Perform operational risk analysis
Evaluate security risk in the actual deployment and operating context before release and whenever material conditions change.
Example: Evaluate security risk in the actual deployment and operating context before release and whenever material conditions change.
Counterexample: Assess the production risk decision only against development assumptions and omit production scale, data, privilege, dependency, and threat differences. | Require preproduction to be identical to live systems even when this creates uncontrolled data and dependency risk. | Leave cross-system responsibility for the production risk decision divided among teams without a named owner.
Limitations: The current plan reuses a development assumption in production without reassessing exposure, ownership, or applicable obligations.
Tradeoffs: Evaluate security risk in the actual deployment and operating context before release and whenever material conditions change.