People and culture

People as the key to resilience

Even the best security technology is of little use if employees are not brought along. In Sections 7, 8, 14 and 16, DIN SPEC 14027 puts the human factor at the centre: from a lived security culture through integrity screening in recruitment to the professional handling of internal investigations and threats.

Resilience cannot be increased without a contribution from every individual in the organisation. Security culture therefore has to become a natural part of the organisational culture.

Your learning objectives

• You can describe how security culture and awareness are built up.
• You can distinguish pre-employment and in-employment screening from third party due diligence.
• You know the requirements for internal investigations and the role of IT forensics.
• You can explain structured case management in threat management.

Key terms from practice:

Security culture
The awareness, values and norms an organisation shares in relation to security. A central building block for lasting resilience.
PES (pre-employment screening)
Screening of applicants as part of security-oriented recruitment: an objective check of qualifications, suitability and trustworthiness.
IES (in-employment screening)
Screening of trustworthiness and suitability while an employee is already working for the company, including in the case of internal applications.
Due diligence
Third party due diligence: meeting duties of care by screening business partners. Partly required by law (the EU supply chain act, for example).
Threat management
Early recognition, assessment and defusing of potential threats, and the prevention of targeted violence through an interdisciplinary approach.
TAMT
Threat Assessment & Management Team (in German: Bedrohungsanalyse- und Risikomanagement-Team).

The four building blocks at a glance

The area of people and culture links four closely interlocking fields of action in corporate security. They work together: a strong security culture creates the basis for threats being recognised early, tip-offs being reported and investigations being conducted fairly.

Section 7 – security culture and communication
Section 16 – integrity screening (PES, IES, due diligence)
Section 8 – internal investigation
Section 14 – threat management and violence prevention

Deep dive

The following sections explore the essential building blocks of people and culture in more depth.

Security culture and awareness (Section 7)
A lived security culture is part of the organisational culture. It rests on consistently building the knowledge, motivation and awareness of all employees in relation to threats. The measures that strengthen it are: culture-building measures, awareness-raising, training, exercises, communication and cooperation. Top management should commit to promoting it and equip subject-matter experts with sufficient resources. Formats range from classroom training and web-based training to serious business gaming and VR experiences. This section has interfaces with every other section of the document.
Integrity screening: PES, IES and due diligence (Section 16)
Integrity screening serves security-oriented recruitment. Following the recommendation of the German Federal Office for the Protection of the Constitution (BfV), screening should follow the principle 'authentic, complete and coherent'. The level of screening always follows the protection need of the position (protection needs matrix). What can be checked includes identity, residence status, the police certificate of good conduct, educational qualifications and references. In the case of due diligence, rules such as the EU supply chain act or the UK Bribery Act make it partly mandatory. Data protection and compliance must be involved.
Internal investigations (Section 8)
Internal investigations are to be conducted professionally, promptly, confidentially and objectively. In certain contexts (where criminal or civil proceedings are in prospect) they have to be conducted so as to stand up in court. The central elements are: an independent organisational structure to avoid conflicts of interest, involvement of the bodies concerned, complete documentation (the duty to keep proper records) and a structured core process. IT forensics secures and analyses digital traces. Limits arise from personality rights and data protection law. Final accountability cannot be delegated to external service providers.
Threat management and violence prevention (Section 14)
Threat management covers the early recognition, assessment and defusing of potential threats and the prevention of targeted violence. It is usually embedded in a security culture and needs a visible mandate. Managers and HR functions play a key role, because they recognise conspicuous behaviour early. At its core is structured case management: standardised recording, assessment, documentation and follow-up, with a transparent escalation process, risk-oriented planning of measures and continuous re-evaluation. In organisations operating globally, case handling should work across sites.

Green, yellow and red flags

Within screening processes, the DIN SPEC uses a three-level classification system to categorise the suitability and trustworthiness of applicants systematically.

● Green flag: an indication that the applicant meets the requirements and is trustworthy.
● Yellow flag: an indication of potential problems or uncertainties that may require further checking (inconsistencies in a CV, for example).
● Red flag: an indication of serious concerns or risks that may rule out an appointment (falsified information, for example).

The key points in brief

People and culture form the human backbone of corporate security. Four fields of action work together:

Security culture creates awareness and motivation among all employees.
Integrity screening (PES, IES, due diligence) minimises risks in appointments and business relationships, based on the protection need and compliant with data protection law.
Internal investigations clarify incidents in a legally sound, fair and fully documented way.
Threat management recognises and defuses dangers through structured case management.

Looking ahead: in Lesson 8 – Management and governance – you will learn from what point a corporate security management system (CSMS) has to be established, how to manage security service providers and how the continuous improvement process (CIP) holds the entire security architecture together.