Do you have visibility into the network and all endpoints to ensure that a proper audit trail exists and that the telemetry data required for security monitoring and incident response exists?
Is there a log that records all infrastructure changes, including who reviewed the changes, testing performed, back out plans, acceptance/denial, and who performed the changes?