Security
Threat, vulnerability and measure as one whole.
What it studies
Security as a risk discipline studies threat, vulnerability and consequence together: who or what can harm an organisation, where the weak point sits, and which measure — physical, organisational or technical — reduces that combination at what cost. It works with threat assessment, penetration and vulnerability testing and security tiers, not with day-to-day guarding execution.
Why Facility Management needs it
FM often delivers the physical measures — access, camera surveillance, guarding — but the threat picture and the risk trade-off around it belong to this discipline, not to operational delivery. Without that separation, a security budget is shaped by what a supplier offers rather than by what the threat justifies.
Questions it answers
- What threat level is realistic for this site and this organisation, and who determined it?
- Where does the vulnerability sit: in the building, the process, or user behaviour?
- Is the measure proportionate to the risk, or mainly visible and reassuring?
Evidence sources
- ASIS International — professional standards and risk methodologies for security management.
- ISO 31000 (generic risk management) applied to physical and organisational threat.
- Criminological and security-science research on situational crime prevention.
Operating and management implications
- A threat assessment should precede a guarding tender, not follow it.
- Security tiers that are not re-assessed after an incident or reorganisation silently lose their validity.
Related services
- Security (the Part 3 service): delivers the daily execution — access, guarding, control room — on the threat level this discipline determines.
Related capabilities
- Threat and vulnerability analysis
- Security tier setting and revalidation
Related operating models
- Regieorganisatie — managing organisation / intelligent client function
The regieorganisatie must be able to set the threat level itself; otherwise the supplier quietly determines risk policy.
Related standards
- ISO 31000; ASIS guidelines for physical security (not an ISO standard, an industry standard).
The standards section arrives in Part 7.
Common misuse
- Security Management (organising guarding and surveillance, a service-delivery discipline in the Service & Experience cluster) is often conflated with security as a risk discipline here. The former organises execution; the latter determines what is actually needed. Both are required and neither substitutes for the other.
- Camera surveillance deployed as a generic measure without a threat assessment justifying placement.
Current research frontier
The convergence of physical and digital threat — a building system attacked over the network, or a physical break-in enabling digital access — is still rarely brought into a single risk assessment; physical security and cybersecurity often remain separate functions with separate threat pictures.
Further reading
- ISO 31000:2018, risk management guidelines.
- ASIS International, Protection of Assets manual.