Page 15 - CITS Theft Guide
P. 15
CITS Guide for Theft Prevention
- 15 -
4.5. Stage 5 — Design Integrated Security Arrangements
The team identifies the design criteria (legal, regulatory, and company requirements), constraints (time,
cost, safety, and emergency provision), and other considerations that will shape the solution, then
identifies options available to reduce the adversarial risk — whether reduction or responsive, and drawing
on personnel, cultural, procedural, physical, technical, and behavioural measures, ideally combined into a
single holistic security programme rather than a single control in isolation.
This is captured in an Operational Requirement, which outlines the blend of capability needed and
specifies the effect required rather than prescribing a specific product or solution. The team agrees a
preferred option, challenges it through a "red team" review where necessary, and develops a costed
proposal and delivery schedule. Approval and funding are then sought from the Senior Risk Owner,
including explicit acknowledgement of the willingness to accept any residual risk; where the Senior Risk
Owner accepts a risk without full mitigation, this should be documented and the consequences made clear
to them, and where only partial agreement is reached, the residual risk should be reassessed and
documented accordingly.
Once approved, the arrangements are installed, commissioned, and implemented, together with a
technical systems maintenance and repair programme. Finally, the relevant documents are created or
updated — including the Site-Specific Security Plan, "as-built" drawings, work instructions, and procedures
— recorded in the organisation's SMR Register, with learning captured and communicated back to the
review team and stakeholders.
Stage outcome (products)
(a) An Operational Requirement.
(b) A Security Plan.
(c) “As-built” drawings of the defensive security systems.
(d) A residual risk register.
(e) An entry listed in the Project’s SMR Register.
4.6. Stage 6 — Review Security Arrangements
The SMR process is revisited whenever it becomes applicable to do so — an SMR is not a one-off exercise,
but a live document that should be refreshed as the asset, the threat, or the organisation's risk appetite
changes. established practice sets out five specific triggers for conducting or repeating an SMR, which CITS
recommends adopting:
Risk # Risk statement Likelihood Consequence Risk score
1
Due to the lack of control at the entrance of the work area there is
an increased risk that unknown person(s) can sabotage installed
equipment, rendering it unusable. This could impact commissioning,
increase cost, or delay production, and lead to reputational damage.
5 3 15 — High
Stage outcome (products)
(a) A shared understanding of the risk.
(b) A list of risk statements (a risk register).
(c) An impact assessment for each risk.
(d) A score for each adversarial risk.

