Security inputs & risk discovery
Create a defensible understanding of the system, attack surface, threats, and inherent risk.
PSLF-02G2Inputs and risk baseline approvedPhase 3 of 9
Gate
G2
Passed
Inputs and risk baseline approved
Decision date
24 Apr 2026
Baseline Design review baseline DRB-0007 (DRV-0001)
Open blockers
0
none at decision
Approvers
3
Priya Raman, Marcus Chen, Dr. Lena Fischer
Define testable requirements; model architecture, assets, trust boundaries, threats, hazards, and initial risk.
- Architecture and data-flow scope is complete.
- Every credible threat is linked to assets, harms, and an explainable risk decision.
- Approved PSMP
- Intended use and system requirements
- Architecture sources and safety-risk records
- 1Define product security and privacy requirements
- 2Normalize architecture and data flows
- 3Identify assets, trust boundaries, misuse cases, threat scenarios, hazardous situations, and security risks
- 4Establish inherent risk using the approved method
- 5Map requirements, risks, and planned controls
- Product Security and Privacy Requirements
- Product Security Risk Assessment
- Product Security Architecture Description
- Initial Product Security Requirements Traceability Matrix
- Requirements are clear, testable, uniquely identified, and approvedMet
- Threat and risk coverage is reviewedMet
- Critical and high risks have owners and treatment plansMet
- Architecture exceptions are dispositionedMet
- Accountable
- Security Architect accountable
- Supporting
- Engineering supplies design; Safety and Privacy review impacts
- Source (pending)
- Architecture element (pending)
- Asset (pending)
- Threat (pending)
- Harm (pending)
- Inherent risk (pending)
- Mapped-element coverage
- Orphan threats
- Risk decisions awaiting review