| Vulnerability scanning | Scanner licence, asset coverage and remediation administration | Agreed scanning coverage and connected remediation workflows |
|---|
| Compliance automation | Framework subscriptions and evidence preparation effort | Selected framework mapping and evidence workflows |
|---|
| Risk register | Risk-tool licence and manual record reconciliation | Connected risk records, owners and review actions |
|---|
| Incident response | Case management tooling and separately contracted response services | Incident workflow; specialist response remains separately scoped |
|---|
| Policy management | Document tooling, approvals and acknowledgement tracking | Policy lifecycle, approvals and staff acknowledgement |
|---|
| Security training | Training subscriptions and administration | Selected training capabilities and agreed user coverage |
|---|
| Audit and evidence | Evidence collection, preparation and recurring staff effort | Connected records and evidence for the agreed controls |
|---|
| Integration maintenance | Connector subscriptions, implementation and maintenance time | Supported integrations and any agreed implementation work |
|---|
| Total commitment | Current licence costs, staff effort, renewal dates and transition costs | Agreed Fig package, optional services and implementation costs |
|---|