STAGE 05 / 16 · ACT 2 · Plan

Project Security Management Plan

Set out how the project will manage security work. A Project Security Management Plan connects responsibilities, interfaces, deliverables, reviews and decision points so security activity stays coordinated throughout delivery.

What to do at this stage

  1. 01

    Identify security responsibilities across the sponsor, designers, delivery team and future operator.

  2. 02

    Plan the assessment, review and approval activities alongside the project programme.

  3. 03

    Record interfaces, document ownership and the process for managing changes.

Questions to work through

  • Who produces and reviews each security deliverable?
  • Where could responsibilities fall between teams?
  • How will changes reach the risk owner?
AN EXAMPLE IN PRACTICE

Before design develops, agree how the architect, technology contractor and facilities team will coordinate access control requirements and operational assumptions.

A common trap

A management plan needs named responsibilities and usable interfaces, not only a statement of policy.

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter