The security situation picture

The basis for decisions

A security situation picture is a qualitative, quantitative and/or visual presentation and analysis of security-relevant matters for the organisation, produced continuously. It covers the collection, assessment, documentation and presentation of relevant information on the current security position, including potential threats, risks and incidents that have already occurred.

The purpose of the security situation picture is to identify potential threats and create transparency about them. This enables the organisation's management to take informed decisions in line with the organisation's objectives. Scope, form and delivery always follow the information needs of the respective recipients. This lesson is based on Section 6 of DIN SPEC 14027.

Your learning objectives

  • You can describe the situation picture process in five phases.
  • You can distinguish internal from external information sources.
  • You know when a monitoring system should be established and when it is mandatory.
  • You know the typical situation products and the requirements for reporting.

The process in five phases

Producing a security situation picture requires all five phases to be completed. Their intensity, scope and depth may be adapted to the individual requirements of the organisation or to the protection level of individual assets. The following learning cards give you a quick overview of the five phases.

Key terms from practice:

Phase 1: Requirement definition
The organisation's management ensures that information requirements are stated and needs are determined. It is set out who needs which information, in which form, when and for what purpose. The need can be temporary or continuous.
Phase 2: Information gathering
Systematic and ongoing gathering of information, both inside and outside the organisation. Where required, an external service provider may be consulted.
Phase 3: Assessment
The potential threat to the organisation is the focus. Assessment along the five Ws (who, what, where, when, why), a forecast where required, and an assessment of the impact on the organisation and its assets.
Phase 4: Situation products
Results are brought together as a single product in a suitable, ideally pre-agreed format and made available to stakeholders, for example as a weekly situation report or a quarterly threat catalogue.
Phase 5: Evaluation & feedback
Continuous evaluation and feedback to improve the processes and the quality of the products. This also includes distributing information to other parts of the organisation.

Deep dive:

The following sections explore the essential building blocks of the security situation picture in more depth, with reference to the requirement catalogues of DIN SPEC 14027 (Section 6 and Table A.1).

The process in five phases
All five phases – requirement definition, information gathering, assessment, production of situation products, and evaluation and feedback – have to be completed. How they are designed remains flexible, however: cadence, intervals and depth are adapted to the organisation's information needs. Overall accountability lies with top management; a function responsible for the security situation picture is to be named and equipped with the necessary competencies (Annex A, nos. 1.1–1.6).
Information gathering: internal and external sources
External sources can be opened up through partner organisations, personal networks, service providers, public authorities and openly available sources (media and the like). Internal sources come from employees and internal systems. Particular attention goes to anomalous behaviour and criminal acts, from digital attacks in IT and cyber security through to physical attacks on facilities or people. Employees must be able to report incidents to a central reporting point without delay; internal reports must not have negative consequences for the person reporting.
Monitoring system: recommended and mandatory requirements
Where the protection need is low or medium (levels C and D), an internal monitoring system for continuous threat and incident detection SHOULD be established. Where the protection need is elevated or high (levels A and B), such a system is MANDATORY and MUST be established. The monitoring process covers at least: receiving reports, observing developments, assessing and classifying relevant incidents, producing outputs, and handing over to the responsible bodies. The aim is to recognise potential damage early and initiate countermeasures.
Situation products and reporting
Typical situation products are the weekly situation report and the quarterly threat catalogue. They bring all the gathered information together into a current situation picture and are made available in a form suited to the target group. Reporting requires events and reports to be recorded systematically. Top management is informed at regular intervals and whenever the need arises, and promptly where the protection need is high. Findings feed into the protection needs assessment, and changed protection needs are communicated to the bodies concerned.

The key points in brief

The security situation picture is the central instrument for making threats to the organisation transparent and enabling well-founded decisions. It is produced in a five-stage process, from requirement definition through information gathering and assessment to situation products and evaluation.

  • Information sources are both internal (employees, systems) and external (authorities, service providers, open sources).
  • A monitoring system is recommended where the protection need is low and mandatory where it is elevated or high.
  • Situation products such as situation reports and threat catalogues support decision-making; reporting to top management takes place regularly.
  • The security situation picture has interfaces with site security, travel security, know-how protection, crisis management and the protection needs assessment.

Looking ahead

The next lesson turns to the central fields of action: site security (Section 11). You will get to know the zone model (onion principle), access control management (ACMS), structural hardening and security of supply.