What Are the Four Objectives of Planning for Security

What Are the Four Objectives of Planning for Security

The four objectives of planning for security are identify, design, test, and monitor. Follow them in order: spot what could go wrong, plan what to do, check that your measures work, and then keep watching over time.

The four objectives of planning for security

Here’s the study order to memorize:

  1. Identify security risks
  2. Design responses for those risks
  3. Test whether the security measures work
  4. Monitor security controls and changing risks

A key idea is that these objectives explain how to build and run a security plan. They are not the same as security “goals” such as keeping data secret or keeping systems running. We’ll sort out that difference next.

1. Identify security risks

Identify means you look closely and answer: *What could harm us?*

In security planning, you don’t start with tools or policies. You start with risks. A risk is a “could this cause trouble?” situation, such as a place an attacker could enter, a process that might fail, or a rule that isn’t being followed.

When you identify risks, you produce a list of problems you need to address. That list becomes the input for the next objective. Skip it, and you end up guessing. Guessing usually leads to security measures that don’t target the real threats.

Quick quiz-style distinction

  • Identify = spot and name the risks.
  • Design = decide what to do about those specific risks.

2. Design responses to identified risks

Once you know the risks, design means you plan the responses.

Here you choose the security approach for each risk. You turn the risk list into actions, such as controls, procedures, settings, or other measures that reduce the chance of harm or reduce the impact if something goes wrong.

For exams: design comes after identify. Your “design” work should connect directly to what you identified in step one.

Labeled connection

Labeled connection
  • Risks found in Identify → specific security responses planned in Design.

3. Test whether the security measures work

Test means you check effectiveness.

This objective asks: *Did our security measures do what we expected them to do?* Testing helps you catch gaps before a real attacker—or a real incident—shows that the measures aren’t strong enough.

Testing can confirm that security behavior matches the plan. It also helps you find mistakes in what you built or chose during the design step.

Why testing shows up on the exam

Because “we added security” isn’t the same as “security works.” The four objectives include testing so the plan doesn’t stay theoretical.

4. Monitor security controls and changing risks

After you test, you don’t just leave the plan in place. Monitor means you keep watching.

Security risks change. New vulnerabilities get discovered. Attack methods evolve. People shift roles and permissions. Systems get updated. Any of those changes can alter the risk picture.

So monitor means you track whether controls still work and whether the threat landscape has changed. If it has, you revisit the earlier objectives and adjust what you’re doing.

Simple way to remember monitor

  • Monitor = ongoing check, not a one-time event.

How these objectives differ from the four network security goals

Some questions get tricky because they mix up two different “four-part” frameworks.

The four objectives of security planning (the one you’re being asked about)

These are identify, design, test, monitor.

They describe the *process* of building and running a security plan.

A related network security framework (often shown as a different set of four)

A separate set you may see lists:

  • confidentiality
  • integrity
  • availability
  • performance

That framework describes security goals—what you’re trying to protect and how you want the system to behave.

#### Plain-English distinction

  • Planning objectives: how you manage security work (identify → design → test → monitor).
  • Network security goals: what you want from security (confidentiality/integrity/availability/performance).

So if your multiple-choice question is asking “objectives of planning”, the correct answer is the four process words. The network-security goals are a different set, even though they also use “four” categories.

How the answer appears in common quiz and multiple-choice questions

You’ll often see this question as multiple choice, such as:

  • “What are the four objectives of planning for security?”
  • “Which option matches the four-part security planning objectives?”

In those cases, the test is usually looking for this exact sequence:

  • identify
  • design
  • test
  • monitor

Why options like “be confident, be vigilant and be quick” don’t match

Some answer choices use security-sounding advice, but they don’t match the four planning objectives. The planning framework is about actions you take in order: spot risks, plan responses, check that they work, then keep watching.

So on a quiz:

  • habits / mindset / general advice → likely not the four planning objectives
  • process steps that match identify → design → test → monitor → likely correct

If you’re using a study set, lock in the four-word sequence: identify, design, test, monitor.

Related planning terms: strategic, tactical, and operational planning

Sometimes the same test sheet mentions planning levels too. These terms are related, but they’re not the same as the four security planning objectives.

Strategic planning

Strategic planning

Strategic planning sets long-term direction. It’s the bigger-picture level.

Tactical planning

Tactical planning focuses on shorter-term goals. It’s how you aim for the bigger picture.

Operational planning

Operational planning covers day-to-day work. It’s where tasks get organized, scheduled, and carried out.

Key point (don’t mix them up)

  • Security planning objectives = identify, design, test, monitor (the process).
  • Planning levels = strategic, tactical, operational (the time horizon and focus).

Also note this for your test prep: the material mentions strategic, tactical, and operational planning, but it doesn’t add a fourth planning level. Don’t force one in.

Before you pick an answer, check what the question is actually asking:

  • “four objectives of security planning” → identify/design/test/monitor
  • “types/levels of planning” → strategic/tactical/operational
DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.