# Security Architecture Review

> From $40K · Compliance & GRC · https://cisomarketplace.services/services/security-architecture-review

Comprehensive analysis of your organization's security architecture design, evaluating defense-in-depth strategies, security control effectiveness, and alignment with business objectives and threat models.

## In scope

- Network segmentation analysis
- Access control frameworks
- Data flow assessment
- Security boundary evaluation
- Defense-in-depth review
- Zero Trust framework compatibility
- Identity and authentication architecture review

## Deliverables

- Detailed architecture assessment report
- Security control gap analysis
- Reference architecture recommendations
- Risk mitigation roadmap
- Prioritized security enhancement plan
- Threat modeling documentation

## Tiers

### Core Architecture Assessment: $40K

One environment: up to 500 employees, up to 2 data centers/sites and up to 3 cloud accounts. Reviews segmentation, access control, identity architecture, data flows and security boundaries from diagrams, configs and workshops. One high-level threat model.

Limits: employees 500, locations 2, cloud accounts 3

Includes:
- Network segmentation and security boundary analysis
- Identity and authentication architecture review
- Data flow assessment for critical data
- One high-level threat model
- Control gap analysis and prioritized enhancement plan

Excludes:
- Zero Trust implementation strategy
- Per-system threat models
- Reference architecture design
- Penetration testing or configuration scanning

### Advanced Architecture Program: $75K

Up to 2,500 employees, up to 5 sites and up to 10 cloud accounts. Adds documented threat models for up to 5 critical systems, a defense-in-depth control mapping and a phased Zero Trust implementation strategy.

Limits: employees 2500, locations 5, cloud accounts 10

Includes:
- Everything in the core assessment
- Threat models for up to 5 critical systems
- Zero Trust compatibility assessment and phased strategy
- Defense-in-depth control mapping
- Risk mitigation roadmap

Excludes:
- Target-state reference architecture
- Security governance framework
- Implementation or engineering work
- Penetration testing

### Enterprise Security Architecture Transformation: $125K

No fixed headcount cap - scoped. Up to 10 sites and up to 25 cloud accounts. Adds a target-state reference architecture, a multi-year modernization roadmap, threat models for up to 10 critical systems and an architecture governance framework (review board, standards, exceptions).

Limits: locations 10, cloud accounts 25

Includes:
- Everything in the advanced tier
- Target-state reference architecture
- Multi-year modernization roadmap with sequencing
- Architecture governance framework
- Threat models for up to 10 critical systems

Excludes:
- Building or deploying the target architecture
- Product selection RFPs
- Penetration testing
- Ongoing architecture review board participation

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=security-architecture-review
