The summary.
ORGANISE AROUND SERVICES, NOT TECHNOLOGY
Users do not care which server failed; they care that email is unavailable.
DISTINGUISH INCIDENTS, REQUESTS AND PROBLEMS
An incident restores service. A request follows a process. A problem eliminates a cause.
Without the distinction, nothing is ever fixed permanently and requests are treated as emergencies.
MOST INCIDENTS FOLLOW A CHANGE
Record what changed, when and by whom. It answers the first question in every incident.
OUT-OF-DATE DOCUMENTATION IS WORSE THAN NONE, BECAUSE IT IS TRUSTED
Update it as part of the change, at the time. Documentation updated later is not updated.
RECORD EVERY SYSTEM GRANTED WHEN SOMEONE JOINS
That record is what you work through on departure. And adjust access on role change rather than adding to it.
YOU CANNOT SECURE, MAINTAIN OR BUDGET FOR WHAT YOU HAVE NOT RECORDED
When a vulnerability is announced, the first question is what you have.
RECONCILE LICENCES IN BOTH DIRECTIONS
Unlicensed installations are exposure; unused licences are recoverable cost.
JUSTIFY SPEND IN BUSINESS TERMS
Risk reduced or capability gained. Technical justification does not persuade non-technical decision makers.