Operations and lifecycle
These pages cover the work after development: inventory, commissioning, monitoring, updates, recovery and retirement. Assign an owner for each operating task.
On this page
Overview#
Secure protocol engineering continues after integration code ships. Versions, certificates, time, storage, vendor services, permissions, network paths, physical dependencies, and support status change throughout the deployment.
Procedures involving doors, gates, alarms, elevators, fire interfaces, emergency communications, relays, or occupied sites require product specific instructions, qualified personnel, system owner approval, and the applicable local authority.
Lifecycle pages#
| Page | Outcome |
|---|---|
| Requirements and procurement | Testable protocol, security, support, and evidence requirements |
| Site survey and design records | Complete topology, dependency, capacity, and boundary inputs |
| Commissioning and acceptance | Controlled transition from delivery to service |
| Asset and configuration inventory | Version specific source of operational truth |
| Change, firmware, and patching | Risk aware change and recovery workflow |
| Certificate and account lifecycle | Prevent expiry, orphaning, and shared access |
| Monitoring and health | Detect loss of security function and degraded evidence |
| Incident response and evidence | Contain cyber risk without creating unsafe physical effects |
| Decommissioning and disposal | Remove trust, data, access, and vendor ownership |
| Operational runbooks | Decision trees for common failures |
Operating record#
Every system should have named sources of truth for inventory, topology, approved flows, configuration baseline, account/role model, certificates and trust anchors, protocol/profile versions, vendor support, backup/recovery, monitoring, and unresolved risks. Those records must use exact model and version identifiers.
Sources#
- NIST 800 82, NIST SP 800-82 Rev. 3, operational technology lifecycle guidance, accessed 25 August 2026.
- NIST CSF, NIST Cybersecurity Framework 2.0, accessed 25 August 2026.