- decide what the PSC's role & involvement should be - write prescriptive checklist that can be followed by subproject owners without incident response experience - decide how vulnerabilities are communicated