An enterprise security risk assessment and treatment plan gave a large Commonwealth department an evidence-based view of its security risks and built internal capability to manage them.
THE CHALLENGE
A large Commonwealth department needed to show that its security posture met its obligations under the Protective Security Policy Framework (PSPF) and its own enterprise risk management policy. That required an enterprise-wide understanding of its security vulnerabilities across people, information and assets, including its portfolio entities. Senior leadership wanted a clear picture of the security risk landscape so that governance could be strengthened and security planning aligned with the department’s objectives. The department also wanted its own staff to be better equipped to manage security risk once the assessment was complete. Findings needed to reach the executive in a form that would support decisions.
OUR APPROACH
Agilient delivered an Enterprise Security Risk Assessment and a Security Risk Treatment Plan using a multi-phase, consultative method based on the PSPF and AS ISO 31000:2018. The engagement opened with discovery and stakeholder consultation to map the department’s operating context across personnel, information and physical security and governance arrangements, and to confirm alignment with its enterprise risk management policy. In the core assessment phase, Agilient completed an Asset Criticality Assessment to identify and prioritise the assets essential to the department’s functions, and a Threat Assessment analysing relevant threat actors, attack methods and plausible scenarios specific to its operating environment. Structured workshops and consultative sessions supported data gathering and were also used for informal knowledge transfer, building the department’s capability to manage security risk on an ongoing basis. Both deliverables were presented to the department’s executive team to support decisions at senior leadership level.
THE OUTCOME
The department now has an evidence-based view of its security risk and a practical plan for treating it.
- An Enterprise Security Risk Assessment evaluating the department’s security posture against PSPF requirements
- A prioritised Security Risk Treatment Plan with practical recommendations for risk mitigation, presented to the executive team
- Informal knowledge transfer through workshops, building internal capability for ongoing security risk management
Related services: protective security and PSPF consulting, the Protective Security Policy Framework (PSPF), security risk assessment consultants. Sector experience: government security consultant. To discuss a similar project, contact Agilient.