Rolling Wave Planning

A progressive, iterative planning approach where near-term work is broken down and scheduled in detail, while activities further in the future remain at a higher-level outline until they get closer to execution.

Key Points

  • Detail what will be done soon; keep distant work at a high-level until more is known.
  • Embodies progressive elaboration of scope, schedule, and estimates as information improves.
  • Uses regular planning checkpoints to expand future work packages into detailed tasks.
  • Balances uncertainty by preserving an overall roadmap while refining details just in time.

Example

On a 12-month facilities upgrade, the team fully decomposes and schedules the first two months of demolition and cabling. Later phases like commissioning and handover stay as high-level work packages with rough estimates. Each month, the next "wave" of work is elaborated in detail and added to the schedule and WBS.

PMP Example Question

A project manager creates a detailed task breakdown and estimates for the next eight weeks, while leaving work planned for later quarters as high-level packages with rough order of magnitude estimates. What technique is being used?

  1. Rolling wave planning
  2. Parametric estimating
  3. Crashing
  4. Scope validation

Correct Answer: A — Rolling wave planning

Explanation: The scenario describes planning near-term work in detail and keeping future work at a higher level until it is closer, which is the essence of rolling wave planning.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course