Protective Security is the term given to the act of managing the risks to an organisation's assets.
Why is protective security important to your organisation?
Protecting your assets is essential. But, the threat landscape is diverse and ever changing, and understanding how you may be at risk, and who from, is necessary before you can develop counter-measures to reduce their likelihood and impact.
The key stages to implementing effective protective security
- Security governance: knowing who is responsible for security at a senior level
- Asset-centred risk management: protecting your critical assets through the effective use of technologies, tools and processes
- Securing your supply chain and partnerships: considering partners and suppliers in your risk management process
- Incident management practices and procedures: helps you review your current processes
The above elements should be reviewed regularly, and when required - based on a change in circumstances or threat.
Key terms you should know
- Critical Asset: All organisational assets that are necessary for the delivery of operations, or those of specific organisational value, should be identified considering the following asset types: People, Process, Information, Technology, Facilities (PPITF). Assets will include tangible assets (those assets that are physical in nature, such as buildings and equipment), and intangible assets (those assets that are non-physical, including ideas, software, brands, expertise, relationships, and organisational know-how).
- Threat: The security threat is the intent and capability for a threat actor to take some adverse action against your organisation. Understanding the threats facing your business or organisation will ensure protective security measures are proportionate, effective and responsive.
- Vulnerability: Vulnerability is how inherently prone an asset is to the threat; for example, any weaknesses that exist which a threat actor could exploit. It considers what measures are in place to protect the asset, as well as the state of those measures.
- Risk: Risks are identified threats or vulnerabilities, aligned to assets, that have been assessed for their likelihood (of the threat event occurring) and impact (to the organisation and/or third parties) should the threat transpire.
- Risk Treatment: The risk treatments options include accepting the risk, mitigating the risk, and transferring or removing the risk. A risk treatment option should be chosen based on a detailed analysis of the accompanying factors: the overall risk strategy (risk appetite) of your company, your resources, the objectives of your organisation, as well as predicted costs against the benefits. It is important to ensure that any risk treatment approach is agreed at board level (or equivalent).
Please also refer to our glossary for definitions of key protective security terms.
How NPSA can help
NPSA produce guidance across a range of mitigation measures that will help you protect your assets.
Start with the Threat and Risk Management menu. This contains guidance on the Risk Management process - which we recommend everyone follows; as well as information about the threat landscape.
The Information For menu provides guidance articles based on role, and the Protection From menu gives guidance articles based on common risks.
If there is something particular you want to explore, have a look at the Guidance by Topic menu; or use the Explore All Guidance filters to get more precise about your situation and needs. The Search function will help you locate specific articles, words or text.
The Resources section has some additional products, such as the Catalogue of Security Equipment, that will help you implement your protective security mitigations.
We will shortly be bringing our online courses to this website where you can delve in to a range of protective security topics.