrate 80 % of the distance to a defensible piece of work.


  1. Three rules for assessing yourself honestly

Rule 1 — Score what is written, not what you know. If your reasoning about why R-01 comes first is in your head and not in the document, it does not count. It is the same rule as in 06-04: what cannot be shown does not exist. Read it as if someone else had written it and all you had was the paper.

Rule 2 — Let the dossier rest and change the medium. Between finishing and assessing, 48 hours minimum. And read it in a format different from the one you wrote it in: exported to PDF, printed, on your phone. Changing the medium breaks familiarity and makes visible the inconsistencies your eye had already normalised.

Rule 3 — Demand evidence for every point you award yourself. You do not score yourself "competent in risks" because it feels that way: you score it by pointing at the line, the table or the paragraph that proves it. The self-assessment sheet in section 10 has a column for exactly that, and it is the column that stops you inflating the mark.

And one negative rule: do not punish yourself for what you decided to leave out, if you left it out with an argument and a review date. A justified discard adds; an oversight subtracts. The difference between the two is either written down or it is not.


  1. The rubric: dimensions, weights and threshold

Seven dimensions, each with four levels: inadequate (1), basic (2), competent (3), excellent (4).

# Dimension Weight What it measures in one sentence
D1 Understanding and application of concepts 10 % That the course vocabulary is used well and applied, not recited
D2 Quality of the risk analysis and its prioritisation 20 % That the order of the list is defensible and justified
D3 Fit and realism of the controls against the budget 20 % That the plan fits in the money and in the hours, and that what was discarded has an argument
D4 Readiness for the incident and the recovery 15 % That someone could execute the plan at three in the morning
D5 Regulatory compliance and data protection 15 % That what the law requires is identified and translated into measures
D6 Traceability and internal consistency of the dossier 10 % That the risk→policy→control→evidence chain does not break
D7 Clarity and usefulness of the communication 10 % That management would understand it and could decide with it

How it is calculated. Each dimension scores from 1 to 4; the mark is Σ (level / 4 × weight), out of 100.

Pass threshold: 60 out of 100, with two additional conditions that do not offset. First: no dimension below "basic" (2) — a dossier that is excellent on risks and non-existent on recovery is not a passing dossier, it is half a dossier. Second: D2 and D3 at "competent" (3) as a minimum, because prioritising risks and fitting controls to a real budget are the core of the craft; without that, the rest is paperwork.

D2 and D3 add up to 40 % of the weight for the same reason 04-01 is the most decisive lesson in the course: they are the only two dimensions where anything is decided. The others describe, document or communicate decisions already taken.


  1. The descriptors, dimension by dimension

D1 — Understanding and application of concepts (10 %)

Level Observable descriptor
Inadequate Terms used with the wrong meaning: a vulnerability is called a "risk", a control is called a "threat", or RTO is confused with RPO
Basic The vocabulary is correct but generic: CIA, STRIDE and CIS appear, and they could appear in any other dossier without changing a word
Competent The concepts are applied to the case: STRIDE produces threats specific to this organisation and the cryptographic decisions respond to its data
Excellent They are applied and discarded with judgement: it is explained why a course concept does not apply here (e.g. why there is no field-level encryption, or why the Zero Trust model is limited to one phase)

D2 — Quality of the risk analysis and its prioritisation (20 %)

Level Observable descriptor
Inadequate Fewer than 10 risks, or risks stated as loose words ("ransomware", "phishing"), with no owner and no scoring
Basic Ten risks with the formula and scored on the matrix, but all technical and from the same family; impact described in system terms, not business terms
Competent Risks across several dimensions — third parties, people, availability, compliance, fraud — impact in business language, a named owner, ≥ 2 ALEs with assumptions and ≥ 1 ROSI
Excellent On top of that, the residual is scored against the verified state of the controls, there is at least one formally accepted risk with an approver and a date, and the order of the list is justified in prose: why R-01 comes before R-02

D3 — Fit and realism of the controls against the budget (20 %)

Level Observable descriptor
Inadequate The controls do not add up costs or hours, or the sum exceeds the case's budget. There is no discard list
Basic Fifteen controls with costs and hours that reconcile, but almost all preventive and technical; discards are mentioned with no reason
Competent It reconciles in euros and in hours, with a reserve for contingencies; there are detective and recovery controls; every top-5 risk is covered; the discards carry a reason and a review date
Excellent On top of that, some discard is justified by sequence and not by cost ("this is the right thing, but not yet"), the resource that is at its limit is explicitly declared, and the cheap control is chosen over the expensive one with a risk-reduction-per-euro argument

D4 — Readiness for the incident and the recovery (15 %)

Level Observable descriptor
Inadequate There is no runbook, or it is a list of good intentions ("contain the incident", "notify those responsible")
Basic A runbook with phases and severities, RTO/RPO set, but no contacts, no specific commands and nothing about how anything is tested
Competent A runbook executable by someone who did not write it: triggers, numbered steps, commands, out-of-band contacts, criteria for returning to production; RTO/RPO justified by impact; backups assessed against 3-2-1-1-0
Excellent On top of that, there is a date for the last restore test — even if it is "never", said as such — the communication matrix identifies who starts the 72-hour clock, and the runbook lists the decisions whoever executes it cannot take

D5 — Regulatory compliance and data protection (15 %)

Level Observable descriptor
Inadequate A list of rules copied with no relation to the case, or GDPR cited with no processing activity identified
Basic Rules correctly identified and a RoPA with three processing activities, but with no lawful basis or with generic ones ("consent" for everything)
Competent Law, standard, framework and contract are distinguished; the RoPA carries a lawful basis and, where there is article 9 data, its 9.2 exception; there is a reasoned DPIA decision and a breach procedure
Excellent On top of that, the "no" is justified as well — why a processing activity does not require a DPIA, why a rule does not apply — the controller and processor roles are identified in each relationship, and the legal obligations are translated into specific E4 controls

D6 — Traceability and internal consistency of the dossier (10 %)

Level Observable descriptor
Inadequate Identifiers cited that do not exist; controls that point at no risk; deliverables that contradict each other
Basic The matrix exists with ten rows, but the evidence is generic ("it is reviewed periodically") and some chains do not close
Competent Every identifier resolves; the matrix has specific, dated evidence; the roadmap contains only E4 controls and their sums match
Excellent On top of that, the chain can be walked in both directions — from a euro to the risk it treats and from a risk to its evidence — and the known inconsistencies are declared in the annex instead of being glossed over

D7 — Clarity and usefulness of the communication (10 %)

Level Observable descriptor
Inadequate There is no executive summary, or the document is only understood by whoever wrote it
Basic There is an executive summary, but it lists technical activities instead of decisions and consequences
Competent One page management would read and could decide with: the five main risks, the total investment and the three key decisions, in their language
Excellent On top of that, the dossier is navigable — index, stable identifiers, sections that can be read on their own — and every hard call carries its justifying paragraph in the place where it is taken, not in an annex

  1. The rubric applied: an E2 risk at its four levels

This is the part of the whole lesson that teaches most: the same dental practice risk, written four times. Read them in order and work out which of the four yours is in.

INADEQUATE
  R-01  Ransomware.  Likelihood: high.  Impact: high.

BASIC
  R-01  Risk that ransomware encrypts the practice's server and we cannot work.
        Likelihood 4, Impact 5, Level Critical. Mitigate. Owner: IT.

COMPETENT
  R-01  If an attacker who has compromised the clinical software vendor uses the
        shared administrator account with no MFA (A-11) to reach the Gijon server
        (A-03), then they encrypt the clinical database (A-01) and the DICOM images
        (A-02), halting clinical activity at all three sites and creating a possible
        health data breach notifiable to the AEPD.
        Inherent L=4 x I=5 = CRITICAL.  Strategy: mitigate with C-01, C-04, C-11.
        Residual: L=2 x I=5 = HIGH.  Owner: Elena Vazquez.  Quarterly review.

EXCELLENT
  [everything above, and in addition:]
        ...and, since the backup NAS (A-04) is permanently mounted on the same network
        and housed in the same room as the server, the encryption reaches the only
        existing backup too, turning a recoverable incident into an irreversible loss
        of the clinical records of 4,800 patients and breaching the retention duty of
        Law 41/2002.
        ALE = 19,080 EUR/year (SLE 127,200 x ARO 0.15). SLE = 67,200 of revenue lost
        over 8 days + 12,000 of recovery + 6,000 legal + 42,000 of patient attrition
        (2 % of the list). ARO estimated at 0.15 from the frequency observed in the
        sector and because the vector depends on a third party.
        Residual L=2 x I=5 = HIGH, scored against the VERIFIED state: C-04 is
        implemented and tested as of 2027-02-28; C-01 is still planned pending
        signature of the contract annex, so the residual does NOT include its effect.
        It comes first on the list because it is the only risk in the register whose
        worst case is irreversible: R-02 (WhatsApp leak) is more likely, but its
        consequences are penalties and are repairable; this one closes the practice.

What separates each level from the next. From inadequate to basic: scoring appears. From basic to competent: the complete causal chain with identified assets appears and the impact is expressed in business consequences. And from competent to excellent there are three jumps, all three imitable: the second-order consequence — the NAS in the same room, which is what turns the incident into a catastrophe — the quantification with explicit assumptions, and the paragraph that justifies its position on the list by comparing it with another risk. That last paragraph is what a director wants to read and what almost no learner's dossier contains.


  1. The rubric applied: an E4 control at its four levels

INADEQUATE
  C-01  Improve the security of the vendor's remote access.

BASIC
  C-01  Require the clinical software vendor to use MFA.  Cost: 0.
        Owner: IT.  Status: implemented.

COMPETENT
  C-01  Replace the vendor's shared administrator account (A-11) with named accounts
        with MFA, enabled on demand against a ticket and revoked automatically after
        8 hours.
        Nature: technical + administrative.  Function: preventive + detective.
        Risks: R-01, R-07.  CIS IG1: 5.x, 6.x.  Cost: 0 EUR.  Effort: 12 h/year.
        Owner: Elena Vazquez.  Status: PLANNED (requires a contract annex).

EXCELLENT
  [everything above, and in addition:]
        Why this and not an EDR: the vector for R-01 is a LEGITIMATE ACCOUNT used by a
        compromised third party. An EDR (3,600 EUR/year) would see anomalous processes
        but not an authorised administrative session; C-01 removes the condition that
        makes the attack possible, and it costs zero euros and twelve hours. Risk
        reduction per euro invested: incomparable.
        Implementation risk: the vendor may refuse, because its support team works with
        a single account for all its customers. Plan B if it refuses, already
        negotiated: keep the shared account but (a) disabled by default and enabled by
        Nuria only for the duration of the incident, (b) with session recording, and
        (c) with alert C-11 on any use outside the window. It is a COMPENSATING
        control, worse than the main one, and it is documented as such with an
        exception EXC-2027-002 expiring in 6 months.
        Verification: quarterly export of the vendor's session list cross-checked
        against the tickets opened. First verification scheduled: 2027-04-15.

Note the detail that most distinguishes the excellent level and that hardly anyone writes: plan B. A control that depends on a third party agreeing to something may not happen, and a dossier that has not thought that scenario through leaves the number one risk hanging on a negotiation. Documenting the compensating control, marking it as worse and giving it an exception with an expiry date is exactly what 04-02 and 04-03 taught, applied where it hurts.


  1. Red flags that invalidate a dossier

These six are spotted in five minutes and cancel out the general impression however good it is. Look for them in yours before you score yourself.

Red flag Why it invalidates How it is fixed
The controls add up to more than the budget The whole dossier is a wish: if it does not fit, nothing written down is going to happen Cut until it reconciles and move the rest to the discard table with a date
Risks with no owner Everyone's risk is nobody's risk; with no owner there is nobody to decide the treatment Assign a person per risk, not a department
Policies the organisation cannot comply with They become a self-inflicted nonconformity at the first audit Lower the statement to what can be complied with, or provide the means it demands
A recovery plan never tested, presented as a capability It is the sector's most expensive lie: a backup that has not been restored is not a backup Write "last test: never" and schedule the first one with a date
Zero detective controls It is the blindness of 02-06: with no detection, any incident lasts weeks Add two or three cheap detections from E6, starting with backup failure
A RoPA with no lawful basis A processing activity with no lawful basis is unlawful processing, not an incomplete form Determine the basis for each activity and, with health data, its 9.2 exception

There is a seventh, subtler and very frequent: every control showing as "implemented". In an organisation that has just carried out its first risk analysis, that is statistically impossible and casts doubt on the rest of the document. An honest dossier has a majority of planned ones.


  1. Peer review: how to ask for it and how to receive it

There is no tutor here, so this is optional. But if you have a study partner, someone with experience or a technical community to hand, an external review will give you in half an hour what would cost you two passes.

How to ask for it properly. Do not send "have a look at this". Send the dossier with three specific questions and a time limit, because a bounded request gets answered and an open one gets postponed:

"I'm sending you the dossier for a security project at a fictitious dental practice
(25 people, 9,000 EUR/year). You don't need to read all of it: it's 20 minutes.

1. Look at E4 (the control catalogue) and tell me: with this budget and these hours,
   what would you take out and what would you put in that isn't there?
2. Read runbook RB-01 and imagine you have to execute it on a Sunday. Where would you
   get stuck for want of a piece of information?
3. Read only the executive summary. If you were the practice manager, would you approve
   the spend? What would you be missing in order to decide?"

The three questions attack D3, D4 and D7, which are the dimensions where an outside reader sees more than you do. Do not ask about D2 and D5: they require knowing the case in depth and cannot be answered in twenty minutes.

How to receive the criticism. Three rules: do not defend the document while it is being commented on — if you need to explain it out loud, the paper is missing something; ask "what made you think that?" instead of "yes, but…", because what you are after is the point where the reading went off course; and write everything down and decide afterwards, in the cold light of day, what you take on board. Not every criticism is right, but every criticism points at a place where the text was not obvious.

If you have nobody to ask, there is a reasonable substitute: reread the dossier playing a role — the manager who pays, the systems person who executes, the auditor who asks for evidence — and note on each pass what that character would ask you. It is worse than a real reader, but it is much better than nothing.


  1. The acid test: five defence questions

Close the dossier. Push the computer away. Answer out loud. If you need to look, the answer is "I have not internalised it", and that is information about the work, not about your memory.

# Question What a good answer is
1 What is your number one risk and why is it first? Naming it, stating the causal chain in one sentence and comparing it with the second: why this one before that one. Without comparison there is no prioritisation
2 It is three in the morning and that happens. What occurs? Who gets the alert, through what channel, what they do in the first fifteen minutes and who they wake up. If the answer starts with "we would have to…", the plan does not exist
3 What have you left out and why? Two or three discards with their reason and their review date, including at least one that is not about money but about sequence or lack of hours
4 How do you prove the control works? Naming the specific evidence, who generates it, how often and when the last one was. "It is configured" is not a proof
5 What do you notify, to whom and how quickly in the first 72 hours? Distinguishing supervisory authority, affected people, customers and suppliers; knowing when the clock starts and who decides to notify

How to interpret the result. Five fluent answers: the dossier is yours and you could defend it in an interview or in front of a management team. Three or four: normal for a first version; the ones you fail mark out your second pass. Two or fewer: it is not that you have studied too little, it is that the dossier is written as documentation and not as decision, and the second pass has to go after the why of everything.

The question most people fail is 4. Almost everyone can say which controls they have put in place; very few can say which piece of paper they would show to prove they work. It is exactly the gap 06-04 came to fill.


  1. Self-assessment sheet ready to fill in

Copy it to self-assessment.yaml in the project folder and fill it in. The column that matters is not the mark: it is evidence, the specific line of your dossier that justifies that level.

project: "Security dossier — <organisation>"
version_assessed: "v1.0"
self_assessment_date: 2027-03-15
days_of_rest_before_assessing: 3          # minimum 2; less and you assess yourself, not the text

dimensions:
  - id: D1
    name: "Understanding and application of concepts"
    weight: 10
    level: 3                               # 1 inadequate · 2 basic · 3 competent · 4 excellent
    evidence: "E1 §1.4: the STRIDE produces threats specific to the radiology flow"
    improvement_action: "Add why field-level encryption is NOT applied"
  - id: D2
    name: "Risk analysis and prioritisation"
    weight: 20
    level: 2
    evidence: "E2: 11 risks with a matrix, but 8 are technical and none is about fraud"
    improvement_action: "Add a third-party risk and a fraud risk; justify the order in prose"
  - id: D3
    name: "Controls and financial realism"
    weight: 20
    level: 3
    evidence: "E4 §4.2 reconciles at 8,628 € and 180 h; §4.3 with 3 dated discards"
    improvement_action: "State that the hours are at the limit and what falls if something slips"
  - id: D4
    name: "Response and recovery"
    weight: 15
    level: 2
    evidence: "RB-01 has phases and contacts, but not a single specific command"
    improvement_action: "Write the containment steps with exact commands and locations"
  - id: D5
    name: "Compliance and data protection"
    weight: 15
    level: 3
    evidence: "E7: RoPA with 4 activities, lawful basis and art. 9.2.h; reasoned DPIA"
    improvement_action: "Translate art. 32 into two specific E4 controls"
  - id: D6
    name: "Traceability and consistency"
    weight: 10
    level: 3
    evidence: "E7 §7.4: 12 rows, all with named evidence and a date"
    improvement_action: "Check that C-09 and C-15 also appear in the roadmap"
  - id: D7
    name: "Clarity and communication"
    weight: 10
    level: 2
    evidence: "The executive summary lists controls, not decisions"
    improvement_action: "Rewrite it: 5 risks, total investment and 3 key decisions"

# Calculation: Σ (level / 4 × weight)
score_out_of_100: 65.0
pass_threshold: 60
no_dimension_below_2: true                 # none below "basic"
d2_and_d3_at_least_3: false                # D2 is at 2 -> does NOT meet the condition
result: "NOT A PASS yet: D2 must reach competent before closing v1.0"

red_flags_checked:
  controls_fit_the_budget: true
  every_risk_has_an_owner: true
  policies_can_be_complied_with: true
  recovery_tested_or_declared_untested: true
  detective_controls_exist: true
  ropa_with_lawful_basis: true

acid_test: {q1: "OK", q2: "OK", q3: "OK", q4: "Failed", q5: "Shaky"}
second_pass_priority: ["D2", "D7", "D4"]

Look at the example: 65 out of 100 and still "not a pass", because D2 stays at basic and the D2/D3 condition is not offset by the mark. That is deliberate: a dossier with a good average and a weak risk analysis is a dossier that cannot be used to decide, which is what it exists for.


  1. What to do with the result: the second pass

Do not rewrite the whole dossier. The second pass is surgical: attack the two or three weakest dimensions and nothing else, within a bounded time — three or four hours — using the list of improvement_action entries as your script.

flowchart LR
    A["v1.0 finished"] --> B["Rest 48 h\nand read in another medium"]
    B --> C["Rubric + red flags\n+ acid test"]
    C --> D{"Threshold and\nD2/D3 conditions?"}
    D -->|"No"| E["Second pass:\nONLY the 2-3 weakest\ndimensions, 3-4 h"]
    E --> F["v1.1"]
    F --> C
    D -->|"Yes"| G["Close v1.0 and tag it.\nNote in the annex what\nis still outstanding"]
    G --> H["Future review:\nrelevant change, incident\nor anniversary"]
    H --> C

Two warnings about the loop. First: put a limit on it. Two iterations and you close. A project rewritten five times is not improving, it is avoiding finishing, and the third pass contributes less than starting to maintain it.

Second: a living dossier is worth more than a perfect one. An imperfect document with a date, a version and a scheduled review is a management system; an impeccable document nobody will ever open again is an essay. What gets assessed in the real world is not version 1.0: it is that a 1.1 exists six months later with the things that changed. That is why the last step of the diagram loops back to the beginning in three cases — a relevant change, an incident or the anniversary — exactly the reassessment triggers from 04-01.


  1. How to use the project professionally

The dossier does not die here. It has three real uses:

Use What to do Watch out for
Portfolio piece Publish the fictitious case dossier — or your own, anonymised — in a public repository, with a README explaining the brief and the constraints Do not publish anything from a real organisation without express authorisation to publish, which is different from authorisation to analyse
A real starting point If the organisation is yours or belongs to someone close to you, the dossier is already the starting point: roadmap, policies and matrix are written Mark the internal version as confidential and never mix the two copies
Technical interview script Bring the case prepared: it is inexhaustible material for "tell me about a project" and it demonstrates judgement, not memory Do not present it as something you implemented. Say what it is: an analysis and design exercise, and defend it as such

Why it works so well in an interview. Most junior candidates answer "talk to me about security" by reciting concepts. You can answer: "let me tell you about a case: a 25-person dental practice, three sites, clinical records on a legacy server, 9,000 € a year. My number one risk was the software vendor's access with a shared account, and I discarded the EDR because the vector was a legitimate credential". That answer cannot be memorised: only someone who has done the work has it. And the five questions in section 9 are, with very high probability, five of the questions you will be asked next.

One last note of professional honesty: do not inflate what it is. If your CV says "security lead at a dental practice", you are lying and it will be found out at the third question. If it says "analysis and design project for a security programme at a healthcare SME (case study)", you are telling the truth and it is still impressive.


Common Mistakes and Tips

  • Scoring yourself highly for the effort. "I put twenty-five hours into it" is not a dimension of the rubric. What is scored is what a reader finds on the paper, not what it cost you to put it there. The evidence column on the self-assessment sheet exists precisely to defuse this bias.
  • Assessing while it is still hot, the same day you finish. You are reading your intention, not your text. The 48 hours of rest are the cheapest and most effective intervention in the whole lesson.
  • Confusing length with quality. A fifteen-page E2 with thirty badly written risks scores below a four-page one with ten well-built risks and a justified order. In D2 and D3 what is assessed is judgement, not volume.
  • Rewriting everything after a criticism. An external review points at symptoms; you decide the treatment. Note it down, let it rest and decide in the cold light of day what you take on board: not every criticism is right, but every criticism marks a point where the text was not obvious.
  • Tip: assess with the sheet in front of you and the dossier behind it. Go dimension by dimension, and for each one look for the evidence before writing the number. If it takes you more than a minute to find it, you already know that level is not the one you were about to write.
  • Tip: keep the self-assessment with the dossier. Having v1.0 carry its own critique attached is a sign of professional maturity, and if one day you show the project, the assessor will read your self-assessment before your executive summary.

Exercises

Exercise 1 — Score one dimension with evidence

Pick D3 (controls and financial realism) in your dossier. Without looking at the rubric, decide what level you would give yourself. Now go to the descriptor, look for the specific line that proves each requirement of the level you have given yourself, and correct the mark if you cannot find it. Write the complete self-assessment.yaml entry for that dimension, with evidence and improvement_action.

Exercise 2 — Raise a deliverable by one level

Take the worst-written risk in your E2 — the one you like least — and rewrite it to raise it one rung of the rubric: from basic to competent, or from competent to excellent. Mark in the text exactly what you have added to change level.

Exercise 3 — The acid test, recorded

Answer the five questions from section 9 out loud and recording yourself, without looking at the dossier. Listen to the recording with the "what a good answer is" column in front of you. Note which questions you failed and turn each failure into an action on a specific deliverable.

Solutions

Solution 1 — D3 scored with evidence (dental practice)

- id: D3
  name: "Controls and financial realism"
  weight: 20
  intuitive_level: 4        # "it reconciles perfectly, I have discards, it must be excellent"
  level_after_looking_for_evidence: 3
  evidence:
    - "E4 §4.2: 8,628 € against 9,000 € and 180 h of Nuria's time, with a 20 % reserve ->
       it reconciles in euros AND in hours [COMPETENT requirement: met]"
    - "E4: C-04 recovery and C-11 detective are present [COMPETENT: met]"
    - "E4 §4.3: EDR, software replacement and pentest, with a reason and a review date
       [COMPETENT: met]"
    - "The pentest discard is argued by sequence and not by cost
       [EXCELLENT: met]"
    - "I can find NO line declaring that Nuria's hours are left with zero margin, nor
       which control falls if something unexpected comes up [EXCELLENT: NOT met]"
  correction: "Down from 4 to 3. The explicit declaration of the resource at its limit is
               missing, and it is one of the two requirements of the excellent level."
  improvement_action: "Add a paragraph in §4.2: 'the real margin is 0 h of Nuria's time;
                       if something unexpected comes up, C-08 (secure photo channel) is
                       postponed to the following quarter, because it is the only one
                       whose associated risk (R-06) has an administrative alternative in
                       the meantime'."

What is relevant about the solution is not the mark: it is that intuition said 4 and the evidence said 3, and that the difference turned into a three-line improvement action that also forces a new decision — which control falls first. That is the real return on a rubric well used: it does not classify, it produces specific work.

Solution 2 — Raising a risk from basic to competent

BEFORE (basic)
  R-02  Risk of patient data being leaked over WhatsApp.
        L=4, I=4, High. Mitigate. Owner: reception.

AFTER (competent)
  R-02  If reception staff send or receive intraoral photographs and clinical data over
        WhatsApp on the practice phones (A-14), then article 9 health data ends up
        stored and backed up in a third party's service outside the practice's control
        and accessible to anyone holding the handset, with processing that has no
        documented lawful basis, no way to honour an erasure request over those copies
        and direct exposure to penalties before the AEPD.
        Inherent: L=5 (it happens daily) x I=4 = CRITICAL.
        Strategy: mitigate with C-08 (integrated secure channel) and C-14 (training).
        Residual: L=2 x I=4 = HIGH, and it will not drop further until the habit is
        replaced: the technical measure without a convenient alternative does not work.
        Owner: Nuria Prado.  Review: monthly for 9 months (indicator 6).

WHAT I ADDED TO RAISE THE LEVEL
  1. The complete causal chain with the identified asset (A-14) instead of a statement.
  2. The impact in business and legal language -art. 9, right to erasure, AEPD- instead
     of "data gets leaked".
  3. An owner with a first name and a surname instead of a department.
  4. The residual justified, with the reason why it does not drop further.
  5. A review cadence consistent with the indicator that measures it.

Solution 3 — Reading the acid test

A typical and very informative result for a first version: Q1 correct (the risk is named but not compared with the second: half an answer), Q2 correct, Q3 correct, Q4 failed, Q5 shaky.

Question Diagnosis Specific action on a deliverable
Q1 partial You know which is first, but not why before the second Add a prioritisation paragraph to E2 comparing R-01 with R-02
Q4 failed The controls are known, the evidence proving them is not Fill in the "evidence" column of the 12 E7 rows with named, dated documents
Q5 shaky You know there are 72 h, not when they start or who decides Write into PR-BRE-01 the exact trigger for the clock and who declares the breach

The overall reading is the one that counts: failing Q4 and hesitating on Q5 is the commonest pattern, and it means the dossier is strong on deciding and weak on proving. It is exactly the jump made in 06-04, and the good news is that it is fixed with two hours of work on E7 without touching any other deliverable.


Conclusion

You now know how to assess yourself, which in a course with no teacher is the last piece that was missing. You know why self-assessment is a professional competency and not a workaround: in real work almost nobody marks your dossier, and whoever can look at their own and say "this is weak and here is why" is the person who ends up being asked to review everyone else's. And you know how to neutralise author bias with the three rules: score what is written and not what you know, let it rest for 48 hours and read it in another medium, and demand evidence for every point you award yourself.

You have the complete rubric: seven dimensions with their weights — D2 risk analysis and D3 realism of the controls add up to 40 %, because they are the only two where anything is decided — four levels with observable descriptors, and a threshold that does not offset: 60 out of 100, no dimension below basic and D2 and D3 at competent as a minimum. And you have the rubric applied, which is the part that really teaches: the same risk written four times — where the jump to excellent is the second-order consequence, the quantification with its assumptions and the paragraph justifying its position on the list — and the same control written four times, where the jump to excellent is explaining why this one and not the expensive one, and above all having a plan B when the control depends on a third party agreeing to something.

You know the six red flags that cancel out a dossier however good it looks — controls that do not fit, risks with no owner, policies that cannot be complied with, a never-tested recovery presented as a capability, zero detective controls and a RoPA with no lawful basis — plus the seventh, subtle and frequent: everything showing as "implemented" in the first year. You know how to ask for a peer review with three bounded questions about D3, D4 and D7, and how to receive it without defending the document. And you have the acid test: what your number one risk is and why before the second, what happens at three in the morning, what you have left out, how you prove the control works — the one almost everybody fails — and what you notify within 72 hours.

You take away the self-assessment sheet with its evidence column and its calculation, the second pass loop — surgical, on the two or three weakest dimensions, with a limit of two iterations — and the thesis that orders it all: a living dossier is worth more than a perfect one, because what gets assessed in the real world is not v1.0 but the existence of a v1.1 with whatever changed. And you know what to do with the project afterwards: an anonymised portfolio piece, a real starting point if the organisation is yours, and a technical interview script — saying exactly what it is, an analysis and design exercise, which is still far more than most people can talk about.

In 07-04 comes the last lesson of the course. You will find a complete reference solution worked out on the dental practice, with the explicit reasoning behind every decision and the hard calls commented on; the honest comparison with what you have done — there is no single correct answer, but there are indefensible ones; and after that, the map of where to go next: specialisations within the profession, certifications commented on honestly, how to keep learning in practice and one last look at Nimbus. Go there only when your dossier is finished and self-assessed: reading it earlier saves you work and takes away the learning.

Fundamentals of Information Security Course

Module 1: Introduction to Information Security

Module 2: Cybersecurity

Module 3: Cryptography

Module 4: Risk Management and Protection Measures

Module 5: Security Tools and Techniques

Module 6: Best Practices and Regulations

Module 7: Final Project

© Copyright 2026. All rights reserved