IT Security Project Management Handbook

This section of your project plan defines the risks to your project and the strategies you ll use to avoid or mitigate your risk. There are always risks with every project, and it s important to take time to identify those risks while you re calm, cool, and collected. There are some projects for which the risks outweigh the benefits and you decide, as a team or an organization, to not go down that path. Securing the infrastructure is not likely to fall into that category, but it s always important to keep this in mind that sometimes doing nothing is a better choice.
However, you ve decided to strengthen security on your network infrastructure and there are attendant risks. Let s look at one risk you might have, and you can then use this structure to develop additional risk and mitigation strategies. We ll use the following ranking system: 1 = Extremely high, 5 = Extremely low.
Risk: Improper configuration could completely disable network.
Criticality: 1
Likelihood of occurrence: 3
Relative risk ranking: 2
Mitigation strategy 1: Test all configurations in lab prior to rollout.
Risk of mitigation 1: Not all lab tests will completely mirror actual conditions.
Mitigation strategy 2: Develop fail-safe rollback plans for all critical configuration changes.
Risk of mitigation 2: Rollback will take time and set back project completion timelines.
Trigger 1: One week prior to scheduled configuration change.
Trigger 2: Forty-five minutes after network outage occurs.
Notes: All configuration changes will be tested in the lab first,...