IT Assessment Discovery & Evidence Guide

A practical field guide for conducting structured IT discovery, asking better assessment questions, requesting useful evidence, and validating how an environment actually operates.

Download DOCX

About this resource

The #GoodwinGetsIT IT Assessment Discovery & Evidence Guide is a practical field guide designed to help IT professionals and consultants understand an unfamiliar technology environment through structured discovery, interviews, evidence, and validation.

Anybody can ask:

"Do you have backups?"

The useful questions are:

What is actually backed up?
When was something last restored?
Who knows how to recover it?
And can we prove it?

That's the difference between collecting answers and performing an assessment.

This guide helps turn an informal technology review into a repeatable discovery process without immediately steering the conversation toward a particular vendor, platform, or replacement project.

Use it when assessing a new environment, beginning a consulting engagement, taking responsibility for an existing IT department, transitioning between MSPs, conducting technology due diligence, or simply trying to understand whether the environment you think exists matches the one that actually exists.

The guide includes:

Discover → Validate → Prioritize Assessment Methodology - Follow a straightforward three-step approach for understanding the environment, confirming important answers with evidence, and prioritizing findings according to actual business and technical risk.

Environment Snapshot - Capture the organization, sites, primary contacts, core technology platforms, business-critical services, known constraints, compliance considerations, staffing concerns, legacy systems, and other assessment context.

Initial Evidence Request - Start an engagement with a practical evidence list covering privileged access, administrator accounts, backups, restore testing, vulnerabilities, patching, infrastructure diagrams, MFA, security exceptions, documentation, licensing, contracts, disaster recovery, and vendor relationships.

Evidence Prioritization - Separate High and Medium-priority evidence so the organization isn't asked to produce every document, screenshot, export, contract, diagram, and log file it has before the assessment can even begin.

Because overwhelming everyone with a 97-item evidence request on Monday morning is an excellent way to become everyone's favorite consultant. 😂

First-Day Assessment Workflow - Follow a practical sequence for establishing scope, identifying business-critical services, validating core controls, reviewing operational areas, and documenting findings and evidence gaps.

Identity & Access Discovery Questions - Explore administrative access, privileged account separation, provisioning and offboarding, service accounts, shared credentials, access reviews, and undocumented dependencies.

Backup & Recovery Discovery Questions - Determine what is protected, how recovery is verified, when restores were last tested, who owns failed jobs, how backup copies are protected, and whether critical SaaS and infrastructure configuration data are included.

Patching & Vulnerability Discovery Questions - Review patch cadence, remediation ownership, exploitable vulnerabilities, exceptions, unsupported systems, lifecycle exposure, and the accuracy of compliance dashboards.

Network & Infrastructure Discovery Questions - Investigate diagrams, internet connectivity, firewalls, switching, storage, virtualization, power, routing, VLANs, DNS, DHCP, monitoring, management interfaces, dependencies, and infrastructure single points of failure.

MFA & Security Discovery Questions - Examine MFA enforcement, bypasses, legacy authentication, endpoint security, email protection, centralized logging, retention, security exceptions, and monitoring.

Documentation Discovery Questions - Determine whether diagrams, runbooks, inventories, recovery instructions, dependencies, vendor contacts, and SOPs are accurate, accessible, owned, reviewed, and usable by someone other than the original author.

Licensing & Spend Discovery Questions - Review utilization, product overlap, renewals, contracts, cancellation windows, legacy subscriptions, inactive users, and other areas where unnecessary cost may be hiding.

Disaster Recovery Discovery Questions - Explore restore order, RTOs, RPOs, decision authority, tabletop exercises, failover testing, communications, major dependency failures, and how lessons from incidents turn into remediation.

Vendor & MSP Discovery Questions - Clarify responsibility boundaries, administrative access, escalation procedures, contracts, SLAs, renewals, support relationships, and third-party dependencies.

Examples of Useful Evidence - See practical examples of evidence that can support findings across each assessment domain, including administrator inventories, restore-test results, vulnerability reports, firewall reviews, diagrams, security configurations, runbooks, utilization reports, DR plans, contracts, and responsibility matrices.

The guide intentionally focuses on evidence instead of assumptions.

An interview tells you what people believe happens.

Documentation tells you what is supposed to happen.

Evidence helps determine what is actually happening.

All three matter.

The goal isn't to interrogate the IT team or prove somebody has been doing something wrong.

The goal is to understand the environment well enough that the eventual recommendations are based on reality.

Because "we've always done it this way" is useful context.

It's just not evidence.

File Information

File Type
Word
File Size
356 KB
Version
1.0
Last Updated
August 21, 2026
Downloads
9

Found this useful?

Follow #GoodwinGetsIT for more practical IT lessons, templates, and resources.