Understand the context of what you are trying to deliver.
Make sure your risk appetite is defined and published.
Your security strategy sets the direction for a capability’s desired security posture.
Every capability must be registered on the Cyber Activity and Assurance Tracker (CAAT).
Know the skill sets needed for defining context and risk appetite.
Follow a Secure by Design (SbD) approach to embed security in investment approvals.
Security plans for achieving high-level goals.
A Security Working Group (SWG) for overseeing security practices and decision-making.
Define your system and security requirements.
Plan your approach to security using Defence Lines of Development.