STAGE 08 / 16 · ACT 3 · Deliver

Security design and procurement

Carry the agreed security requirements into design and procurement. Review drawings, specifications and contracts for traceability to the intended controls. Evaluate deviations and supplier dependencies before they become difficult to change.

What to do at this stage

  1. 01

    Trace design decisions and contract requirements back to the security requirements.

  2. 02

    Review proposed substitutions, interfaces and supplier assurance arrangements.

  3. 03

    Reassess risk where a deviation or value engineering proposal changes protection.

Questions to work through

  • Where is each requirement realised in the design?
  • What evidence must the supplier provide?
  • Does a cost reduction change the forecast residual risk?
AN EXAMPLE IN PRACTICE

A substitute door assembly may look equivalent but alter delay, emergency egress or integration with alarms. Review those consequences before accepting the change.

A common trap

A technically compliant component can still fail the overall protection concept if interfaces are overlooked.

When the work needs to return

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter