STAGE 06 / 16 · ACT 2 · Plan

Detailed security risk assessment

Develop the detailed security risk assessment around specific assets and scenarios. Examine existing controls and their effectiveness, document the evidence behind the ratings and identify findings that require a treatment decision.

What to do at this stage

  1. 01

    Describe each scenario clearly enough to identify its causes, event and consequences.

  2. 02

    Evaluate the controls that actually operate and record the basis for crediting them.

  3. 03

    Document the current risk, uncertainty and findings for the risk owner to consider.

Questions to work through

  • What could happen, and through which pathway?
  • Which controls are operating effectively?
  • What evidence would change this assessment?
AN EXAMPLE IN PRACTICE

For unauthorised access to a critical room, examine permissions, door behaviour, monitoring and response. A written access policy alone does not establish that these controls work.

A common trap

Treating planned controls as already effective can understate the current risk.

When the work needs to return

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter