Mohsin Anwar Sharif

Checking that a rollout delivered what it promised

After each platform went live, I wrote a post-implementation assessment for my team: a terms of reference setting the scope, then a printed checklist where every check had an owner, evidence and a manager's signature. I did this for Defender, SentinelOne, Darktrace and Zscaler.

The method

  1. Scope it. A terms of reference sets the objectives, the components in scope, the stakeholders to interview, the frameworks to map against (NIST CSF, CIS, ISO 27001) and the timeline.
  2. Define each check. Every check says what good looks like and how it will be verified, before anyone looks.
  3. Evidence every result. Each result points to a screenshot or export. No evidence, no pass.
  4. Judge it. Pass, partial, fail or not applicable, with a remark for anything that is not a pass.
  5. Sign it off. The assessor and the manager sign the printed copy, and every failure becomes a tracked action.

Sample checklist: Microsoft Defender for Endpoint

Try it: set results and remarks, then print it to see the signed-off version.

OrganisationFictional Bank Ltd
ScopeDefender for Endpoint with Intune
AssessorEndpoint security
PeriodPost go-live review
#AreaWhat good looks likeHow verifiedOwnerEvidenceResultRemarks
1Onboarding coverageIn-scope devices onboarded, compared with the asset inventoryInventory export vs Defender device listEndpoint teamEV-01
2Sensor healthOnboarded devices report an active sensor and recent telemetryDevice health report, filtered for inactive or impairedEndpoint teamEV-02
3Real-time and cloud protectionEnabled everywhere and not overridable by usersIntune antivirus policy plus device sampleEndpoint teamEV-03
4Tamper protectionEnabled across the tenantPortal setting plus device sampleEndpoint teamEV-04
5Attack surface reductionASR rules in block or audit mode as approvedIntune ASR policy vs approved rule listEndpoint teamEV-05
6Firewall policyWindows Firewall profiles enforcedIntune policy assignment reportEndpoint teamEV-06
7Device complianceCompliance policy uses the Defender device risk levelIntune compliance policy settingsIntune adminEV-07
8Conditional accessNon-compliant devices blocked from corporate appsEntra conditional access policyIdentity teamEV-08
9Alerts reach the SIEMA test detection on a lab device appears in the SIEMTest alert plus SIEM searchSOCEV-09
10Automated investigationAutomation level set as approvedPortal settingsSOCEV-10
11Role-based accessPortal roles follow least privilegeRole assignment export reviewSecurity adminEV-11
12Vulnerability viewSecure Score and vulnerability findings reviewed, owners assignedScore export and action listVulnerability teamEV-12
Assessed by
Date and signature
Reviewed and approved by (manager)
Date and signature
Comments

Same template, other platforms

I wrote one of these after each rollout. The structure stays the same; the checks change.

SentinelOne

  • Policy mode set per group as approved
  • Exclusions ticketed, risk-approved and time-limited
  • Console certificate expiry monitored
  • Agent versions within support

Darktrace

  • Sensors cover the agreed network segments
  • Known scanners labelled to cut false positives
  • Alerts routed to the SOC

Zscaler

  • All users forwarded through the proxy
  • SSL inspection bypass list approved
  • Blocklists current
  • URL and application policy per group

The originals stayed with the bank. This page shows the structure, rebuilt on fictional data.