Even the best security technology is of little use if employees are not brought along. In Sections 7, 8, 14 and 16, DIN SPEC 14027 puts the human factor at the centre: from a lived security culture through integrity screening in recruitment to the professional handling of internal investigations and threats.
Resilience cannot be increased without a contribution from every individual in the organisation. Security culture therefore has to become a natural part of the organisational culture.
• You can describe how security culture and awareness are built up.
• You can distinguish pre-employment and in-employment screening from third party due diligence.
• You know the requirements for internal investigations and the role of IT forensics.
• You can explain structured case management in threat management.
The area of people and culture links four closely interlocking fields of action in corporate security. They work together: a strong security culture creates the basis for threats being recognised early, tip-offs being reported and investigations being conducted fairly.
Section 7 – security culture and communication
Section 16 – integrity screening (PES, IES, due diligence)
Section 8 – internal investigation
Section 14 – threat management and violence prevention
The following sections explore the essential building blocks of people and culture in more depth.
Within screening processes, the DIN SPEC uses a three-level classification system to categorise the suitability and trustworthiness of applicants systematically.
● Green flag: an indication that the applicant meets the requirements and is trustworthy.
● Yellow flag: an indication of potential problems or uncertainties that may require further checking (inconsistencies in a CV, for example).
● Red flag: an indication of serious concerns or risks that may rule out an appointment (falsified information, for example).
People and culture form the human backbone of corporate security. Four fields of action work together:
• Security culture creates awareness and motivation among all employees.
• Integrity screening (PES, IES, due diligence) minimises risks in appointments and business relationships, based on the protection need and compliant with data protection law.
• Internal investigations clarify incidents in a legally sound, fair and fully documented way.
• Threat management recognises and defuses dangers through structured case management.
Looking ahead: in Lesson 8 – Management and governance – you will learn from what point a corporate security management system (CSMS) has to be established, how to manage security service providers and how the continuous improvement process (CIP) holds the entire security architecture together.