Security Design Process

Design before Technology

The Security Design Process describes the structured approach used to transform business objectives into a complete engineering design.

Each stage builds upon the previous one. Decisions made during assessment influence the performance specification. The performance specification shapes the system architecture. The architecture informs the detailed engineering design. Finally, the completed system is validated against the original operational requirements before entering operational service and continuing through its lifecycle.

By following a consistent design process, security systems become easier to justify, easier to procure and more likely to deliver the operational outcomes they were intended to achieve.

The Six Phases

The methodology is organised into six distinct phases. Each phase has a defined purpose, set of deliverables and outputs that provide the inputs to the next stage of the design process.

  • Understand
  • Assess
  • Define
  • Design
  • Assure
  • Lifecycle Management

1. Understand

Develop a clear understanding of the organisation, its objectives, critical assets and the operational outcomes the security system is intended to achieve.

  • Business Objectives
  • Stakeholder Engagement
  • Operational Requirements
  • Critical Assets
  • Constraints & Assumptions

2. Assess

Identify threats, evaluate risks and determine the level of security required to protect the organisation and support its operational objectives.

  • Threat Assessment
  • Risk Assessment
  • Vulnerability Assessment
  • Risk Prioritisation
  • Residual Risk

3. Define

Translate operational and security requirements into measurable performance criteria that can be designed, procured and validated.

  • Performance Requirements
  • Functional Requirements
  • Non-functional Requirements
  • Acceptance Criteria
  • Success Measures

4. Design

Develop both the overall system architecture and the detailed engineering documentation required to deliver the specified performance.

  • High Level Design (HLD)
  • Low Level Design (LLD)
  • Technology Selection
  • Integration Strategy
  • Engineering Documentation

5. Assure

Verify that the completed solution satisfies the operational requirements and performs as intended before it enters service.

  • Factory Acceptance Testing (FAT)
  • Site Acceptance Testing (SAT)
  • Operational Validation
  • User Acceptance
  • Handover Documentation

6. Lifecycle Management

Maintain, review and continually improve the security system to ensure it continues to meet operational needs throughout its service life.

  • Preventive Maintenance
  • Performance Reviews
  • Technology Refresh
  • Change Management
  • Continuous Improvement

Related Resources

Continue your learning with: