Each control is evaluated against techniques actually used against the client's sector, not against a documentary compliance checklist alone.
Audit
An audit conducted from a checklist alone measures an organization's documentary compliance with a framework — whether a policy, procedure, or expected configuration exists. It does not measure how well those controls actually resist an intrusion attempt.
TRACE complements this documentary review by testing each control against the techniques actually used against the client's industry. A control judged compliant on paper can prove ineffective against the specific technique that would be used against the organization — TRACE is built to surface that gap.
TRACE runs in five steps, each named after a letter of the acronym.
Threat profiling
The client's sectoral and geographic threat profile is established: attacker groups active in this sector and region, preferred techniques and vectors, recent documented incidents.
Reconnaissance
The client's real exposure surface is mapped — exposed assets, entry points, trust chains with third parties — as an attacker would discover it.
Assessment
Each existing control is evaluated against the applicable framework (ISO/IEC 27001, NIST CSF, PASSI DGSSI, or another, depending on the client's context), in the sense of a classic compliance audit.
Control effectiveness
The real-world effectiveness of each control is tested against the techniques identified in the Threat profiling step — not against a generic use case.
Evidence
Each identified gap is recorded with opposable evidence and tied to a remediation plan prioritized by impact and likelihood of exploitation.
In a TRACE audit, every documented gap is tied to an identified attack technique (referenced against MITRE ATT&CK where applicable) and to a quantified impact scenario for the organization — not merely to a reference to a standard's clause. The resulting remediation plan prioritizes gaps by real exploitability rather than by documentary weight alone.
TRACE structures our security and compliance audit engagements, whether aimed at certification, regulatory compliance, or an independent posture assessment.