Security Management
Organising guarding, access and surveillance.
What it studies
Security management studies threat, risk and the organisation of guarding, access and surveillance: threat analysis, vulnerability assessment, security design and the operational deployment of people and technology to reduce risk. The field overlaps with, but is not identical to, the broader security discipline that also covers physical and organisational risk beyond malicious threat.
Why Facility Management needs it
FM delivers the security service (guarding, access, camera surveillance), but the underlying threat and risk analysis is a separate field with its own methodology. There is also a recurring taxonomic ambiguity between 'security management' as an operational service and 'security' as the broader risk discipline where it meets safety, which creates confusion over exactly where responsibilities sit.
Questions it answers
- Is the security measure based on a current threat analysis, or on a historical, unrevised security plan?
- Does responsibility for this risk sit with security (threat from people) or with the broader safety domain (physical, organisational)?
Evidence sources
- ASIS International — security standards and practice frameworks.
- Threat and risk analysis methodology from the security discipline.
Operating and management implications
- Security deployment should be periodically recalibrated against a current threat analysis, not continued on the basis of an outdated design.
- The boundary between security management (threat from people) and the broader safety domain should be explicitly documented to prevent overlap and gaps.
Open question
Security management, security, or the broader security discipline: which taxonomy applies?
This Atlas places security management in the Service & Experience cluster, as the operational service FM delivers, and security as the broader risk discipline in the Risk, Compliance & Resilience cluster. That separation is analytically defensible but not universal: in many organisations and in parts of the literature the two terms are used interchangeably without that distinction. The choice here is deliberate, not neutral, and readers should determine for themselves which division their own organisation actually applies.
Related services
- Security & access control
Related capabilities
- Conducting and periodically recalibrating threat and risk analyses
Related operating models
- In-house (retained) delivery organisation
Critical sites often deliberately keep threat analysis in-house given the sensitivity of the information.
Related standards
- ASIS International standards; ISO 18788 (management of private security operations).
The standards section arrives in Part 7.
Common misuse
- Security level determined by visibility ('more people in uniform') rather than by threat analysis.
Current research frontier
The integration of cyber threat with physical security (access systems as an attack surface, connected camera and building systems) requires a combination of security management and cybersecurity knowledge that most FM organisations have not yet brought together.
Further reading
- ASIS International, Protection of Assets manual.