Critical infrastructure projects need a clear scope, defined responsibilities and careful handling of operational information. Use this guide to prepare a high-level brief with the asset owner and responsible specialists.
Define assets and operating constraints
Identify the property areas, equipment and business functions within the proposed scope. Describe the consequences of interruption and the work windows available. Keep sensitive layouts, configurations and detailed protective procedures within approved channels.
Separate detection from response
For each event of concern, specify what should be detected, what evidence should be available and who evaluates it. Clarify how alarms, video, access records and system-health information support the operator. Do not assume that an alert establishes the nature of an event.
Document dependencies and acceptance
Inventory existing equipment, network responsibilities, power and communications. Ask the project team to identify environmental requirements and relevant review obligations. Define agreed fault scenarios, maintenance access, training and documentation before equipment is selected.
Questions for your project brief
- Who approves design, network access and operating changes?
- What functions must remain available during work?
- How will failure and recovery behavior be demonstrated?
- Who maintains accounts, configurations and support records?
Contractor coordination and field delivery
Critical infrastructure projects need tightly controlled scope, change management, and information handling. Define the approved access process, asset owner, outage windows, and escalation contacts. Do not assume a security subcontractor controls operational technology networks or may change an existing integration without owner authorization.
Use a responsibility matrix to separate design, material supply, cable installation, mounting, configuration, testing, and closeout. Ask bidders to list access assumptions, exclusions, dependencies on other trades, and the process for documenting changes. Require an agreed test record and deficiency list before accepting the subcontracted work.
Where NERSA capabilities fit
NERSA’s commercial and industrial capability areas include video surveillance, access control, intrusion alarms, monitoring, and integrated systems. Use its service overview to identify the relevant work package, then confirm the exact subcontractor role, geographic coverage, qualifications, and scheduling for your project. The project scope should state who supplies equipment and who owns configuration, testing, and support.
Related resources
Use the planning resource directory and security planning glossary to organize follow-up questions. For property-specific service information, continue to the relevant NERSA resource.
