1. Introduction
The SAFRA programme ensures that all securitysensitive projects are assessed for risk, monitored, and corrected throughout their lifecycle. The midterm report is a mandatory deliverable that provides stakeholders with a snapshot of project status, risk exposure, and mitigation actions after the initial implementation phase.
This page presents a readytouse template, explains each section, and offers tips for completing it efficiently.
2. Objectives of the MidTerm Report
- Confirm that the project remains aligned with the original business case and security requirements.
- Identify new or emerging risks that have surfaced since the inception phase.
- Demonstrate that mitigation measures are effective and, if not, propose corrective actions.
- Provide an evidence base for decisionmakers to approve continuation, modification, or termination of the project.
3. Template Overview
The template is divided into eight logical sections. Below is a brief description of each heading, followed by a full example layout.
| Section | Purpose |
|---|---|
| 1. Executive Summary | Highlevel synthesis for senior management. |
| 2. Project Overview | Scope, objectives, timeline, and governance. |
| 3. Risk Landscape | Current risk rating compared with baseline. |
| 4. Mitigation Status | Progress of each control implementation. |
| 5. Incident & Findings Log | Security events recorded during the period. |
| 6. Resource & Budget Review | Spend vs. plan and resource availability. |
| 7. Stakeholder Feedback | Key concerns and suggestions from reviewers. |
| 8. Recommendations & Next Steps | Action plan for the remainder of the project. |
4. Detailed Section Guidance
4.1 Executive Summary (150words)
Provide a concise narrative that answers:
- Is the project on track?
- What are the most critical risks?
- What actions are required from senior leadership?
4.2 Project Overview
Include a brief description, the original scope, start and planned end dates, major milestones, and the governance structure (project sponsor, steering committee, security officer).
4.3 Risk Landscape
Present a risk matrix that compares the baseline risk rating (from the initial SAFRA) with the current rating. Highlight any risk that has moved up a level and explain why.
4.4 Mitigation Status
For each identified control, list:
- Control ID and description.
- Planned implementation date.
- Actual status (Not Started, In Progress, Completed).
- Evidence of effectiveness (test results, audit findings, etc.).
- Issues or delays.
4.5 Incident & Findings Log
Summarise security incidents, audit findings, or penetrationtest results that occurred since the last report. Use a table with columns for date, description, impact, remediation status, and lessons learned.
4.6 Resource & Budget Review
Show a simple budget variance chart (planned vs. actual spend) and comment on any shortfalls, overruns, or staffing gaps that affect risk mitigation.
4.7 Stakeholder Feedback
Capture input from the steering committee, endusers, and the security reviewer. Summarise concerns and any agreedupon adjustments.
4.8 Recommendations & Next Steps
List concrete actions, owners, and target dates for the remaining project lifecycle. Prioritise items that address elevated risks.
5. Sample Template (HTML Form)
The following HTML skeleton can be copied into a document editor (Word, Google Docs, or a wiki) and filled in by the project team.
<!-- SAF RA MidTerm Report Template --><h1>MidTerm Report [Project Name]</h1><h2>1. Executive Summary</h2><p>[Brief overview 150 words]</p><h2>2. Project Overview</h2><ul> <li><strong>Scope:</strong> </li> <li><strong>Objectives:</strong> </li> <li><strong>Timeline:</strong> Start , Planned End </li> <li><strong>Governance:</strong> Sponsor , Security Officer </li></ul><h2>3. Risk Landscape</h2><table> <tr><th>Risk ID</th><th>Description</th><th>Baseline Rating</th><th>Current Rating</th><th>Change Reason</th></tr> <tr><td>R01</td><td></td><td>Medium</td><td>High</td><td>New vulnerability discovered</td></tr> </table><h2>4. Mitigation Status</h2><table> <tr><th>Control ID</th><th>Description</th><th>Planned Date</th><th>Status</th><th>Evidence</th><th>Issues</th></tr> <tr><td>C01</td><td>Encrypt data at rest</td><td>15Mar2026</td><td>Completed</td><td>Certificate audit</td><td>None</td></tr> </table><h2>5. Incident & Findings Log</h2><table> <tr><th>Date</th><th>Incident / Finding</th><th>Impact</th><th>Remediation Status</th><th>Lesson Learned</th></tr> <tr><td>02Apr2026</td><td>Phishing clickthrough</td><td>Low</td><td>User training scheduled</td><td>Need MFA reminder</td></tr> </table><h2>6. Resource & Budget Review</h2><p>Planned Budget: $XXXXX<br>Actual Spend: $XXXXX (Variance: X%)</p><h2>7. Stakeholder Feedback</h2><ul> <li>Steering Committee Increase staffing for monitoring</li> <li>End Users Performance impact of encryption is noticeable</li> </ul><h2>8. Recommendations & Next Steps</h2><ol> <li>Accelerate remediation of R01 Owner: Security Lead Target: 30Jun2026</li> <li>Conduct performance testing after encryption rollout Owner: Ops Team Target: 15Jul2026</li> </ol>
6. Best Practices for Completing the Report
- Use quantitative data wherever possible. Numbers (e.g., risk scores, % of controls implemented) make the assessment objective.
- Keep the executive summary jargonfree. Decisionmakers may not be technical.
- Link each recommendation to a specific risk. This ensures traceability.
- Update evidence links. Attach test reports, audit logs, or screenshots as annexes.
- Review with the security reviewer before submission. Early feedback avoids rework.
7. Additional Resources
For deeper guidance, consult the following documents:
8. Contact Information
If you have questions about the template or need assistance filling it out, please contact the SAFRA support team:
- Email: safra-support@example.com
- Phone: +18005550199
- Internal portal: SAFRA Knowledge Base
