Indicator

Risk description

Possible solutions

References

Employment policy

including for temporary personnel

Infiltration of staff that could pose a security risk.

background checks on prospective employees, e.g. previous employment history and references;

additional checks on new or existing employees moving to security sensitive posts e.g. police checks on unspent convictions;

requirements on staff to disclose other employment, police cautions/bail, pending court proceedings, or convictions;

periodic background checks/reinvestigations for current personnel;

removal of computer access, return of security pass, keys and/or badge when staff leave or are dismissed;

checks on temporary staff applied at the same standard as permanent staff;

contracts with employment agencies detail level of security checks required;

procedures to ensure employment agencies comply with those standards.

SAQ - 6.11.2 ; SAQ - 6.11.4

ISO 28001:2007, section A.3

Level of safety and security awareness of personnel

Lack of proper knowledge on security procedures related to different process (incoming goods, loading, unloading, etc.) with the consequence of accepting/loading/unloading unsafe or insecure goods.

staff awareness on security measures/arrangements related to different process (incoming goods, loading, unloading, etc.);

set up a register for recording security and safety anomalies and discuss this with staff on a regular basis;

procedures in place for employees to identify and report suspicious incidents;

pamphlets on security and safety issues can be displayed in specific areas and communicated via a notice-board;

display the security & safety rules in the relevant areas (loading/unloading etc.). The signs must be visible internally (in the sites) and externally (places dedicated to the drivers, temporaries, various partners).

ISO/28001:2007, section A.3

Security and Safety training

Lack of mechanisms for training employees on safety and security requirements and, consequently, inadequate awareness of security requirements.

persons responsible for identifying training needs, ensuring delivery and keeping training records;

training employees to recognise potential internal threats to security, detection of intrusion/tampering and preventing unauthorised access to secure premises, goods, vehicles, automated systems, seals and records;

conducting tests with “unsafe” goods or occasions;

security and safety training can be part of industrial safety training to outreach all staff;

Security and Safety trainings have to be documented and updated regularly based on happened situations in the company (e.g. every year);

New staff should be trained intensively due to their lack of knowledge and awareness.

SAQ - 6.11.3

ISO 28001:2007, section A.3