marine division template powerpoint presentation -...
TRANSCRIPT
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Security ManagementSecurity Management
Managing Security PragmaticallyManaging Security Pragmatically
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Events that changed the world
•• ETA’s planned bomb ETA’s planned bomb attach of Spanish car attach of Spanish car ferryferry
•• October 12th 2001 October 12th 2001 Attack on USS ColeAttack on USS Cole
•• September 11th 2001 September 11th 2001 Attacks of WTC and Attacks of WTC and PentagonPentagon
•• October 6th 2002October 6th 2002Attack on LimburgAttack on Limburg
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
And more recently……
• Madrid –March 2004
• London - July 2005
• Aqaba –August 2005
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Actions were needed
• Maritime Transportation Security Act – MTSA
• International Maritime Organisation - IMO
• US Department of Homeland Security - DHS
• World Customs Organisation - WCO
• International Standards Organisation – ISO
• European Union - EU
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Maritime Transportation Security Act - 2002
• Amends the Merchant Marine Act 1936
• Improves security for US seaports
• 361 public seaports: Any disruption would ‘seriously’ harm the economy
• Ports are open & exposed - susceptible to terrorism
• Current inspection levels of containers are insufficient. Technology not adequate
• Recognised the work of the International Maritime Organisation (IMO)
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
The International Ship and Port Facility Security (ISPS) code
• Ships and Ports
• Conceived in 2002
• Developed in 2003
• Implemented on July 1st 2004
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Consider all threats, including:
• Damage or destruction
• Hijacking
• Tampering with cargo
• Smuggling weapons
• Piracy
• Use as weapons
• Unauthorised access
• Attacks on ships at sea and at berth
The ISPS code for ships and ports
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
• Risk assessments
• Plans and procedures
• Auditing
• Communication
• Drills and exercises
• Port security officer
• Ship security officer
• Company security officer
• Training and assigned duties
The ISPS code for ships and ports
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Port FacilitySea passage
Ship and Ports
The ISPS CodeThe ISPS Code
But what about th
e rest ?
But what about th
e rest ?
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Packing stationFactory
Port Facility
Rail Sea passage
Warehouse
The supply chain
Road Freight Yard
The ISPS CodeThe ISPS Code
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
The real threats to the supply chain
•• 90% of the world’s 90% of the world’s cargo is cargo is transported in transported in containerscontainers
•• 9 million containers 9 million containers are transported are transported into US ports each into US ports each yearyear
•• About 3% actually About 3% actually inspectedinspected
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
The Ubiquitous Container
• The unit of transport
• Once closed, locked and sealed - assumed ‘OK’
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Maybe so, but…….
• What else maybe inside?
• Do we prevent or do we rely on detection
• How will we know?
• …………….many questions?
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Packing stationFactory
Port Facility
Rail
Warehouse
Sea passage
The real potential concern
Road Freight Yard
The ISPS CodeThe ISPS Code
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Container packing
• Container packing (‘stuffing’) isn't a sophisticated process
• Many small & busy packing stations
• Semi skilled ‘stuffers’
• Tight timescales
• Reliant on up stream declarations
• Accuracy of manifests
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
The potential issues
• Inadequate training
• No verification
• Poor records
• Poor systems
The consequences• Threats to security
The solutions• Management systems
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Is the solution simple ……?
Make sure you know what is in these before Make sure you know what is in these before ……..
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
………….before they get put in this .before they get put in this ……....
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
………….before they disappear into this !!.before they disappear into this !!
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
…….....with something not on the manifest.....with something not on the manifest……..
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Who is doing what right now…?Who is doing what right now…?
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Current and emerging initiatives
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
ISO’s program of work
Standards and codes of practice for supply chain security
ISO 28000 - Supply chain security management
ISO 28001 - Supply chain best practices
ISO 28004 - Guidance for ISO 28000
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
ISO PAS 28000
• To be published end of 2005
• Looks and feels like ISO 14001
• Risk based
• P D C A
• ISO 19011 audits
• Will be a full Standard
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
ISO 28001
• “Best practices Custody in Supply Chain Security”
• Describes:
Security requirements at point of origin
Security issues that ‘shippers’ must consider – security assessments and resultant plans (procedures)
Requirements for safeguarding data and goods in custody
Specifies that data, documentation and training are required
Requires underpinning management system
• Aligned with WCO’s Framework of Standards
• But not a requirements specification
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
WCO Framework of Standards
• To secure and facilitate global trade
• Enhance the capabilities of Customs
• Strengthen networking between Customs
• Promote cooperation between Customs and businesses
• Link to ISO 28001
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
EU Regulation
• Member States shall:
Designate a competent authority
Establish a regime to grant “known operator” status
Grant “known operator” status and maintain a register
Appoint Recognised Security Organisations
• Requires a management system
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
• I’m a quality company
• I’m an environmentally responsible company
• I need security management for my supply chain
So, where from here?
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Continual Improvement
Security Management Policy
Security risk assessment and planning
Revision 2
Implementation and OperationChecking and Corrective
Management Review
Secu
rity
Man
agem
ent
Secu
rity
Man
agem
ent
a
Where are the threats to your supply chain?
Management Systems
Management Systems