STAGE 16 / 16 · ACT 5 · Sustain

Change, decommissioning and disposal

Treat a change of use, upgrade, decommissioning or disposal as a security risk decision. Identify what changes, what remains and what must be protected during the transition. Where an operation continues in a new form, revisit the context.

What to do at this stage

  1. 01

    Assess the security impact of the proposed change and the transition arrangements.

  2. 02

    Address access, information, equipment and responsibilities that remain after closure or transfer.

  3. 03

    Return to the context stage for a changed operation, or document the basis for closing the risk.

Questions to work through

  • What exposure is created by the change itself?
  • What information or access remains after disposal?
  • Does the revised use require a new assessment context?
AN EXAMPLE IN PRACTICE

Closing a facility may require revoking credentials, transferring sensitive records and checking equipment for retained information before assets leave the site.

A common trap

A project ending does not automatically end its security responsibilities or information exposure.

When the work needs to return

Suggested resources

Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.

Keep the whole life cycle in view

These practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.

KEEP BUILDING YOUR PRACTICE

A useful next step, in your inbox.

New SRMBOK resources and practical security risk management guidance.

Free to join. Sign up on SRMBOK. Unsubscribe any time.
Join the free newsletter