Start with insight. Create an overview of critical processes, data, systems, suppliers, subcontractors, management access, applicable jurisdiction and existing exit options.
Then link the most important dependencies to availability, integrity and confidentiality. Only when it is clear what is critical and what it depends on, can you choose an appropriate goal and measures.