Design before Technology
The Security Design Process describes the structured approach used to transform business objectives into a complete engineering design.
Each stage builds upon the previous one. Decisions made during assessment influence the performance specification. The performance specification shapes the system architecture. The architecture informs the detailed engineering design. Finally, the completed system is validated against the original operational requirements before entering operational service and continuing through its lifecycle.
By following a consistent design process, security systems become easier to justify, easier to procure and more likely to deliver the operational outcomes they were intended to achieve.
The Six Phases
The methodology is organised into six distinct phases. Each phase has a defined purpose, set of deliverables and outputs that provide the inputs to the next stage of the design process.
- Understand
- Assess
- Define
- Design
- Assure
- Lifecycle Management

1. Understand
Develop a clear understanding of the organisation, its objectives, critical assets and the operational outcomes the security system is intended to achieve.
- Business Objectives
- Stakeholder Engagement
- Operational Requirements
- Critical Assets
- Constraints & Assumptions
2. Assess
Identify threats, evaluate risks and determine the level of security required to protect the organisation and support its operational objectives.
- Threat Assessment
- Risk Assessment
- Vulnerability Assessment
- Risk Prioritisation
- Residual Risk
3. Define
Translate operational and security requirements into measurable performance criteria that can be designed, procured and validated.
- Performance Requirements
- Functional Requirements
- Non-functional Requirements
- Acceptance Criteria
- Success Measures
4. Design
Develop both the overall system architecture and the detailed engineering documentation required to deliver the specified performance.
- High Level Design (HLD)
- Low Level Design (LLD)
- Technology Selection
- Integration Strategy
- Engineering Documentation
5. Assure
Verify that the completed solution satisfies the operational requirements and performs as intended before it enters service.
- Factory Acceptance Testing (FAT)
- Site Acceptance Testing (SAT)
- Operational Validation
- User Acceptance
- Handover Documentation
6. Lifecycle Management
Maintain, review and continually improve the security system to ensure it continues to meet operational needs throughout its service life.
- Preventive Maintenance
- Performance Reviews
- Technology Refresh
- Change Management
- Continuous Improvement
Related Resources
Continue your learning with:
- Knowledge Base: Core engineering concepts and terminology.
- Technology Guides: Vendor-neutral explanations of security technologies.
- Design Guides: Practical guidance for individual security disciplines.
- Free Engineering Tools: Calculators and design aids that support the design process.
