Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Working Security — the method

This repository holds the method for building working security — the emphasis on working, and on resilience. The method is about making security work in organisations of any size and stage — not about prescribing treatments for specific security domains, methodologies, or tools. What it offers is the structure that keeps security work moving in the right direction.

What the method gives you

  • Planning horizons that connect long-term direction to daily execution
  • A scoping discipline that sizes security work to the gap between the risk you carry and the risk you'll accept
  • Delegation with context — security ownership distributed across the organisation, with the time, tools, and context to carry it
  • Finishing work — cycles with hard ends and evidence as a byproduct, even as the targets keep moving

One loop runs through all of it: clarity, feedback, proportionality. Working security compressed into a single sentence sounds something like this: connect your entities, distribute the work, invest proportionately, prove it continuously. The guides here unpack it.

The guides

  1. Core Principles — resilience over prevention, and the loop the method runs on
  2. Planning Horizons — security work at four time scales, connected by the regular reviews
  3. Scoping Security Work — turning changes, planned or forced by events, into briefs a team can deliver
  4. Delegation with Context — the four groups that share security ownership, and what real ownership takes

Read the book first if you want — it's free and published in the open. If you're already convinced, start with Core Principles. If you want to organise your security work today, go straight to Planning Horizons.

Each guide covers three sizes of organisation: startup (5–50 people), scale-up (50–500), enterprise (500+). The examples in the guides are illustrations, not case studies. Case studies are very welcome — CONTRIBUTING describes how.

Contributing

The method is open on purpose. Use it, improve it, disagree with it: open an issue or a pull request. Worked examples from real programmes are worth more than any other contribution.

Influences

The cycle discipline echoes the agile tradition. The decision mechanics come from risk management practice: tolerance, briefs, regular reviews.

License

CC BY 4.0. Use it, adapt it, build on it, with attribution.

About

No description, website, or topics provided.

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors