Baseline Review · Version 1.0

Private, local review. Not an assessment platform.

Work through the ten-question Baseline privately.

Answer the canonical Domain Governance Baseline questions in this browser tab, optionally consider six broader governance themes, then generate a review summary of priorities, evidence needs and practical next steps.

10 canonical questions Optional follow-on themes No retained answers Copy or print summary

No account. No score. No assurance conclusion. Your answers stay in this browser tab and disappear when the page is closed or reloaded. Use the resulting summary in governance processes your organisation already operates.

About the Baseline See a worked walkthrough

Review boundaries

Checklist
Ten canonical Version 1.0 starting-point questions
Optional guidance
Six follow-on themes for broader domain-governance review
Output
Baseline Review Summary - not a score, rating or assurance report
Processing
Generated locally in the browser. No answers are sent to a backend.
Canonical reference
Version 1.0 reference edition
Starting point · Canonical Baseline

The ten-question checklist

The questions are intentionally basic, not a comprehensive control framework. If the organisation cannot answer one clearly, that uncertainty is where follow-up starts. Items marked externally observable form part of the public trust surface.

0 of 10 answered
Optional follow-on

Go further only where useful

The ten questions are the complete starting point. These six themes are optional prompts for organisations that want to carry the findings into broader recurring governance. You do not need to answer them to generate a review summary.

0 of 6 considered
Your baseline review

Review summary

Priorities for follow-up

Baseline questions you marked as partial, not in place, or not sure - ordered so the most open questions come first. Each is shown at three levels: board / exec / risk, technical, and public trust / service impact.

Your public trust surface

The externally observable items - the parts of your domain layer anyone can inspect from outside via DNS, RDAP, DMARC or certificate transparency.

Practical next steps

Guide links based on the questions that need follow-up. These are not scores, findings of fault or automated assurance recommendations.

What is already in place

Baseline items you can answer clearly today. Worth protecting - the recurring-review guide is how you keep them true.

Optional follow-on themes

Only the broader themes you chose to consider in this pass.

A missing signal does not mean an organisation is irresponsible, and a passing signal does not mean everything behind it is well managed. Observation is not judgement - but it can strengthen governance decisions, evidence and follow-up. Use this as a starting point to bring the domain layer into broader digital governance.
Move from review to practice. See the worked walkthrough for one fictional organisation's path from uncertainty to evidence, decisions and records, then use the five practical guides to establish and sustain domain visibility, privileged authority, email trust, incident readiness and recurring governance.