Every major project makes security decisions. Most make them implicitly.
Supplier selection determines what authentication the organisation lives with for a decade. Architecture choices set network boundaries. Data flow decisions create compliance obligations before anyone consults the compliance team.
The pattern is consistent across industries. An ERP replacement, a manufacturing system upgrade, a CRM rollout. Months in, someone raises authentication or network segmentation. Retrofitting costs more and produces weaker outcomes than building it in from the start.
Security is a dedicated project activity. The system security concept, aligned to buy-build-run phases, makes this explicit: specific requirements in buy, design baseline in build, operational handover in run.
Project steering is accountable for ensuring a delivery that can be securely operated. The security concept is how they verify that.
https://sten.eikrem.org/blog/security-concepts-in-major-projects
#InfoSec #SecurityGovernance #ProjectManagement #CyberSecurity



