Insights / Cybersecurity

Security throughout the delivery lifecycle

Connecting architecture, deployment and operations through clear responsibilities.

Make responsibility visible

NIST’s Cybersecurity Framework 2.0 organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond and Recover. The addition of Govern gives explicit attention to how cybersecurity decisions connect with organizational responsibilities and risk management.

Connect design with operation

For a technology program, security responsibilities should remain visible across design, deployment and ongoing operation. Architecture decisions affect monitoring. Access arrangements affect support. Recovery requirements affect infrastructure and service planning.

Use the handover to close gaps

A handover should clarify who owns the system, who operates it and how issues are escalated. The relevant documentation, monitoring arrangements and response processes need to be understandable to the people who will use them. These operational details influence how a design performs after deployment.

Delivery perspective

Security is easier to sustain when it is considered within the complete delivery lifecycle. The practical objective is to connect technical controls, system knowledge and operational ownership. A framework can structure that conversation; it does not, by itself, demonstrate that a particular system is secure or compliant.

Reference
NIST: Cybersecurity Framework 2.0

The delivery perspective is original editorial interpretation informed by the cited reference.

All insights →