Service Delivery & ITSM Weight: 15% Incident management, SLA tracking, problem governance, change control, service reviews
Monthly service reviews with SLA/KPI reporting Major incident process with executive communication Problem management reduces recurring incidents Change control with risk assessment and rollback
Risk & Resilience Weight: 20% Cyber risk governance, DR/BCP, privacy assessments, audit readiness, operational continuity
IT risk register owned and reviewed quarterly DR/BCP tested annually with documented results Privacy impact assessments for new processing Audit-ready evidence for key controls
Supplier Governance Weight: 25% Vendor scorecards, contract oversight, MSP management, commercial control, escalation paths
Vendor scorecards with quarterly review cadence Contract register with renewal tracking MSP performance measured against SLA/OLA Commercial escalation paths documented
Modern Workplace Readiness Weight: 15% M365 maturity, identity/access, endpoint management, Zero Trust, collaboration governance
Entra ID / Azure AD with Conditional Access Intune or equivalent endpoint management MFA enforced for all external access Collaboration governance (Teams/SharePoint)