An IT team wants to improve their risk management maturity but does not know where their current vulnerabilities lie. What should be their very first step according to ITIL 4 guiding principles?
Starting where you are requires investigating the actual current state before planning improvements.
Why this answer
Not knowing where vulnerabilities lie means assessing the current state using 'Start where you are'.