Preparing a secure service

Activity Delivery phase
Considering security within the business case (Opens in new tab) Discovery Alpha Private beta Public beta and live
Identifying security resources (Opens in new tab) Discovery Alpha Private beta
Agreeing roles and responsibilities (Opens in new tab) Discovery Alpha Private beta
Tracking Secure by Design progress Discovery Alpha Private beta Public beta and live
Working out the project's security risk appetite (Opens in new tab) Discovery Alpha

Understanding the security landscape

Activity Delivery phase
Managing third-party product security risks (Opens in new tab) Discovery
Understanding cyber security obligations (Opens in new tab) Discovery
Understanding business objectives and user needs (Opens in new tab) Discovery

Managing cyber security risks

Activity Delivery phase
Documenting service assets (Opens in new tab) Discovery Alpha Private beta
Assessing the importance of service assets (Opens in new tab) Discovery Alpha Private beta
Sourcing a threat assessment (Opens in new tab) Discovery Alpha
Performing threat modelling (Opens in new tab) Alpha Private beta
Performing a security risk assessment (Opens in new tab) Alpha Private beta
Agreeing a security controls set for your service (Opens in new tab) Alpha Private beta
Responding to and mitigating security risks (Opens in new tab) Alpha Private beta Public beta and live
Assessing the effectiveness of security controls (Opens in new tab) Alpha Private beta Public beta and live

Anticipating and responding to incidents

Activity Delivery phase
Implementing a vulnerability management process (Opens in new tab) Alpha Private beta
Discovering vulnerabilities (Opens in new tab) Alpha Private beta Public beta and live
Managing observability (Opens in new tab) Alpha Private beta

Maintaining continuous assurance

Activity Delivery phase
Evaluating the security impact of changes (Opens in new tab) Alpha Private beta Public beta and live
Retiring service components securely (Opens in new tab) Alpha Private beta Public beta and live