To save content items to your account,
please confirm that you agree to abide by our usage policies.
If this is the first time you use this feature, you will be asked to authorise Cambridge Core to connect with your account.
Find out more about saving content to .
To save content items to your Kindle, first ensure no-reply@cambridge.org
is added to your Approved Personal Document E-mail List under your Personal Document Settings
on the Manage Your Content and Devices page of your Amazon account. Then enter the ‘name’ part
of your Kindle email address below.
Find out more about saving to your Kindle.
Note you can select to save to either the @free.kindle.com or @kindle.com variations.
‘@free.kindle.com’ emails are free but can only be saved to your device when it is connected to wi-fi.
‘@kindle.com’ emails can be delivered even when you are not connected to wi-fi, but note that service fees apply.
• Understand the management of incidents, which is the consequence of vulnerabilities and threats.
• Distinguish between the concepts incidents, threats and vulnerabilities.
• Be aware of the different types of incidents and how to handle them.
• Describe the steps a security practitioner must follow when attending to security incidents.
INTRODUCTION
This book was written to enlighten security officials about security information management, which includes the collection and analysis of information on security incidents, threats and vulnerabilities and the implementation of security risk control measures. The security industry operates within a diverse and multi-disciplinary knowledge base, with security risk management being a fundamental knowledge domain within security. Over the past decade, the concept of security risk management as a formal discipline has emerged throughout the private and government sectors of security. Security risk management is now a well-established discipline, with its own body of knowledge. The standards and compliance requirements for risk management only considers security risk management and not security information management. In security risk management, security risk assessment is carried out to identify areas that need security intervention. The security risk management framework currently used by the security industry provides for security risk analysis. This does not include the day-to-day collection of security information on security incidents, threats and vulnerabilities for the purpose of reducing crime, increasing detection rates and preventing losses. In this final chapter, attention will be given to a brief summary of the kinds of security information that was discussed in this book.
SECURITY INCIDENTS, THREATS AND VULNERABILITIES
Security incidents occur because of security breaches, breaches of discipline by security officers, and poor implementation of existing security policies and procedures. Threat is considered as the consequence of the incident, which at the time the incident was taking place, may have affected people, information or assets. In the security context, a threat may be defined as an adversary, being the sum of intent and capability (Smith and Brooks, 2013). Vulnerability on the other hand gives exposure for an incident to occur, causing physical and emotional hurt, being open to attack, or lacking resilience (Smith and Brooks, 2013). It was found that in many organisations/companies security incidents are managed without any strategic direction and infrastructure.
• Discuss the historical context relating to security information management
• Discuss what constitutes a traditional approach in the management of security information
• Critique the statement, “Overprotection of a non-essential entity or failure to adequately protect a vital portion of a facility”
• Appraise the need for a model for the management of security information
INTRODUCTION
This book is about managing security information on incidents, threats and vulnerabilities. Incident-based information refers to a variety of events, including for instance an accident, anecdote (bird flies into a camera), or violation of law or of company policy. Reference is made to threat information as information on crimes, criminals, victims, commercial or industrial competitors and people with malicious intent to harm an entity. Security measures are emphasised as the source of information on vulnerabilities and risks. This book has been written with the support of security managers, security officials and stakeholders from different sectors of the security industry, both private and in government. By the end of the book the reader will have a good idea of the collection and analysis of security information relevant to incidents, threats, and vulnerabilities as well as the implementation of security risk control measures (physical protection systems (PPS), strategies and/or actionable information products).
The management of security information is one of the key functions of a security service provider, whether in-house or contracted. It contributes to a wide range of objectives at every level of security, from the reduction of crime to increasing detection rates and preventing losses. Whatever security objectives it is directed at, the management of security information will involve the collection and analysis of security information and the implementation of security risk control measures. Questions on how security practitioners should respond and manage information on incidents, threats and vulnerabilities have plagued scholars and practitioners for decades. It is still our constant source of discussion and is perhaps debated more so now than before the aftermath of the 11 September 2001 attacks on the World Trade Centre in New York and the Pentagon in Washington, DC.
In writing this book, the author considered the International Risk Management Standard ISO 31000:2009, crime combatting and risk mitigation models used internationally and in South Africa by law enforcement and the private security industry.
The concept of students’ opportunity to learn (OTL) the content of any assessment is grounded in the early discussions that led up to the Pilot Twelve-Country Study in 1960. The model of school learning later published by Carroll (1963) and mastery learning by Bloom (1968), both of whom were involved in those early discussions, explicated the thinking around OTL and its connection to measures of student achievement. This chapter provides an historical and conceptual overview of OTL and the important role it has in any study of student achievement or performance. The chapter also provides an overview for how OTL has been included in both IEA and PISA studies of mathematics and science.