Having covered the fundamentals, the protection needs assessment and the security situation picture, we now turn to one of the most important practical fields of action in corporate security: site security (Section 11 of DIN SPEC 14027).
In the context of corporate security, site security covers all measures that serve to protect a defined site – a company site, a building, a piece of critical infrastructure or a facility, for example – against threats within the meaning of the all-hazards approach, and thereby to secure the organisation's protection objectives.
After this lesson you will be able to:
A central principle of DIN SPEC 14027 is that all site security measures are derived from an object-specific risk assessment and from the protection needs assessment. There is no off-the-shelf security: every measure has to match the security level identified (A = very high to D = low).
Site security measures comprise a coordinated mix of structural, technical, organisational and personnel protective measures. They make sense for every organisation in principle, but they become indispensable where an organisation operates critical infrastructure, processes highly sensitive data, stores valuable goods, occupies an exposed location or is subject to statutory requirements.
DIN SPEC 14027 divides site security into several core areas. The central requirements include perimeter protection and the zone model, access control management, structural hardening and security of supply. These areas interlock and together yield a coherent protection concept for any site.
The following section explores these fields of action in more depth, with reference to the respective requirements of the DIN SPEC.
The following sections explore the four pillars of site security in more depth.
Site security never stands alone. DIN SPEC 14027 emphasises its close interlocking with other sections: the protection needs assessment (Section 5), security culture and communication (Section 7), business continuity management (Section 10), know-how protection (Section 17), the selection and management of security-related services (Section 19) and the security management system (Section 20).
Personnel guarding measures and security of supply show particularly clearly how closely physical security and business continuity work together to strengthen the resilience of the organisation as a whole.
In Lesson 5 – Reactive structures: from disruption to crisis (Sections 9 and 10) we leave the preventive level and turn to responding to events. You will learn to draw a clean line between disruption, emergency and crisis, to understand the difference between the standing organisation and a special response organisation (BAO), and to know the role of the BIA and the BCP in business continuity management.