Skip to content

Security LifeCycle

Knighthood identifies the people, information, and assets that require protection, their importance to customers, health and safety needs, and the business impact of potential harm or loss. We consider how the facility will be used, who will use it, and what will be stored. We recognise any secure information or assets stored, and any other legal requirements. When sharing a space, we build this understanding together with other organisations.

Knighthood assesses risks to people, information, and assets to identify security measures that reduce them to an acceptable level. We identify the threats and vulnerabilities relevant to the situation, analyse existing security measures, and assess the likelihood and impact of each risk to decide whether more action is needed. We also consider the combined security risk of co-located organisations.

Knighthood designs security measures that match the identified risks and the customer’s risk tolerance. We build security requirements into the customer’s business continuity and disaster recovery plans.

Knighthood presents the plan to the responsible executive, who must accept the proposed security design before it is implemented.

Knighthood executes the agreed security measures — policies, processes, procedures, and technical security controls — and provides security awareness training for all staff and contractors.

Knighthood confirms that the risk mitigations and security controls in the design can be implemented effectively and are fit for their intended use.

Knighthood keeps customers secure by staying current with security threats and vulnerabilities and keeping security controls up to date. We provide ongoing security awareness training for staff and contractors.

We identify and respond to security incidents or breaches as per our incident reporting process.

We carry out regular reviews to keep security measures fit for purpose and to identify changes in the use of facilities, the organisation, or the threat environment that should inform improvements.

When a building or facility is no longer needed, we consider the security implications of any information, assets, or chattels during decommissioning. We recommend items for secure destruction, redeployment, or disposal.