Page 13 - CITS Theft Guide
P. 13
CITS Guide for Theft Prevention
- 13 -
4. The Security Management Review (SMR) Process
CITS recommends that the threat, vulnerability, and risk assessment referred to throughout this guide is
carried out using the Security Management Review (SMR) methodology, a proven process previously used
successfully across the construction security sector (see Annex B). SMR is a logical, repeatable, and
defensible six-stage process, grounded in established risk-assessment research, that produces a risk-
commensurate, cost-efficient, and proportionate protective security solution and a clear, auditable set of
outputs at every stage.
An SMR can be scaled to the asset in question — good practice suggests it can be conducted "in 30 days
or 30 minutes" — so a large, critical, or novel site should expect a fuller review, while a small or low-
criticality site may complete the same six stages in a short workshop. The six stages are illustrated below
and set out in detail at Sections 4.1 to 4.6, each ending with the specific outputs ("products") that stage
should produce.
Figure 2: The six-stage Security Management Review (SMR) process.
4.1. Stage 1 — Asset Characterisation
The review team first develops a shared understanding of what is to be protected, and identifies the critical
aspects, elements, or constituent parts of the asset, area, or system in question. A useful technique is to
speak directly to the designers or operators of the asset and ask them how they would attack it to render
it unusable — this often surfaces critical dependencies that are not obvious from a plan alone.
The team should identify and involve the key stakeholders at this stage, including the asset owner or
operator, the organisation's Accountable Person, the Senior Risk Owner, supply chain security specialists,
and, where necessary, external agencies such as the police. An SMR Lead should be appointed, and, where
responsibilities are not already clear, a RACI chart (Responsible, Accountable, Consulted, Informed) should
be produced to set out protective responsibilities without ambiguity.
Stage outcome (products)
(a) A description of the asset.
(b) The owner of the asset or system.
(c) The person responsible for protecting the asset.
(d) The Senior Risk Owner (budget holder).

