Sequence improvements to internal security investigation so that each step makes the next one easier.
Corporate Internal Security Investigation Methods
Learn to design, measure and defend your organisation's approach to internal security investigation.
Course Overview
Security arrangements around internal security investigation are tested by adversaries, not by auditors. Insider risk in this area of corporate security practice is uncomfortable to discuss and expensive to ignore. Buying a tool rarely fixes this part of corporate security practice; the underlying capability has to be built internally first. Sessions alternate between guided analysis of internal security investigation and supervised application. The programme works equally well for those formalising this strand of corporate security practice for the first time and those improving an existing approach. Participants take away a working set of documents supporting the practice within corporate security practice, ready to be adapted internally. Post-incident reviews keep identifying weaknesses in internal security investigation that were visible long before the incident. It treats the wider corporate security practice agenda as an operating discipline and equips participants to run it as one. The course ends by identifying what the participant will stop doing to make this aspect of corporate security practice sustainable.
Expected Learning Outcomes
Prepare a short, evidence-based briefing on internal security investigation for senior management.
Design layered controls for internal security investigation across deterrence, detection, delay and response.
Design a practical operating method for internal security investigation that fits the organisation's size and maturity.
Design surveillance coverage for internal security investigation that supports investigation.
Exercise and test arrangements for internal security investigation under realistic conditions.
Balance security requirements in internal security investigation against operational practicality.
Who Should Attend
Information security staff whose remit overlaps internal security investigation.
Human resources staff handling vetting and insider risk in internal security investigation.
Managers with direct responsibility for internal security investigation within the protected site.
Operations managers whose activity is protected by internal security investigation.
Risk managers assessing exposure from internal security investigation.
Managers of multi-site operations seeking consistency in internal security investigation.
Course Modules
Internal security investigation: continuity, exercises and external coordination
2 sessions · 8 pointsSession 1Making the investment case for internal security investigation
- Anticipate the objections internal security investigation will raise and prepare the answers.
- Review whether internal security investigation is aligned with the objectives of the protected site.
- Identify the data already collected that bears on internal security investigation.
- Set escalation criteria and out-of-hours contacts for internal security investigation.
Session 2Getting other functions to support internal security investigation
- Benchmark the organisation's internal security investigation against comparable operations.
- Write down the assumptions underpinning the approach to internal security investigation.
- Confirm vetting standards applied to staff and contractors in internal security investigation.
- Review internal security investigation after every incident, exercise or change in threat.
Internal security investigation: insider risk, vetting and personnel security
2 sessions · 8 pointsSession 1Reviewing internal security investigation when nothing has gone wrong
- Remove steps in internal security investigation that add effort without adding assurance.
- Check guard force instructions for internal security investigation are current and understood.
- Verify identity checks applied at entry points relevant to internal security investigation.
- Assign responsibility for keeping documentation of internal security investigation current.
Session 2The first fifteen minutes of an incident involving internal security investigation
- Establish evidence handling and chain of custody for internal security investigation.
- Check that controls on internal security investigation cover deterrence, detection, delay and response.
- Assess insider risk in roles with privileged access to internal security investigation.
- Identify vulnerabilities in internal security investigation and rank them by consequence, not ease of fix.
Internal security investigation: layered controls — deter, detect, delay, respond
2 sessions · 8 pointsSession 1Exercising the plan for internal security investigation realistically
- Coordinate arrangements for internal security investigation with civil defence and police in advance.
- Build the threat picture for internal security investigation from sources relevant to this site and sector.
- Define the first response actions for an incident involving internal security investigation.
- Prepare the summary of internal security investigation that senior management will read.
Session 2Where internal security investigation typically breaks, and why
- Exercise the plan for internal security investigation under realistic conditions and record failures.
- Check that internal security investigation still works when volumes rise unexpectedly.
- Collect evidence on the present handling of internal security investigation before proposing changes.
- Establish what evidence demonstrates internal security investigation is under control.
Internal security investigation: threat assessment and intelligence
2 sessions · 8 pointsSession 1Handling evidence from internal security investigation so it survives scrutiny
- Report on internal security investigation in terms that support an investment decision.
- Confirm recorded material from internal security investigation is retained long enough to be useful.
- Set out how exceptions to internal security investigation are requested and approved.
- Agree the indicators that will show whether internal security investigation is improving.
Session 2Layering controls on internal security investigation so one failure is not fatal
- Confirm access control on internal security investigation cannot be routinely bypassed.
- Define the trigger that would require internal security investigation to be redesigned.
- Build the internal briefing that explains internal security investigation to those affected.
- Establish who is informed, consulted and accountable in internal security investigation.
Choose the package that suits you
Silver Package
At least 3 people
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Gold Package
At least 3 people
- 5-night stay in a 5-star hotel
- Workshop or Program Participation
- Airport Transfers
- Customized Badge
- Expert Mentorship (Private Sessions)
- Supervision & Secretarial Services
- Accredited Certificate of Participation
- Complete Training Kit
- Coffee Break
- Closing Ceremony
Complete your registration
We will contact you within one business day to confirm.