Specific protection

Distinct protection needs

While the central fields of action in corporate security deal with the basic protection of sites and processes, specific protection addresses particular, clearly delimited protection needs. This lesson brings together five topic-specific fields of action from DIN SPEC 14027: know-how protection (Section 17), personal protection (Section 12), event security (Section 13), travel security (Section 15) and supply chain security (Section 18).

What these fields have in common is that they build on the findings of the protection needs assessment (Section 5) and are implemented on a risk basis. Their scope and depth follow the organisation's individual security level, from SMEs to global players.

Learning objectives of this lesson

After this lesson you will be able to:

  • distinguish know-how, product and prototype protection from one another,
  • describe the building blocks of personal protection for exposed individuals,
  • name the requirements for event security and travel security,
  • explain the risk-based protection of the supply chain.

Key terms from practice:

Know-how protection
Protection of non-public knowledge and confidential information, such as trade and business secrets (Section 17).
Product protection
Protection of products already on the market against counterfeiting and piracy. It covers finished products as well as ideas and knowledge.
Prototype protection
Protection during the development phase up to market launch, covering physical prototypes (test models) and digital designs (CAD drawings).
Counter-eavesdropping
Preventive and detective measures to prevent, detect and respond to the unauthorised eavesdropping of confidential information.
Personal protection
Protection of exposed individuals (board members, for example) against deliberate threats and attacks through proactive and reactive measures (Section 12).
Travel security
Protection of goods carried and sensitive information (prototypes or know-how, for example) on business trips, in line with DIN ISO 31030 (Section 15).

The all-hazards approach as the basis

All fields of specific protection follow the all-hazards approach and a protection needs analysis. Before any concrete protective measure is taken, the question always comes first: which assets are worth protecting, and which threats are they exposed to? Only from this assessment are preventive, reactive and corrective measures derived that match the security level identified (A = very high to D = low).

Deep dive:

The following sections explore the essential building blocks of specific protection in more depth.

Know-how, product and prototype protection (Section 17)
Know-how protection covers all measures that protect confidential knowledge, intellectual property, trade or business secrets and innovative technologies against loss, unauthorised use or unauthorised disclosure. The aim is to maintain competitiveness in the long term and secure the capacity to innovate. The three categories differ in focus and timing: know-how protection concerns internal knowledge, product protection the products already on the market, and prototype protection the development phase. The areas of action are: organisational preparation, preventive, reactive, technological, structural and legal protective measures, counter-eavesdropping, responsibilities and personnel measures. The requirement catalogue is consistent with DIN EN ISO/IEC 27000.
Personal protection for exposed individuals (Section 12)
Personal protection aims to protect exposed individuals such as board members against deliberate threats and attacks. This applies particularly in large organisations or those with high public visibility. Every measure is preceded by a comprehensive protection needs analysis as the basis for a tailored security concept. The measures required include: further analyses (visibility or medical risks, for example), drawing up an individual security concept, initiating an official threat classification where appropriate, and selecting qualified personnel. Important external interfaces are police authorities, private security service providers and public bodies.
Event security (Section 13)
Event security ensures that internal and external events run smoothly and protects exposed individuals and the general public against threats. The relevant rulebooks are the German model regulation on places of assembly (MVStättVO) and DGUV Information 215-310. Measures to be carried out in a structured way include: an event-specific risk analysis and security concept, securing communications, selecting and training personnel, admission and access controls, property protection and surveillance, medical provision, traffic and transport management, and interfaces to emergency and crisis management and to insurance cover.
Travel security (Section 15)
Travel security integrates the protection of mobile business activity into corporate security. In this document the focus is not the safety of the employee but the protection of goods carried and sensitive information (prototypes or know-how, for example). Further guidance is given in DIN ISO 31030. Measures extend across the phases: organising travel security, trip preparation, during the trip, and documentation and review. Through systematic trip registration, the organisation knows at all times which trips are taking place and can respond quickly to incidents. External interfaces are assistance providers for travel security and travel medicine, and security service providers.
Supply chain security (Section 18)
Supply chains are central to an organisation's success but contain many vulnerabilities. Protecting them requires standardised security measures combined with a risk-based approach. The risk profile is determined by two factors: the nature of the product (demand, ease of resale) and the geographical characteristics of the transport routes (crime rate, natural hazards, political stability). Concepts must cover at least the following areas: strategy and management, risk assessment and mitigation, cargo and goods security, transport security, incident management and response, supplier and third-party security, and disposal management. Complete, traceable documentation plays a central role.

Connections and interfaces

The five fields of specific protection are closely interlocked with one another and with other fields of action. Know-how protection in particular influences site security, supply chain security and integrity screening. Personal protection interlocks closely with travel security and event security wherever exposed individuals have to be protected while travelling or at events. On international trips, in turn, travel security and supply chain security overlap in protecting the goods being carried.

The key points in brief

  • Five fields: know-how protection, personal protection, event security, travel security and supply chain security make up specific protection.
  • Three know-how categories: know-how protection (knowledge), product protection (products on the market) and prototype protection (development phase) differ in focus and timing.
  • Protection need first: every measure builds on a risk-based protection needs analysis and follows the security level A–D.
  • Standards referenced: travel security follows DIN ISO 31030, know-how protection DIN EN ISO/IEC 27000, and events the MVStättVO and DGUV 215-310.

Looking ahead: in the next lesson, Lesson 7 – "People and culture", we look at Sections 7, 8, 14 and 16: security culture and awareness, integrity screening, internal investigations and structured threat management.