SECURITY AND CONTINUITY

Resilience is a design decision.

Security is a property of how a system is built and operated. It is assessed against the organisation’s actual exposure and obligations, and specified as controls with owners rather than as products.

Capability

Resilience is a design decision.

Exposure Assessment

What the organisation holds, who would want it, and how it could be reached, established before controls are selected.

Identity and Access

Authentication, privilege and joiner-mover-leaver process, which is where most practical exposure sits.

Continuity

Backup, restoration and the tested time to recover. An untested backup is an assumption.

Incident Response

Roles, decision authority, communication and regulatory notification agreed before an incident, not during one.

Third Parties

Supplier and platform dependencies assessed, since exposure follows integration.

Assurance

Testing and review at a cadence proportionate to the exposure and the obligations that apply.

What a credible initiative brief includes
  • The decision or process to be improved
  • Who uses the system and how often
  • Existing systems and data sources
  • Constraints: regulatory, security, residency
  • Success measure
  • Budget envelope
  • Decision timetable
DISCLAIMER

Technology descriptions represent areas of capability and development interest. Availability, ownership, licensing and delivery model depend on the specific solution and may involve third-party platforms, developers and specialist partners.

Start from the decision.

The right system follows the requirement, rarely the other way.