Business Requirement Documents (BRD)

A document that compiles the full set of business requirements for a specific project and establishes the agreed scope of what must be delivered.

Key Points

  • Lists all agreed business requirements, both functional and nonfunctional, with clear acceptance criteria.
  • Acts as a scope baseline and supports traceability and change control throughout the project.
  • Developed with business stakeholders and approved to confirm shared understanding and commitment.
  • In agile or hybrid work, the BRD may be represented by a prioritized backlog of user stories and criteria.

Example

On an e-commerce upgrade, the team produces a BRD that includes requirements such as enabling guest checkout, supporting two payment providers, page load under 2 seconds for 95 percent of users, and order confirmation emails within 1 minute. When a stakeholder requests adding a new loyalty feature mid-project, the change is evaluated against the BRD to assess scope, impact, and priority.

PMP Example Question

Which artifact provides the complete, approved set of business needs used to baseline scope and guide acceptance testing?

  1. Project charter
  2. Business Requirement Documents (BRD)
  3. Work breakdown structure (WBS)
  4. Risk register

Correct Answer: B — Business Requirement Documents (BRD)

Explanation: The BRD consolidates all business requirements and acceptance criteria. The charter authorizes the project, the WBS decomposes scope, and the risk register lists risks.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build complete project plans in minutes with AI

Stop spending hours on documentation. Learn how to use AI to create charters, WBS, schedules, risk registers, and executive reports faster—while staying fully in control. This course gives you ready-to-use prompt templates and practical workflows based on real project work. No guesswork, no fluff—just tools you can apply immediately. Backed by Udemy’s 30-day money-back guarantee, so you can start risk-free.

Learn More