The document comprises a Code of Practice (CoP) for security-informed safety in the rail sector and provides guidance on security issues for railway safety engineers and managers
The consequences of failing to plan properly for new security projects or upgrades of existing security measures can be costly.
A key purpose of connected places, also known as smart cities, also known as is to join up specific vertical sectors across organisational boundaries into a whole-city approach for the creation, delivery and use of city spaces and services
PAS 185:2017 Specification for establishing and implementing a security-minded approach
PAS 185:2023 is a specification for establishing and implementing a placewide, strategic-level, security-minded approach as part of both its development and operation
Guidance on how to take a security-minded approach to Digital Engineering, Technologies, Projects and Initiatives
This guidance provides the questions which an organisation needs to ask of itself and its supply chain, including its professional advisers, in order to gain an understanding of what information it, or others, holds in relation to its built assets
An introductory guide for built asset owners and facilities managers
This guidance document is intended for use by managers leading and teams delivering digitalisation initiatives. It sets out a process to determine high-level information need and any associated security and management requirements
Guidance on how to take a Security-Minded approach to Digital Engineering, Technologies, Projects and Initiatives
This short document illustrates a ‘4 Step Publication Approach’ aimed at helping those preparing documents for electronic publication to a wide community, including publicly accessible websites and document servers
A Security Considerations Assessment (SCA) is a structured process for ensuring that potential security-related vulnerabilities are considered across a range of activities and processes
A Security Considerations Assessment (SCA) is a structured process for identifying and managing security risks associated with an activity
This guidance lists the key UK legislation, regulations and codes that decision-makers responsible for connected places should be aware of when collecting, storing, processing, generating or sharing data and information relating to connected place services and built assets
A specification for security-minded building information modelling, digital built environments and smart asset management
A specification for security-minded building information modelling, digital built environments and smart asset management
This provides generic guidance on developing security-informed safety assurance using a combined approach
This page and guidance documents provide information on assuring safety systems so they are also secure
Passport to Good Security - Identify your Most Valuable Assets: understanding which assets are critical to your organisation’s existence and operation should be the starting point in your protective security planning process.
Passport to Good Security - Good Governance: in your role as a manager with responsibility for security matters, you should aim to identify answers to key questions about the governance arrangements your organisation has (or may not have) in place for security risks.
Passport to Good Security - Security Pre-Screening: pre-screening of employees, contractors and service providers should be included as part of your overall organisation security strategy.
Passport to Good Security - Legality, Ethics and Transparency: employees should understand the role they can play in protecting the organisation from internal and external threat.
Passport to Good Security - Mitigate your Risks: plan the specific actions your organisation will take following completion of the risk assessment, focusing on the threats specific to your organisation’s critical assets.
NPSA’s Passport to Good Security for Senior Executives sets out 20 principles for effective security management
Passport to Good Security - Hard Measures: ‘hard’ measures require establishing clear procedures to address any failures to adhere to security policy.
Passport to Good Security - Build it Secure: poor or insufficient attention to security at the design and build stage can pose significant risks once the build is completed and operational.
Passport to Good Security - Identify the Threats: consider threats from across the full spectrum of physical, personnel and people, and cyber, and how these threats might evolve over time.
Passport to Good Security - Adopt a Risk Management Approach: provide a framework to help you specify how you will manage the identified threats or risks to your most critical assets.
Passport to Good Security - Control Access: the level of security in your access control system needs to be a balance between business needs and effective security.
Passport to Good Security - Soft Measures: ensure security information is clearly and regularly communicated to staff, contractors and suppliers.
Passport to Good Security - Protect Your Information: a loss of data can cause organisation significant harm across every level, from loss of capital and reputation to a loss of staff confidence and well-being.
Passport to Good Security - Sharing of Information: sharing information inappropriately can pose a significant risk to your organisation, leaving it vulnerable to theft, loss of data or improper use of information.
Passport to Good Security - Online Social Behaviour: what your employees do and say online, or how they use digital devices, can make them and your organisation vulnerable to security threats.
Passport to Good Security - Home and Mobile Working: working away from the office can have numerous benefits for employees, but can also present an additional security risks.
Passport to Good Security - Staff Exit Strategy: employees leaving your organisation may take knowledge about operations, assets and security vulnerabilities with them.
Passport to Good Security - Search and Screening: your threat assessment will give you a good idea of the likely risks posed by anyone - and anything - entering your premises
All organisations need to ensure they have the processes and procedures in place to deliver an effective, efficient and compliant security provision
Protective Security Management Systems Case Study from the Transport sector
Protective Security Management Systems Case Study from the Transport sector
Protective Security Management Systems Case Study from the Transport sector
Protective Security Management Systems Case Study from the Financial Sector
Protective Security Management Systems Case Study from the Transport sector
Effective security risk management requires an organisation to have defined governance and oversight of protective security management systems.
An essential tool to enable you to produce a clear, considered, high-level statement of security needs based on the risks faced
Protective security is important for a site’s own infrastructure which is crucial for it to function or could present hazards if attacked.
Passport to Good Security - Identify your Most Valuable Assets: understanding which assets are critical to your organisation’s existence and operation should be the starting point in your protective security planning process.
Passport to Good Security - Good Governance: in your role as a manager with responsibility for security matters, you should aim to identify answers to key questions about the governance arrangements your organisation has (or may not have) in place for security risks.
Passport to Good Security - Legality, Ethics and Transparency: employees should understand the role they can play in protecting the organisation from internal and external threat.
Passport to Good Security - Mitigate your Risks: plan the specific actions your organisation will take following completion of the risk assessment, focusing on the threats specific to your organisation’s critical assets.
NPSA’s Passport to Good Security for Senior Executives sets out 20 principles for effective security management
Passport to Good Security - Identify the Threats: consider threats from across the full spectrum of physical, personnel and people, and cyber, and how these threats might evolve over time.
Passport to Good Security - Adopt a Risk Management Approach: provide a framework to help you specify how you will manage the identified threats or risks to your most critical assets.
An effective security culture is an essential component of an organisation’s protective security regime. Learn more about security culture and how effective leadership can shape the security culture of your organisation.
Get started here with an overview of security culture and why it’s important.
Guidance for developing and sustaining effective security behaviours within a Critical National Infrastructure organisation
The Security Industry Authority (SIA) has launched the Stay Safe, Tell Security campaign, urging the public and businesses to remain vigilant and report any unusual activity to nearby licensed security operatives or the police.
How will you embed the desired security behaviours and culture in your organisation?
Access NPSA’s tools and resources that can support you as you look to improve your security culture
Security-Mindedness is about encouraging business leaders, managers and practitioners to consider security across all areas of your organisations
This guidance is for users of shared workspaces and provides practical advice tailored to your workspace and activities
This guidance is designed to help workspace providers provide the safety and collaboration that your users seek.
This guidance helps you to recognise suspicious adverts and recruiter behaviours and understand how you can protect yourself and your organisation by reporting concerns and ceasing engagement if something doesn’t look right
Guidance aimed at Users and Providers of shared workspaces, offices, coworking spaces and laboratories to encourage basic security practices and enhance your security awareness
Guidance on supply chain resilience or the security of supply. Aims to help businesses and organisations to anticipate, prepare and adaptively respond to prevent disruption to supply chains.
Guidance for business who are also suppliers on how to develop and improve their security profile. This aims to encourage suppliers to see security as part of their competitive edge.
Guidance for those practitioners responsible for implementing supply chain security within organisations. Suitable for procurement professionals, commercial teams, security professionals, and others.
High level guidance for senior business leaders on protecting business from supply chain attacks. This aims to empower to prioritise and resource supply chain security.
High level guidance for senior business leaders on protecting business from supply chain attacks. This aims to empower to prioritise and resource supply chain security.
Protected Procurement is guidance for businesses and organisations to help embed security across supply chains and to protect from supply chain attacks. Created in partnership with CIPS
A key purpose of connected places, also known as smart cities, also known as is to join up specific vertical sectors across organisational boundaries into a whole-city approach for the creation, delivery and use of city spaces and services
PAS 185:2023 is a specification for establishing and implementing a placewide, strategic-level, security-minded approach as part of both its development and operation
Guidance on how to take a security-minded approach to Digital Engineering, Technologies, Projects and Initiatives
Guidance on how to take a Security-Minded approach to Digital Engineering, Technologies, Projects and Initiatives
When deploying digitally connected physical security systems in the modern world, is it important to use products that have been independently tested to help withstand cyber threats. This guide sheds light on the different cyber standards available to organisations and products
When deploying digitally connected physical security systems in the modern world, is it important to use products that have been independently tested to help withstand cyber threats. This guide sheds light on the different cyber standards available to organisations and products
Information on how open and shared data relates to a Security-Minded approach.