STAGE 03 / 16 · ACT 1 · Decide

Preliminary security risk assessment

Assess the broad security risks while there is still room to change the concept. A preliminary security risk assessment compares options, identifies major constraints and exposes uncertainty before the team commits to a detailed solution.

What to do at this stage

  1. 01

    Build a short list of plausible security scenarios for each main option.

  2. 02

    Compare the indicative risks, existing protections and important uncertainties.

  3. 03

    Record the assumptions that will need testing in the detailed assessment.

Questions to work through

  • Which options change the risk most?
  • What remains uncertain at this point?
  • Could a different concept avoid a costly treatment later?
AN EXAMPLE IN PRACTICE

Compare two potential sites before signing a lease. Access arrangements, neighbouring activities and emergency response may affect the security concept.

A common trap

A preliminary rating is an aid to choosing a direction; it should not silently become the final accepted risk rating.

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter