Review the practices together, not as five separate programmes
The recurring review is the maintenance mechanism for the earlier guides. It should draw from authoritative records, incidents and changes - not ask teams to complete a new assessment or produce a parallel report every quarter.
Portfolio and ownership
New, changed, legacy and retirement-candidate domains; accountable owners; renewal continuity; unresolved inventory questions.
Registrar and DNS authority
Privileged access, MFA, recovery paths, locks, provider changes, automation credentials and material DNS changes.
Email authority and public signals
Approved senders, supplier authority, SPF, DKIM, DMARC, report themes, non-sending posture and obsolete records.
Incident and continuity readiness
Incidents, near misses, exercises, provider limitations, stale contacts, recovery evidence and overdue remediation.