Secure development lifecycle

Security throughout the delivery lifecycle

Security is a series of decisions made from discovery through operation—not a final check added immediately before launch.

The lifecycle

Six stages, scaled to the requirement

01

Discover

Define outcomes, users, workflows, information, integrations and constraints.

02

Assess risk

Consider misuse, access risks, sensitive information and failure scenarios.

03

Design

Document architecture, trust boundaries, identity, data handling and monitoring.

04

Build

Use controlled environments, reviews and secure configuration handling.

05

Verify

Test functions, permissions, error handling, logging and recovery expectations.

06

Operate

Monitor, manage changes, respond to issues and improve controls.

Possible lifecycle outputs

  • Requirements and risk record
  • Threat and misuse scenarios
  • Architecture and access model
  • Verification plan
  • Operational handover information
  • Prioritised improvement backlog

Proportionate by design

Activities should be scaled to the size, sensitivity, complexity and risk of each engagement.

Discuss your delivery lifecycle

Identify where security decisions or ownership need to become clearer.

Start an enquiry