Security LifeCycle
Understand
Section titled “Understand”Knighthood identifies the people, information, and assets that require protection, their importance to customers, health and safety needs, and the business impact of potential harm or loss. We consider how the facility will be used, who will use it, and what will be stored. We recognise any secure information or assets stored, and any other legal requirements. When sharing a space, we build this understanding together with other organisations.
Assess
Section titled “Assess”Knighthood assesses risks to people, information, and assets to identify security measures that reduce them to an acceptable level. We identify the threats and vulnerabilities relevant to the situation, analyse existing security measures, and assess the likelihood and impact of each risk to decide whether more action is needed. We also consider the combined security risk of co-located organisations.
Design
Section titled “Design”Knighthood designs security measures that match the identified risks and the customer’s risk tolerance. We build security requirements into the customer’s business continuity and disaster recovery plans.
Accept the security approach
Section titled “Accept the security approach”Knighthood presents the plan to the responsible executive, who must accept the proposed security design before it is implemented.
Implement
Section titled “Implement”Knighthood executes the agreed security measures — policies, processes, procedures, and technical security controls — and provides security awareness training for all staff and contractors.
Validate
Section titled “Validate”Knighthood confirms that the risk mitigations and security controls in the design can be implemented effectively and are fit for their intended use.
Go live
Section titled “Go live”Knighthood keeps customers secure by staying current with security threats and vulnerabilities and keeping security controls up to date. We provide ongoing security awareness training for staff and contractors.
Operate and maintain
Section titled “Operate and maintain”We identify and respond to security incidents or breaches as per our incident reporting process.
Review
Section titled “Review”We carry out regular reviews to keep security measures fit for purpose and to identify changes in the use of facilities, the organisation, or the threat environment that should inform improvements.
Retire
Section titled “Retire”When a building or facility is no longer needed, we consider the security implications of any information, assets, or chattels during decommissioning. We recommend items for secure destruction, redeployment, or disposal.
