Central fields of action

Site security

Having covered the fundamentals, the protection needs assessment and the security situation picture, we now turn to one of the most important practical fields of action in corporate security: site security (Section 11 of DIN SPEC 14027).

In the context of corporate security, site security covers all measures that serve to protect a defined site – a company site, a building, a piece of critical infrastructure or a facility, for example – against threats within the meaning of the all-hazards approach, and thereby to secure the organisation's protection objectives.

Your learning objectives

After this lesson you will be able to:

  • explain the zone model (onion principle) and its layers of protection,
  • describe the requirements for access control management (ACMS),
  • judge when structural hardening is required by the standard,
  • name the critical components of security of supply.

From the protection need to the measure

A central principle of DIN SPEC 14027 is that all site security measures are derived from an object-specific risk assessment and from the protection needs assessment. There is no off-the-shelf security: every measure has to match the security level identified (A = very high to D = low).

Site security measures comprise a coordinated mix of structural, technical, organisational and personnel protective measures. They make sense for every organisation in principle, but they become indispensable where an organisation operates critical infrastructure, processes highly sensitive data, stores valuable goods, occupies an exposed location or is subject to statutory requirements.

The four pillars of site security

DIN SPEC 14027 divides site security into several core areas. The central requirements include perimeter protection and the zone model, access control management, structural hardening and security of supply. These areas interlock and together yield a coherent protection concept for any site.

The following section explores these fields of action in more depth, with reference to the respective requirements of the DIN SPEC.

Deep dive

The following sections explore the four pillars of site security in more depth.

Perimeter protection and the zone model (Section 11)
Protection begins at the property line. Unless business operations require public access, properties are to be fenced so that a legally unambiguous property boundary is visible. Depending on the protection objective, boundary or security fencing, anti-burrowing protection, vehicle barrier systems and measures in the outer protection area (no-stopping zones, traffic-directing signage) are added. The core element is the zone model based on the onion principle: rooms and areas with a similar need for protection are grouped into security zones, with the values most worth protecting ideally enclosed by zones with a lower protection need. This is supplemented by lighting, detection (intruder alarm systems) and, where required, video surveillance systems (VSS/CCTV), taking data protection and employment law aspects into account.
Access control management (ACMS)
An area owner is to be named for every physical area, carrying responsibility for access and supervision (the right of access). Personalised locking media and identification tokens (keys, access cards) are issued, documented and regularly audited or inventoried. Access rights must be managed in an audit-proof manner and reviewed regularly; temporary rights are to be withdrawn once they expire. Visitors and external parties must be unmistakably identifiable as such and are accompanied at all times, at least in critical areas. Also important are governed processes for onboarding, offboarding and internal moves, along with rules on bringing items in and out.
Structural hardening
On the basis of the risk assessment, it must be ensured that buildings and areas worth protecting have appropriate structural hardening. As a rule, resistance classes should be chosen that exceed the site-specific intervention time where one applies; the structural barrier therefore has to hold until intervention forces arrive. Locking systems (mechanical, electronic or combined) are to be selected according to their purpose and the protection need; for electronic systems, the fail-safe direction (open or closed) has to be defined. In addition, single-person access systems, control areas and protection against being observed or overheard may be required.
Security of supply
Critical systems and their requirements are to be prioritised and categorised in order to ensure uninterrupted supply. The critical components comprise: the electrical power supply (UPS, emergency power systems, redundant supply routes, for example), the thermal energy supply (self-sufficient heating and cooling for rooms essential to operations), lighting during a power failure (safety and standby lighting), the availability of materials and operating supplies, securing the ability to communicate and, where needed, food supplies and places to rest or sleep. All systems are to be tested and maintained regularly and integrated into life-cycle management; the maximum tolerable downtime follows from the protection need identified.
Planning new sites & security away from the site
Security-relevant aspects must already be taken into account when planning and constructing new sites: the person responsible for site security is to be involved early, a risk and gap analysis carried out and the cost of security measures budgeted for. In addition, organisational assets and processes outside the organisation's own premises (mobile workers or outsourced processes, for example) are to be identified and integrated into the existing site security measures.

Interfaces with other fields of action

Site security never stands alone. DIN SPEC 14027 emphasises its close interlocking with other sections: the protection needs assessment (Section 5), security culture and communication (Section 7), business continuity management (Section 10), know-how protection (Section 17), the selection and management of security-related services (Section 19) and the security management system (Section 20).

Personnel guarding measures and security of supply show particularly clearly how closely physical security and business continuity work together to strengthen the resilience of the organisation as a whole.

The key points in brief

  • Risk-based: every site security measure derives from the protection needs assessment and the object-specific risk assessment.
  • Onion principle: security zones build on one another from the outside (lower) to the inside (higher).
  • Four pillars: perimeter protection, access control management (ACMS), structural hardening and security of supply form the foundation.
  • Structural hardening: resistance classes should exceed the site-specific intervention time.
  • Security of supply: power, heating and cooling, lighting, communications and materials are critical components, to be tested and maintained regularly.

A look ahead to the next lesson

In Lesson 5 – Reactive structures: from disruption to crisis (Sections 9 and 10) we leave the preventive level and turn to responding to events. You will learn to draw a clean line between disruption, emergency and crisis, to understand the difference between the standing organisation and a special response organisation (BAO), and to know the role of the BIA and the BCP in business continuity management.