This is the stage where scope actually gets decided — which controls you test first, which identity assurance level you commit to, and how you keep configuration from drifting the moment testing ends. Three practical breakdowns, each with its own worksheet and training.
Pain point: teams don't know the difference between "the baseline" and "what actually applies to us." The control catalog hands you a starting list — it doesn't tell you which controls carry real risk in your environment, which identity tier your systems actually need, or how to keep what you've selected from drifting out of sync with reality.
The three topics below are the practical answer to that gap, in the order most teams hit them: sequence the catalog, decide identity assurance, then keep configuration honest once controls are in place.
Each one is a standalone article with its own fillable worksheet, training deck, and course — start wherever your environment needs it most.
Nobody tells you which NIST controls you can actually defer. The four-question framework that sorts 300+ controls into a sequence you can defend to an assessor.
Teams default to "MFA = done" without understanding IAL/AAL/FAL tiers — or the current push toward phishing-resistant MFA. What identity assurance actually requires.
Config drift is the gap between what's documented and what's actually deployed. How to keep a CM plan honest after the controls are selected and testing is done.
Prioritization decides what you test first. Identity assurance decides how strong access controls need to be, once you know which systems carry the most weight. Configuration management decides how you keep those decisions true after testing ends. Different questions, same discipline: does what's written down still match what's real.
All three worksheets and all three training decks for Stage 3, in one package — prioritization, identity assurance, and configuration management.