# P12 AWS Resilience Hub assessment workbook

Use with AWS235. This is a no-create model and evidence review.

## 1. Experience and ownership

- Account and home Region:
- Existing Resilience Hub application model or Next generation model:
- Review date and Region availability source:
- Business/system owner:
- Service/application owner:
- Resilience policy owner and approver:
- Invoker/discovery role and cross-account roles:
- KMS key and service-data owner:
- Monthly assessment/test/dependency-discovery budget:

Do not mix `aws resiliencehub` application APIs with `aws resiliencehubv2`
system/service APIs. Record which experience produced every item of evidence.

## 2. Business topology

| User journey | Service/application component | Entry point | Resources/Regions/accounts | Hard dependencies | Soft dependencies/fallback | Data store/source of truth | Owner |
|---|---|---|---|---|---|---|---|
| Place order |  |  |  |  |  |  |  |

Prove data-flow edges. Inventory-only membership is not topology. Classify DNS-
discovered internal, AWS and third-party dependencies and document blind spots,
including direct IPs, inactive dependencies and shared-VPC attribution.

## 3. Resilience objectives

### Existing application model

| Disruption | Target RTO | Target RPO | Business rationale | Estimated RTO/RPO | Met/breached/not applicable | Evidence limitation |
|---|---|---|---|---|---|---|
| Application/software |  |  |  |  |  |  |
| Infrastructure/hardware |  |  |  |  |  |  |
| Availability Zone |  |  |  |  |  |  |
| Region |  |  |  |  |  |  |

### Next-generation modular policy

| Policy component | Objective/SLO | Evaluation scope | Finding | Recommendation owner | Due date |
|---|---|---|---|---|---|
| Availability |  |  |  |  |  |
| Disaster recovery |  |  |  |  |  |
| Data recovery |  |  |  |  |  |

Estimated values and GenAI findings are decision support, not measured recovery.

## 4. Resource discovery and version

| Input source | Exact version/location | Included count | Missing/unsupported resources | Wrong/shared resources | Correction/owner |
|---|---|---|---|---|---|
| CloudFormation |  |  |  |  |  |
| Tags |  |  |  |  |  |
| Terraform state |  |  |  |  |  |
| EKS |  |  |  |  |  |

- Published application version or discovered service topology ID/time:
- At least two resources with a data-flow relation for next-gen assessment:
- Configuration drift since assessment:
- Dependency-discovery lookback and attribution limitations:

## 5. Assessment and recommendation register

| Assessment/finding ID | Version/time/status | Disruption/failure mode | Severity | Reasoning and assumptions verified? | Recommendation | Accept/change/reject | Owner/date/evidence |
|---|---|---|---|---|---|---|---|
|  |  |  |  |  |  |  |  |

Never accept a generated recommendation without checking resource support,
architecture constraints, blast radius, cost, IAM and business objective.

## 6. Operational readiness

| Failure mode | Detection/CloudWatch alarm | SOP/SSM runbook and role | FIS/test hypothesis | Targets/blast radius | Stop conditions | Expected steady state | Last successful measured result |
|---|---|---|---|---|---|---|---|
|  |  |  |  |  |  |  |  |

An implemented alarm is not a tested alarm. An SOP document is not a successful
recovery. A recommended FIS experiment is not authorization to execute it.

## 7. Proof and reassessment

- Baseline assessment and score/finding export:
- Resource/topology corrections:
- IaC change set and approval:
- Alarm positive/negative test:
- SOP execution and permission/failure test:
- Controlled failure test and stop-condition evidence:
- Measured data loss and end-to-end recovery time:
- New published version/topology refresh:
- Reassessment ID and changed findings/compliance:
- Remaining accepted risk, exception expiry and owner:
- Removed test resources and exact negative inventory:
