Management and governance

Corporate security management system

The individual fields of action in corporate security only take full effect once they are embedded in an overarching system. This closing lesson covers Sections 19 and 20 of DIN SPEC 14027: managing security service providers and building a corporate security management system (CSMS).

A CSMS comprises the entirety of the processes and resources subject to management and contributes to reaching a defined maturity level in a controlled way. It secures the interface between all the organisation's security-relevant activities.

Learning objectives of this lesson

  • You know from what point a CSMS has to be established and what it comprises.
  • You can describe the four phases of service provider management.
  • You can explain the continuous improvement process (CIP).
  • You can use Annex A as a basis for audits and compliance checks.
Building a corporate security management system (Section 20)
Establishing a CSMS is of central importance for implementing comprehensive measures to strengthen physical resilience. Its introduction involves establishing requirements, structures, processes and procedures within the organisation. The requirements for a CSMS are at least: establishing the security management system, interface management, reporting, and assessment and monitoring. The requirements set out in Annex A are operational minimum standards and are consistent with DIN ISO 28000. Top management must adopt a security policy that sets the strategic framework and is derived from the organisation's objectives, statutory provisions and the current and expected future hazards.
Managing security service providers (Section 19)
Depending on the context, it can make sense to rely on external security service providers, from guarding and protection services through security consulting and risk analyses to forensic investigations. Using them is required in particular where the complexity exceeds internal capacity, specialised capabilities are needed or there is a temporarily elevated protection need. Before placing an order, a documented make-or-buy decision should be taken. Poor management can create considerable security risks. Responsibility for management always remains with the organisation: final accountability cannot be delegated.
Continuous improvement process (CIP)
A CIP for security management must be implemented, documented, carried out and assured in an appropriate manner. Where reviews identify deviations, the causes are to be discussed, possible adjustments to the policy assessed, adjustments implemented and the measures checked for effectiveness. All findings from controls, reviews and audits are collected, analysed and translated into needs for improvement. Changes to the CSMS must be documented, centrally managed and implemented.
Annex A: the basis for audits and compliance
For each field of action, the DIN SPEC contains explanatory prose setting out background, objectives and considerations. In addition, Annex A provides a tabular requirement catalogue with clearly worded, auditable requirements. These tables are standardising and are suitable as a basis for audits, internal reviews or delivery by external service providers. The prose gives orientation, while the tables specify the requirements. Effectiveness is to be verified through regular controls, audits and inspections using control and performance indicators.

The key points in brief

The corporate security management system forms the governing umbrella over all the fields of action in DIN SPEC 14027. As soon as at least two sections of the standard are implemented, the establishment of a CSMS is to be reviewed on an ongoing basis. It provides interface management, reporting, and assessment and monitoring.

The management of external service providers follows a structured four-phase model, from preparation through selection and onboarding to ongoing control. The CIP ensures that the system as a whole remains able to learn. Annex A supplies the auditable requirements as the foundation for audits and compliance.

Course completion

With this lesson you complete the course on DIN SPEC 14027. From the fundamentals through the protection needs assessment, the security situation picture, site security, reactive structures, specific protection and people & culture to management & governance, you have covered all eight areas of physical resilience and corporate security. You are now able to apply the individual fields of action modularly or holistically in your organisation and to manage them effectively through a CSMS.

Our offer:

Download our brochure here:

📄 Download brochure (PDF)