Understand how capabilities might be attacked or fail.
Consider risks, including human error, social engineering, and the impact of organisational culture on security.
Define your system and security requirements.
A systems-engineering based approach to security.
Procedural, physical, or technical measures to avoid, detect, counteract or minimise security risks.