CERG Lite Adoption Pack
CERG Lite is the minimum viable adoption path for a small or early security function. It is designed for teams that need a real operating loop without adopting the full CERG library at once.
1. Who should use this pack
Use CERG Lite if:
- The security team has roughly 2 to 8 active participants.
- Security ownership exists, even if part time.
- Leadership supports documented guardrails, risk decisions, and evidence.
- The organization can name its core systems, owners, and regulatory concerns.
If there is only one security person, use CERG as a planning reference until there is an executive sponsor and an independent approver for High or Critical risk decisions.
2. What to adopt first
Adopt only the MVC spine first:
- Cybersecurity Policy
- CERG Framework
- Operating Model
- Document Catalog
- Risk Management Framework
- Risk Register and Exception Process
- Risk Register Templates
- Exposure Management Procedure
Use the Organization Adaptation Profile, Small Team Adoption Path, and Role-Based Implementation Checklists as aids, not extra first-week obligations.
3. First 48 hours
- Confirm executive sponsor and security owner.
- Select CERG Lite and document why.
- Fill the Organization Adaptation Profile at a draft level.
- Assign consolidated roles for Engineering, Risk, and Governance accountabilities.
- Create the first risk register entry.
- Create the first exposure backlog item.
- Decide where records will live.
- Schedule the first monthly risk and exposure review.
4. First 30 days
| Week | Outcome |
|---|---|
| Week 1 | Scope, owners, record locations, first risk, first exposure item |
| Week 2 | Risk register cadence, exception path, initial asset/source inventory |
| Week 3 | First exposure management cycle and remediation ownership |
| Week 4 | First evidence review, deferral list, and next adoption decision |
5. Safe deferrals
These are normally safe to defer during the first 30 days:
- Most standards, unless an immediate environment or regulator requires them.
- Detailed job descriptions.
- Workforce planning, succession, and performance frameworks.
- Regulated operational packages unless CMMC, NERC-CIP, SOX, ISO, privacy, OT, or CUI scope applies.
- Advanced machine-readable schemas.
Do not defer the risk register, exception process, owner assignment, or exposure management loop.
6. Files in this pack
README.md: human adoption guide.document-list.yaml: structured MVC and helper document list.agent-prompt.md: copy/paste prompt for agent-assisted adoption.
7. Success test
CERG Lite is working when the team can show:
- Named owners for the three pillars, even if consolidated.
- A current risk register.
- A current exposure backlog.
- A documented exception or risk acceptance path.
- Evidence that at least one exposure cycle was run.
- A deferral list explaining what is not yet adopted and why.
Source: adoption-packs/cerg-lite/README.md ·
Download .md ·
View on GitHub