The individual fields of action in corporate security only take full effect once they are embedded in an overarching system. This closing lesson covers Sections 19 and 20 of DIN SPEC 14027: managing security service providers and building a corporate security management system (CSMS).
A CSMS comprises the entirety of the processes and resources subject to management and contributes to reaching a defined maturity level in a controlled way. It secures the interface between all the organisation's security-relevant activities.
The corporate security management system forms the governing umbrella over all the fields of action in DIN SPEC 14027. As soon as at least two sections of the standard are implemented, the establishment of a CSMS is to be reviewed on an ongoing basis. It provides interface management, reporting, and assessment and monitoring.
The management of external service providers follows a structured four-phase model, from preparation through selection and onboarding to ongoing control. The CIP ensures that the system as a whole remains able to learn. Annex A supplies the auditable requirements as the foundation for audits and compliance.
With this lesson you complete the course on DIN SPEC 14027. From the fundamentals through the protection needs assessment, the security situation picture, site security, reactive structures, specific protection and people & culture to management & governance, you have covered all eight areas of physical resilience and corporate security. You are now able to apply the individual fields of action modularly or holistically in your organisation and to manage them effectively through a CSMS.