STAGE 15 / 16 · ACT 5 · Sustain

Review and improvement

Reconsider whether the security arrangements remain appropriate. Periodic reviews and event-driven reviews bring new threats, incidents, assurance findings and organisational changes back into risk decisions and improvement priorities.

What to do at this stage

  1. 01

    Bring together changes in context, incidents, assurance findings and treatment progress.

  2. 02

    Identify which assessments, controls or risk acceptances need reconsideration.

  3. 03

    Record decisions and follow through on agreed improvements.

Questions to work through

  • What has changed since the last decision?
  • Are the controls still appropriate for the current threats?
  • Which risk acceptances need to be renewed or revised?
AN EXAMPLE IN PRACTICE

A significant incident at a comparable facility may justify examining an assumption before the next scheduled annual review.

A common trap

A calendar review should not delay action when an event has already changed the risk picture.

When the work needs to return

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter