STAGE 02 / 16 · ACT 1 · Decide

Context, criticality and threat

Understand what needs protection and why it matters. Set the context for assessing security risks by considering assets, critical activities, dependencies, threats and risk criteria. For an existing operation, establish what controls already operate and how well they work.

What to do at this stage

  1. 01

    Identify the people, assets, information and services within scope, including important dependencies.

  2. 02

    Describe plausible threats and the consequences of losing a critical capability.

  3. 03

    Agree risk criteria and document the assumptions and evidence that shape the assessment.

Questions to work through

  • What would be most difficult to lose or replace?
  • Which threats are relevant to this setting?
  • Are existing controls being credited on evidence?
AN EXAMPLE IN PRACTICE

A laboratory may depend on a small refrigeration system more than on a much more expensive but replaceable item of equipment. Criticality helps distinguish those priorities.

A common trap

Asset purchase price alone is an incomplete measure of the consequence of its loss.

When the work needs to return

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter