To save content items to your account,
please confirm that you agree to abide by our usage policies.
If this is the first time you use this feature, you will be asked to authorise Cambridge Core to connect with your account.
Find out more about saving content to .
To save content items to your Kindle, first ensure no-reply@cambridge.org
is added to your Approved Personal Document E-mail List under your Personal Document Settings
on the Manage Your Content and Devices page of your Amazon account. Then enter the ‘name’ part
of your Kindle email address below.
Find out more about saving to your Kindle.
Note you can select to save to either the @free.kindle.com or @kindle.com variations.
‘@free.kindle.com’ emails are free but can only be saved to your device when it is connected to wi-fi.
‘@kindle.com’ emails can be delivered even when you are not connected to wi-fi, but note that service fees apply.
• Critically discuss the conceptualised assumptions generated through the grounded data.
• Defend the functioning of Security Information Management Companies.
• Discuss the security information management model used in Western Australia.
• Compare the security industry in Gauteng, South Africa with that of Perth in Western Australia.
INTRODUCTION
This chapter focuses on security information management practices used by security service providers in the Gauteng province of South Africa and in Perth, Western Australia. Research on the management of security information was conducted in Gauteng, South Africa and in Perth, Western Australia using the grounded theory design. This strategy was used to accurately determine how security information is managed in private and government organisations in both countries. The researcher held a social constructivist worldview that officials understand the world in which they live and work better than anyone not specifically working in their environment. Therefore, the researcher relied as much as possible on the one-on-one interviews and focus group interviews. Simultaneously, there was a need to understand the responses provided by the participants and to interpret their meaning, so that a theory or pattern of meaning could be generated and inductively developed from the grounded data. Using one-on-one interviews and focus group discussions, the author was directly involved with the participants in the study. Data was collected in the form of written and spoken language using an interview schedule and an interview guide for the focus group interviews. The researcher collected qualitative data from selected security managers, security officials and other stakeholders relating to their own practical experiences on security information management. In so doing, the researcher gained an understanding of the worldview of security practitioners based on their knowledge and experience.
The grounded theory design was used to analyse the data so that a grounded theory could be inductively constructed to contribute to the scientific body of knowledge for this specific discipline. The researcher found the grounded theory design to be a systematic way of developing and integrating this scientific knowledge and information. The open, axial and selective coding procedures were used to generate the grounded theory. This involved generating themes and categories of information, selecting subcategories and positioning it with specific categories and themes within a theoretical model.
• Discuss the problems that gave rise to a security information management model.
• Reconstruct the model for the collection and analysis of security information and the mitigation of security risks.
• Apply the model for the management of security information, describing each stage.
• Formulate a policy framework for the management of security information.
INTRODUCTION
Security information collection first emerged in the mid-1950s. From then onwards the extent, complexity and detail of security information collection, analysis, interpretation and utilisation changed dramatically and developed in many different ways. These changes and developments in the field of security management, gave rise to the design and development of a security information management model (SIMM). All stakeholders in an organisation need to be informed of these changes and developments, in order to ensure that they are aware of the importance and impact of security information in their overall work environment. Contextually, security management will derive the most significant benefits from the SIMM, which should be integrated into the organisations’ existing functional processes. Security information management should be seen as part of the existing functional processes of an organisation. Incidents, threats and vulnerabilities have the potential to affect an organisation's assets negatively. Information on these incidents, threats and vulnerabilities are important to security. It is therefore necessary for this security information to be managed effectively and efficiently, so that correct decisions can be made on the implementation of security risk control measures. A SIMM is important for the management of security information. This chapter will discuss the design and development of the SIMM.
DEVELOPMENT OF A SECURITY INFORMATION MANAGEMENT MODEL
No specific SIMM currently exists for the collection and analysis of security information on security incidents, threats and vulnerabilities, and for the implementation of appropriate security risk control measures to reduce crime, increase detection rates and prevent losses in organisations.
Justification for the Model
Collection of security information
According to the respondents, no policy framework exists for the collection of security information. In general, security information is not collected according to the threats and vulnerabilities confronting an organisation. Most of the information is randomly collected by security managers, investigators and supervisors. This type of collection is done mainly by using technical and human methods.
The advent of the Third International Mathematics and Science Study (TIMSS-95) introduces a new era in international assessments. Prior studies had only about two dozen or fewer countries participating. TIMSS-95 saw a sharp increase in the interest of countries to participate in this type of study. This chapter provides an overview of the countries participating in the mathematics and science studies sponsored by the IEA and PISA from the first pilot study in the early 1960s to 2015. The increase in countries’ interest and participation is situated in the historical context of these studies.
• Define the concept of security information management.
• Defend a framework that supports a contextual definition of security information management.
• Discuss the concepts: security information collection, analysis, and security risk control measures.
• Critique the Private Security Industry Regulatory Act, 56 of 2001.
INTRODUCTION
The discussion and definitions of key concepts in this chapter are important for two reasons: firstly, to provide clarity as far as the use of these concepts are concerned, and, secondly, to provide an early indication of the direction of the discussions in this book. Different definitions and interpretations of important concepts were discovered in the literature and other sources, including official publications and personal interviews. For some concepts, no definitions could be found, hence a “lay person’s” interpretation was provided to give meaning to its application. It is important to define and discuss the key concepts, so that readers will have a common understanding of the important concepts. The following important concepts will be explained:
• security
• security service
• security management
• security information management
• security incident
• security threat
• security vulnerability
• security information collection
• security information analysis
• security risk control measures
SECURITY
“Security implies a stable, relatively predictable environment in which an individual or group may pursue its ends without disruption or harm and without fear of such disturbance or injury” (Fischer, Halibozeck, and Green, 2008). According to Smith and Brooks (2013), a traditional definition of security may be the provision of private services in the protection of people, information and assets for individual safety or community wellness. In addition, Post and Kingsbury (1991), consider the security of private and commercial property as the provision of paid services in preventing undesirable, unauthorised, or detrimental loss to an organisations assets. Private security refers to those efforts by individuals and organisations to protect their assets from loss, harm or reduction in value, due to threats. These assets may include people, fixed and immovable property, business rights, information, company image, operational strategies, contracts, agreements and policy (Bosch, 1999).
SECURITY SERVICE
According to section 1 (1) of the Private Security Industry Regulatory Act, 56 of 2001: “Security service” means one or more of the following services or activities:
• protecting or safeguarding a person or property in any manner;
One of the consequences of the decision to use a total scaled score for reporting both student and country level performance is that international comparative studies have indeed become “cognitive Olympics.” This is evident in the way results are reported with countries ranked according to their score. This is further exacerbated by the shallow domain sampling of the student assessments. Practices are reviewed and discussed that could make international assessments better reflect the curriculum students actually study. In addition, this chapter discusses how measures of what students have been learning in their classroom instruction are essential in interpreting student performance in each country.
Enormous resources have been devoted to international assessments of mathematics and science over the past 50 years. This chapter presents a summary of what the field has learned from all of these studies to clarify ways in which schools really do matter. The focus is on the educational policy-relevant insights gleaned from a macro-level view. In addition, it explores some of the cross-country results that have emerged particularly from the more current studies of PISA and TIMSS (both TIMSS-95 and TRENDS). Ten key findings are summarized that reflect what has been found that has international implications rather than those that are country-specific. In conclusion, results from three countries, Russia, Germany and the United States, are addressed as the effects related to opportunity to learn are broad based, have international implications, and the results have been published so that the results are accessible beyond national boundaries.
In this publication, Prof Doraval Govender has produced a comprehensive study focused on the management of security information by security practitioners in the field of private security. However, it is as applicable for security managers and risk managers working in government departments and entities.
In the process of researching this topic, Prof Govender also investigated aspects of the sub-discipline of security risk management. As a starting point for his analysis he used the broad concept/term ‘security’, which in itself implies that there exists the threat of risk. Such security risk or threat can emanate from a number of different quarters inter alia terrorism, cybercrime and other forms of criminality or identity/personal information theft threat. As a result, organisational management decisions on security risk control measures need to be taken in order to secure an organisation from all of these diverse threats. The security industry itself operates within a diverse and multi-disciplined knowledge base, with security risk management being a fundamental knowledge domain within the security environment.
Accordingly, his study was undertaken in order to understand the role of security information and its collection, interpretation and utilisation in addressing the threat of risks facing in the security industry and the clients they serve and protect. Any incidents of information theft, breaches in security, threats and vulnerabilities have the potential to negatively affect an organisation's assets. Therefore, as Prof Govender points out, information on these incidents, threats and vulnerabilities are crucially important to any organisation's overall security.
The core outcome of his research and outlined in detail in this book was the development of a security information management model (SIMM). In brief, this model is explained as follows: Security information management is spread out in three phases, namely the collection of security information phase; analysis of security information phase; and the implementation of security risk control measures phase. The collection and the analysis of the security information is handled by the Security Information Management Centre (SIMC) and referred to top management as an analysis report (result/outcome). The analysis report is handled by top management and referred to the operational manager or the human resources manager for the application of security risk control measures.