What to do at this stage
- 01
Assess the security impact of the proposed change and the transition arrangements.
- 02
Address access, information, equipment and responsibilities that remain after closure or transfer.
- 03
Return to the context stage for a changed operation, or document the basis for closing the risk.
Questions to work through
- What exposure is created by the change itself?
- What information or access remains after disposal?
- Does the revised use require a new assessment context?
Closing a facility may require revoking credentials, transferring sensitive records and checking equipment for retained information before assets leave the site.
A common trap
A project ending does not automatically end its security responsibilities or information exposure.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
Traffic Light Protocol (TLP) Toolkit
Support clear expectations for sharing information.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.