Security planning
Turn applicable obligations into a funded, scheduled, and accountable security plan.
PSLF-01G1Plan approvedPhase 2 of 9
Gate
G1
Passed
Plan approved
Decision date
13 Feb 2026
Baseline PSMP-0042 v1.0
Open blockers
0
none at decision
Approvers
3
Dana Whitfield, Marcus Chen, Elena Vasquez
Establish strategy, owners, milestones, methods, tools, suppliers, and evidence plan.
- Every required activity has an owner, milestone, and evidence expectation.
- Independent review and supplier responsibilities are planned.
- Approved PSAA and FAR
- Program schedule
- Quality and software plans
- 1Define security objectives, roles, competence, independence, tools, supplier responsibilities, and review cadence
- 2Select risk method, threat-model method, security test strategy, evidence retention, incident preparation, and customer documentation
- 3Plan cybersecurity activities through retirement
- Product Security Management Plan
- Responsibility and Approval Matrix (RAM)
- Security milestone and evidence plan
- PSMP approved by Product Owner, Security Lead, Quality, and Regulatory as applicableMet
- Resource and competence gaps resolvedMet
- Gate dates and acceptance authorities namedMet
- Accountable
- Security Lead accountable
- Supporting
- Product Owner approves resources; Quality assures process
- Profile (pending)
- Obligation (pending)
- Plan activity (pending)
- Role (pending)
- Milestone (pending)
- Planned evidence (pending)
- Planned obligations with owners
- Competency and independence coverage