Creation of service enterprise security is usually preceded by two events: either it is a strong desire to enterprise managers to respond to a sudden emerged real threats to property, physical harm to personnel, etc., or it is based on the results of the study conclude that an unsatisfactory state of enterprise security. In the first case created hastily security service can, to some extent reflect a threat in the future to respond to their appearance on the “threat – a reflection.” The situation changes significantly in the implementation of the second embodiment. After a detailed study of the enterprise security posture (with the involvement of experts, if they are not in the company) from its leaders will have a real understanding of the company’s security system.
Such a system view (recorded in written form) allows you to consciously and purposefully carry out work to ensure the safety of business and the enterprise all its divisions and employees. The primary role of security does not disappear, on the contrary, an understanding of their role and place in the enterprise security system will only lead to positive results.
It should be emphasized, however, that so far there is no unified approach to the definition of “security of the enterprise system.” To give such a definition, you must first identify the elements of the system. Study of specialized literature and practice allowed the author to conclude that the structural elements of enterprise security systems are the scientific theory of its security policy and security strategy, means and methods of security and, finally, the concept of enterprise security.
The totality of these elements is the enterprise security system.
The scientific enterprise security theory strictly speaking, such a theory is in its formative stages. This applies primarily to the conceptual apparatus. Let us examine some of these concepts.
In the Russian legislation (Ukrainian in this respect, unfortunately, is far behind) the concept of security is provided in Art. 1 of the Federal Law of March 5, 1992 “On Security”, “state of the protection of the vital interests of the individual, society and state from internal and external threats.” Disclosure of this concept the term “security” significantly narrows its meaning, emphasizes passivity in response to the threat. SUMMARY security, it appears to be related to the terms “development” and “stability”. In this regard, it should be understood under the security state of an object (in our case – the company) in the system of its relations with the viewpoint of stability (self-survival) and development in the context of internal and external threats, actions unpredictable and unpredictable factors. Based on this notion, we define the following security functions: detection, prevention, reduction, weakening, neutralization, suppression, containment, reflection and eliminating threats.
Under the threat of plant safety to be understood or potentially possible event, action, process or phenomenon that can disrupt its stability and development, or lead to a shutdown of its operations. The threat can be classified by various bases and to measure them in the quantitative parameters. For example, the potential damage is estimated the number of dead people who have lost (worsened) health, monetary amount of economic losses, etc. According to the degree of probability of the threat is assessed as improbable, unlikely, likely, very likely, and it is likely. According to the degree of threat it passes four phases: appearance (nucleation), expansion, stabilization and elimination. time remote threat is defined as the direct, close (up to 1 year) and far (over 1 year), and the distance in the space – the enterprise territory adjacent to the enterprise territory, region of the country, overseas territory. The rate of growth of the threat is measured by months, quarters, years. the threat of tension is reflected in two dimensions:
a) normal, increased, which is close to the limit (threshold), excessive;
b) growth, or decrease in stability.
In addition, the threats are divided on the nature of their origin into two classes:
1) natural (objective), i.e. caused by natural disaster, do not depend on a man (floods, earthquakes, hurricanes, etc.);
2) artificial (subjective), i.e. caused by human activity, unintended (inadvertent) and deliberate (intentional) threats.
A distinction is also economic, social, legal, organ-ionized, information, environmental, technical and criminal threats.
Under the company’s security object is to be understood the degree of stability and development of the company, its ability to withstand threats. The enterprise security objects can be identified:
– various structural units or groups of employees or owners of the company’s shares;
– resources of the enterprise (IT, human resources, logistics, information, intellectual and financial);
– various activities (management, production, supply, etc.).
To ensure the security of the enterprise is a complex effect on the potential and real threats, allowing it to operate successfully in the unstable conditions of the external and internal environment.
Achieving this objective requires implementation of the following tasks:
– identification of threats to the stability and development of the company and the development of measures to counter them;
– protection of technological processes;
– implementation of measures to counter all kinds of espionage (industrial, scientific, technological, economic, etc.);
– timely information to the company’s management on violations of the law by state and municipal authorities, commercial and non-profit organizations that affect the interests of the company;
– prevention of poaching employees of the enterprise, possessing confidential information;
– a comprehensive study of business partners;
– early detection and adequate response to the disinformation activities;
– development and improvement of local regulations aimed at ensuring the security of the enterprise;
– implementation of measures to protect commercial and other information;
– organization of measures to counteract the unfair competition;
– ensuring the protection of all kinds of resources of the enterprise;
– implementation of measures to protect intellectual property;
– organization and carrying out measures for the prevention of emergency situations;
– identify adverse trends among the company’s staff to inform them about the company’s management and the development of appropriate recommendations;
– cooperation with law enforcement and regulatory agencies in order to prevent and suppress offenses against the company’s interests;
– development and implementation of measures to prevent threats to the physical security of the property of the company and its personnel;
– compensation for material and moral damage caused to the company as a result of illegal actions of organizations and individual persons.
Enterprise security system can be built based on the following principles:
1) The priority of preventive measures. The content of this principle is the timely identification of trends and prerequisites for promoting development threats on the basis of the analysis which are produced by appropriate preventive measures to prevent the emergence of real threats.
2) the law. Security measures the company developed on the basis and within the framework of existing instruments. Local legal acts of the enterprise should not contradict the laws and regulations.
3) Integrated use of energy and resources. All available forces and means of the enterprise are used for safety. Each employee must be within the framework of its competence to participate in enterprise security. Organizational form of complex use of forces and means of the program is to ensure the security of the enterprise.
4) coordination and interaction within and outside the enterprise. Threats of countermeasures are carried out on the basis of cooperation and coordination of efforts of all departments, enterprise services, as well as establishing the necessary contacts with external organizations that can provide the necessary support to ensure the security of the enterprise.
5) The combination of transparency with secrecy. Informing the public and the staff of the enterprise within an acceptable range of security measures play an important role – the prevention of potential and real threats. This openness, however, must necessarily be complemented by measures in justified cases conspiratorial nature.
6) Competence. The staff and employees of the group must address security issues in a professional manner, and where necessary, to specialize in its main lines.
7) The economic feasibility. The cost of the financial costs of the security must not exceed the optimal level at which the lost economic sense for their application.
8) Planned basis of activity. Security activities should be based on a comprehensive enterprise security program, security routines for the main types of it (economic, scientific, technical, environmental, Cesky technologists, etc.) and developed for their implementation plans of the enterprise units and individual employees .
9) System. This principle implies taking into account all the factors that affect the safety of the enterprises included in the activities of its employees to ensure all units, the use of this activity all the forces and means.
Enterprise security system includes a number of the following subsystems:
Economic security – state the most effective use of all resources in order to prevent (neutralization, elimination) threats and ensure stable functioning of the enterprise in the market economy.
Techno Security – a set of actions to ensure that the design, construction and operation of complex technical devices in compliance with the essential requirements of accident-free work them.
Environmental security – a secure state of the vital interests of the enterprise personnel and their assets against potential or real threats posed by the effects of human impact on the environment, as well as from natural disasters and catastrophes.
Information security – is the ability of plant personnel to ensure the protection of information resources and streams from the threat of unauthorized access to them.
Psychological security – the state of protection from the negative psychological effects of plant personnel and others involved in its activities.
Physical security – the state of protection of life and health of individuals (groups of individuals) of the enterprise of violent crimes.
Scientific and technical security – the ability of plant personnel to protect its own valuable scientific and technical products from unfair competition.
Fire safety – state of the objects of the enterprise, in which the fire prevention measures and fire protection compliance.
It should be noted that the aforementioned second level subsystems may include a third level subsystem. For example, the sub-systems of economic security can be – the financial, commercial, property and other security subsystems.
In addition, the subsystem itself is not separated by a boundary impenetrable, because they are so interconnected with each other in the organic unity of form a single enterprise security system. The division of the unified enterprise security subsystem on the second and the third level is made from methodological considerations, as it allows for a more detailed study of all the elements.
Reliability and efficiency of enterprise security system is estimated on the basis of a single criterion – the degree of presence or absence caused him pecuniary and non-pecuniary damage. The content of this criterion is revealed through a series of indicators:
1) preventing the leak of confidential information;
2) the prevention or suppression of unlawful acts on the part of personnel of the enterprise, its visitors, customers;
3) preservation of the property and the intellectual property of the enterprise;
4) prevention of emergency situations;
5) prevention of violent crimes against the individual (dedicated) employees and groups of employees of the enterprise;
6) timely detection and prevention of unauthorized access attempts on protected objects of the enterprise.
And security policy
Enterprise security policy – a common reference points for action and decision-making, which facilitate the achievement of the objectives. Thus, for the establishment of general guidelines need to initially formulate the goal of ensuring security of the enterprise (the common goal we have already defined above). Such goals may be:
– the strengthening of labor discipline and raising productivity;
– protection of the legitimate rights and interests of the enterprise;
– strengthening of intellectual potential of the enterprise;
– preservation and enhancement of the property;
– improving the competitiveness of their products;
– the most complete information support of the company and increase its efficiency;
– focus on global standards and leadership in the design and development of new technologies and products;
– fulfillment of production programs;
– Assisting management structures to achieve business objectives;
– prevention, depending on a random and unfair business partners.
In view of the above, you can define the following general guidelines for action and decision-making, which facilitate the achievement of these objectives:
– the preservation and increase re resource potential;
– a complex of preventive measures to improve the level of protection of property and personnel of the enterprise;
– inclusion in the activities of the security enterprises of all its employees;
– professionalism and specialization of plant personnel;
– the priority of non-violent methods to prevent and neutralize threats.
For successful implementation of this policy is necessary to implement enterprise security strategy, which is understood as a set of the most significant decisions aimed at ensuring an acceptable level of safety of operation of the business.
The following types of security policies:
1) focused on the elimination of existing and prevention of potential threats;
2) aimed at preventing the effects of existing or potential threats for safety;
3) to restore (compensation) of damage caused.
The first two types of strategies include activities such security, as a result of which there is no threat or creates a barrier to its influence. In the third case, the damage may be (there), but it is compensated by the actions that provides a strategy. It is obvious that the third type of strategy can be developed and implemented in relation to situations where the damage vospolnimo, or when there is no possibility to carry out any implementation strategy of the program of the first or second type.
Enterprise security principals
Enterprise security involved two groups of subjects. The first group is engaged in this activity directly in the company and is subject to its management. Among this group, you can select specialized subjects (council or the company’s security committee, the security service, fire department, rescue service, etc.), the main purpose of which is the constant professional activities to ensure the security of the enterprise (within its competence). Another portion of the subjects of this group can be termed poluspetsializirovannoy because part of the functions of these entities is designed to provide enterprise security (medical unit, the legal department, etc.). Finally, the third part of this group of subjects include the rest of the staff and the enterprise division, which as part of their job descriptions and positions of departments are obliged to take measures to ensure safety. It should be borne in mind that effectively ensure the safety of the enterprise, these subjects can only be if the objectives, tasks, functions, rights and responsibilities will be distributed among them so that they do not overlap with each other.
The second group of subjects include external bodies and organizations, which operate independently and are not subject to the company’s management, but their activities have a significant (positive or negative) impact on the security of the enterprise. The subjects of this group are:
1) Legislatures.
2) The bodies of executive power.
3) courts.
4) The law enforcement agencies.
5) Research and educational institutions.
The latter (especially non-governmental institutions for the preparation of private security guards) are designed to provide scientific and methodological elaboration of enterprise security and training of relevant specialists in the field of enterprise security.
It is obvious that the subjects of the second group on its own initiative occasionally connected (or never) to ensure its security on the enterprise. Organizational form of such a connection can be a complex enterprise security program, which is necessary to provide the forms and methods of work. In addition, we can recommend the development of plans of structural units and the enterprise as a whole, the organization of interaction with the aforementioned authorities and organizations.
Means and methods of security
Among the existing security products are the following:
1) Technical means. These include security and fire systems, video-radio equipment, means of detecting explosive devices, bulletproof vests, fences, etc.
2) Organizational tools. The creation of specialized org-structural units that provide enterprise security.
3) Information agent. First of all, it is printed and video products for the preservation of confidential information. In addition, important information for decision-making on security issues is stored on computers.
4) Funds. It is obvious that without sufficient financial means can not function security systems, the only question is how to use them purposefully and with high efficiency.
5) Legal means. This refers to the use of not only the higher authorities issued laws and regulations, but also the development of their own, so-called local regulations on security.
6) Human means. This refers primarily adequacy of personnel responsible for the security. At the same time solve the problem of increasing their professional skills in this field.
7) Intelligent agents. The involvement of highly skilled professionals, scientists (sometimes it is advisable to involve them from the side) allows to introduce new safety systems.
It should be noted that the use of each of the above means alone gives the desired effect, it is possible only in an integrated manner. At the same time it should be noted that the simultaneous implementation of all the above means, in principle, impossible. It usually takes place a series of steps:
Stage I. The allocation of funds.
Stage II. Formation of human and organizational resources.
Stage III. Develop a system of legal remedies.
Stage IV. Involving technical, informational and intellectual resources.
Translated from the static to the dynamic state of said means are means, ie techniques, modes of action. Accordingly, it is possible to talk about the technical, organizational, informational, financial, legal, human resources and intellectual methods. Here is a short list of these specific methods:
– technical – surveillance, monitoring, identification, etc .;
– organization – establishment of security zones regime, investigation, posts, patrols, etc .;
– information – drawing on the characteristics of employees, analysis of a confidential nature, etc .;
– financial – financial incentives for employees who have achievements in providing security, cash paying informants, etc .;
– Legal – Judicial protection of the legitimate rights and interests, and assist law enforcement agencies, etc .;
– Personnel – selection, placement and training of personnel to ensure the safety of the enterprise and their education, etc .;
– intellectual – patents, know-how, etc.
Enterprise security concept
After studying all the above elements of enterprise security systems must go to the drawing up of its concept. The concept is defined as a system of beliefs, ideas, target setting, imbued with a single, defining intent, the leading idea containing formulation and solutions to identified problems. For any concept of the following requirements:
1) Constructibility. Such a requirement is found to be realized if the concept will be reflected in:
a) the initial state of the object on which the concept is directed transformation;
b) the state of the object, achieved as a result of implementation of the concept;
c)the measures necessary to achieve the objectives set out in the concept;
g) means necessary and sufficient to achieve the goals;
e) sources of resource support, used in the course of implementation of the concept;
e) the mechanism of realization of the concept, ie, methods (methods) using the allocated resources and resources.
2) Inscribability. It is understood that the concept of transformation of an object must integrate harmoniously with the system transforms into a single system of interconnected objects, one component of which he is.
3) Open. The developed concept is to allow within its framework to respond to changing conditions of implementation of the concept and make adjustments to the implementation in case of need.
The above requirements dictate as a requirement for inclusion in the logical structure of the concept of the following items:
1) Identification of the object and the object, to determine their effect, among many other places.
2) A clear formulation of the role of the implementation of the concept and challenges in its implementation.
3) Allocation of the conditions necessary and sufficient for the implementation of the concept, and their comparison with the actually existing.
4) Determination of the range of measures to ensure the transformation of the object implementation of the concept, as well as ways to implement it.
5) Formulation of criteria for the success of measures for the development of the concept, as well as to assess the results of its implementation.
Enterprise security concept is approved the document, which reflects the views of the system, requirements and conditions for the organization of security personnel and the ownership of the enterprise. Est structure concept may look as follows:
I. Description of the problem situation in the field of enterprise security:
– the list of potential and real threats, their classification and ranking;
– causes and factors of origin of threats;
– the negative consequences of threats to the enterprise.
II. Security mechanism:
– definition of the object and the subject of enterprise security;
– the formulation of policy and security strategy;
– principles of safety;
– security objectives;
– the problem of security;
– criteria and indicators of enterprise security;
– the creation of org structure for the management of the enterprise security system.
III. For the implementation of security measures Events:
– the formation of subsystems total enterprise security;
– definition of enterprise security actors and their po-li;
– calculation means and the definition of security methods;
– monitoring and evaluating the implementation of the concept.
It must be borne in mind that the most complete picture of the company’s security system can be formally adopted after studying the documents of the enterprise security concept, integrated enterprise security programs and plans of business units to implement this program. Formed on the basis of the scientific enterprise security system is an organizational basis for the creation of its structural units – security.
Source: Journal Best of Security
