Implementing project life-cycle security is an integrated, iterative process that requires the involvement of the project team, security management personnel and risk management personnel. The nine-step process incudes steps to identify threats, consequences, and the risks to a project so the project team can develop strategies and actions to implement project life-cycle security. (IR-BMM-3, p. 9)
- Review phase checklist before phase start
- Develop activity risk matrix
- Identify security practices relevant to project phase
- Implement practices as appropriate
- Complete questionnaire and calculate phase SRI score
- Conduct periodic review
- Update phase SRI score
- Conduct post-phase implementation review
- Closeout phase SRI
Examples of key security considerations that are identified within the implementation process include the following three as part of Step 2:
- Identifying “threat levels” for the project based on five threat levels as defined by this research; very low, low, medium, high or very high as defined by this research.
- Assess the “consequence levels” of damages that may be expected if a security breach on an asset was successful based on five levels defined by this research; very low, low, medium, high, and very high.
- Create an “activity risk matrix” and measures to address the risk by each phase of the project.