For the complete documentation index, see llms.txt. This page is also available as Markdown.

Scope, Source Basis and Maintenance

Purpose

This playbook is a tailored security, vetting, cyber resilience and technical assurance operating model for high-assurance UK public sector, defence, enterprise and regulated delivery.

It is intended to sit alongside the Company Operating Manual and the Agile Delivery Playbook. It does not replace customer policy, contract terms, accreditation authority instructions, MOD sponsor instructions, legal advice or current official guidance.

How This Playbook Is Used

  • use it when shaping bids and Statements of Work;

  • use it when onboarding people and suppliers;

  • use it when designing secure systems and services;

  • use it when preparing assurance, accreditation and customer evidence;

  • use it when defining RBAC, ABAC, vetting, data handling and operational controls;

  • use it when establishing cyber resilience and incident response arrangements.

Maintenance Rule

Security policy, defence policy and cyber guidance change. This playbook should be reviewed at least quarterly and whenever a customer, MOD sponsor, accreditor, regulator or contract introduces new requirements.

Source Basis

The public source basis used to shape this playbook includes:

Controlled or Customer-Specific Content

Some requirements, including project-specific defence policy, JSP content and accreditation authority instructions, may not be public or may only be accessible through a relevant sponsor. This playbook therefore defines an alignment and evidence approach rather than reproducing controlled material.

Interpretation Rule

Where this playbook conflicts with an executed contract, customer security schedule, project security instruction, accreditation authority decision or current official policy, the stricter or formally binding requirement must be followed and the conflict must be recorded.

Last updated

Was this helpful?