What to do at this stage
- 01
Identify security responsibilities across the sponsor, designers, delivery team and future operator.
- 02
Plan the assessment, review and approval activities alongside the project programme.
- 03
Record interfaces, document ownership and the process for managing changes.
Questions to work through
- Who produces and reviews each security deliverable?
- Where could responsibilities fall between teams?
- How will changes reach the risk owner?
Before design develops, agree how the architect, technology contractor and facilities team will coordinate access control requirements and operational assumptions.
A common trap
A management plan needs named responsibilities and usable interfaces, not only a statement of policy.
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
Outline Security Plan — Template 13.5
Use an outline to organise the content of a security plan.
View in the SRMBOK shopSecurity Risk Management Policy Template
Set out the organisation’s approach to managing security risk.
View in the SRMBOK shopSRMBOK Guide to OSCAL
Understand OSCAL, its control models, limitations and questions to ask before investing in compliance automation.
View in the SRMBOK shopFive Cybersecurity Strategies for Boards and Executives
A short guide for boards and executives on cyber risk priorities and organisational resilience.
View in the SRMBOK shopSRMBOK Procedure Template
Document consistent operational procedures, responsibilities and step-by-step instructions in an editable template.
View in the SRMBOK shopSRMBOK Guide to Management Systems
Guidance on designing, implementing and maintaining a security risk management system.
View in the SRMBOK shopSRMBOK Process Flow One-Page Template
Create an editable one-page process flow in Excel, using swimlanes to show actions and accountabilities.
View in the SRMBOK shopSRMBOK Information Security Policy Template
Adapt an information security policy to define responsibilities and expectations for protecting information assets.
View in the SRMBOK shopTraffic Light Protocol and Controlled Information Sharing
A handbook on controlled information sharing, including sharing decisions, policy language and handling violations.
View in the SRMBOK shopSRMBOK BCM Policy
An example business continuity policy covering responsibilities, critical processes and recovery priorities.
View in the SRMBOK shopSRMBOK SRM Framework Project Plan Template
An editable project plan for initiating and managing the development of a security risk management framework.
View in the SRMBOK shopSRMBOK BCM Framework Template
Adapt a business continuity management framework to organise prevention, continuity and recovery planning.
View in the SRMBOK shopSRMBOK Guide to Governance
Guidance on integrating security risk management into governance, accountability and organisational decision-making.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.