STAGE 13 / 16 · ACT 5 · Sustain

Operations

Operate the security controls and keep the supporting records current. Day-to-day activity generates evidence about incidents, access, maintenance and changes. Use that evidence to keep the view of current risk connected to what is happening.

What to do at this stage

  1. 01

    Run the agreed controls and maintain the registers needed for operational accountability.

  2. 02

    Record incidents, exceptions, maintenance and changes that may affect protection.

  3. 03

    Escalate emerging weaknesses or changes through the agreed review process.

Questions to work through

  • Are the controls being operated as intended?
  • What do recent incidents and exceptions reveal?
  • Are records current enough to support a decision?
AN EXAMPLE IN PRACTICE

Regularly reconcile access permissions with current roles and departures, and record exceptions so recurring weaknesses can be investigated.

A common trap

An unchanged risk register can conceal an operation whose people, assets or controls have changed substantially.

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter