Risk, Compliance & Resilience

Security

Threat, vulnerability and measure as one whole.

Risk, Compliance & Resilience

What it studies

Security as a risk discipline studies threat, vulnerability and consequence together: who or what can harm an organisation, where the weak point sits, and which measure — physical, organisational or technical — reduces that combination at what cost. It works with threat assessment, penetration and vulnerability testing and security tiers, not with day-to-day guarding execution.

Why Facility Management needs it

FM often delivers the physical measures — access, camera surveillance, guarding — but the threat picture and the risk trade-off around it belong to this discipline, not to operational delivery. Without that separation, a security budget is shaped by what a supplier offers rather than by what the threat justifies.

Questions it answers

  • What threat level is realistic for this site and this organisation, and who determined it?
  • Where does the vulnerability sit: in the building, the process, or user behaviour?
  • Is the measure proportionate to the risk, or mainly visible and reassuring?

Evidence sources

  • ASIS International — professional standards and risk methodologies for security management.
  • ISO 31000 (generic risk management) applied to physical and organisational threat.
  • Criminological and security-science research on situational crime prevention.

Operating and management implications

  • A threat assessment should precede a guarding tender, not follow it.
  • Security tiers that are not re-assessed after an incident or reorganisation silently lose their validity.

Related services

  • Security (the Part 3 service): delivers the daily execution — access, guarding, control room — on the threat level this discipline determines.
To the Services Atlas

Related capabilities

  • Threat and vulnerability analysis
  • Security tier setting and revalidation

Related operating models

All operating models

Related standards

  • ISO 31000; ASIS guidelines for physical security (not an ISO standard, an industry standard).

The standards section arrives in Part 7.

Common misuse

  • Security Management (organising guarding and surveillance, a service-delivery discipline in the Service & Experience cluster) is often conflated with security as a risk discipline here. The former organises execution; the latter determines what is actually needed. Both are required and neither substitutes for the other.
  • Camera surveillance deployed as a generic measure without a threat assessment justifying placement.

Current research frontier

The convergence of physical and digital threat — a building system attacked over the network, or a physical break-in enabling digital access — is still rarely brought into a single risk assessment; physical security and cybersecurity often remain separate functions with separate threat pictures.

Further reading

  • ISO 31000:2018, risk management guidelines.
  • ASIS International, Protection of Assets manual.