|
01 · Stack and suppliers
Applications, suppliers, contracts and responsible owners.
|
Concentration, business criticality, contractual exit and clarity of ownership. |
A system and supplier inventory with a recommendation per component. |
|
02 · Data and portability
Data locations, flows, formats, exports and integrations.
|
Sensitivity, interoperability, lock-in and whether exported data can be restored elsewhere. |
A data-flow view, portability findings and an export or recovery action. |
|
03 · Identity and continuity
Identity dependencies, access paths, critical processes and acceptable downtime.
|
Failure impact, recovery assumptions and single points of dependency. |
A criticality profile and a retain, hybrid or replace route. |
|
04 · Compliance and control
Jurisdictions, contractual requirements and relevant compliance constraints.
|
Where data and control reside, and whether supplier or hosting terms remain proportionate. |
Attention points and a revised hosting or control boundary. |
|
05 · Operations and recovery
Backups, restore evidence, internal capability and current management effort.
|
Tested recovery, operational burden, security updates and responsibility during incidents. |
Priority fixes and an explicit operational or managed responsibility model. |
|
06 · Alternatives and roadmap
Available alternatives, budget, timing and migration constraints.
|
Feasibility, cost, continuity, migration effort and the actual value of change. |
A prioritised roadmap: retain, hybrid, replace, host differently, retire or evaluate later. |